|
210481
|
9.8 |
CRITICAL
Network
|
bluecms_project
|
bluecms
|
BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php.
|
CWE-89
SQL Injection
|
CVE-2020-19853
|
2024-11-21 14:09 |
2021-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210482
|
7.5 |
HIGH
Network
|
rtb1_project
|
rtb1
|
A lack of target address verification in the BurnMe() function of Rob The Bank 1.0 allows attackers to steal tokens from victim users via a crafted script.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-19769
|
2024-11-21 14:09 |
2021-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210483
|
7.5 |
HIGH
Network
|
tokensale_project
|
tokensale
|
A lack of target address verification in the selfdestructs() function of ICOVO 1.0 allows attackers to steal tokens from victim users via a crafted script.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-19768
|
2024-11-21 14:09 |
2021-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210484
|
7.5 |
HIGH
Network
|
zeroxracer_project
|
zeroxracer
|
A lack of target address verification in the destroycontract() function of 0xRACER 1.0 allows attackers to steal tokens from victim users via a crafted script.
|
NVD-CWE-noinfo
|
CVE-2020-19767
|
2024-11-21 14:09 |
2021-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210485
|
7.5 |
HIGH
Network
|
tokenerc20_project
|
tokenerc20
|
The time check operation of PepeAuctionSale 1.0 can be rendered ineffective by assigning a large number to the _duration variable, compromising access control to the application.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2020-19766
|
2024-11-21 14:09 |
2021-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210486
|
7.5 |
HIGH
Network
|
proofofdiligencetoken_project
|
proofofdiligencetoken
|
An issue in the noReentrance() modifier of the Ethereum-based contract Accounting 1.0 allows attackers to carry out a reentrancy attack.
|
CWE-863
Incorrect Authorization
|
CVE-2020-19765
|
2024-11-21 14:09 |
2021-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210487
|
7.5 |
HIGH
Network
|
lcdf fedoraproject
|
gifsicle fedora
|
The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-19752
|
2024-11-21 14:09 |
2021-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210488
|
9.1 |
CRITICAL
Network
|
gpac
|
gpac
|
An issue was discovered in gpac 0.8.0. The gf_odf_del_ipmp_tool function in odf_code.c has a heap-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-19751
|
2024-11-21 14:09 |
2021-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210489
|
7.5 |
HIGH
Network
|
gpac
|
gpac
|
An issue was discovered in gpac 0.8.0. The strdup function in box_code_base.c has a heap-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-19750
|
2024-11-21 14:09 |
2021-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210490
|
7.2 |
HIGH
Network
|
zzcms
|
zzcms
|
A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.
|
CWE-94
Code Injection
|
CVE-2020-19822
|
2024-11-21 14:09 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|