|
208351
|
5.5 |
MEDIUM
Local
|
innogames
|
god_kings
|
The God Kings application 0.60.1 for Android exposes a broadcast receiver to other apps called com.innogames.core.frontend.notifications.receivers.LocalNotificationBroadcastReceiver. The purpose of t…
|
NVD-CWE-Other
|
CVE-2020-25204
|
2024-11-21 14:17 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208352
|
7.5 |
HIGH
Network
|
we-con
|
levistudiou
|
An XXE vulnerability exists within LeviStudioU Release Build 2019-09-21 and prior when processing parameter entities, which may allow file disclosure.
|
CWE-611
XXE
|
CVE-2020-25186
|
2024-11-21 14:17 |
2020-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208353
|
7.5 |
HIGH
Network
|
advantech
|
r-seenet
|
The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries on the database and retrieve sensitive information.
|
CWE-89
SQL Injection
|
CVE-2020-25157
|
2024-11-21 14:17 |
2020-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208354
|
8.1 |
HIGH
Network
|
overwolf
|
overwolf
|
In the client in Overwolf 0.149.2.30, a channel can be accessed or influenced by an actor that is not an endpoint.
|
NVD-CWE-Other
|
CVE-2020-25214
|
2024-11-21 14:17 |
2020-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208355
|
7.8 |
HIGH
Local
|
laquisscada
|
scada
|
An attacker who convinces a valid user to open a specially crafted project file to exploit could execute code under the privileges of the application due to an out-of-bounds read vulnerability on the…
|
-
|
CVE-2020-25188
|
2024-11-21 14:17 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208356
|
9.8 |
CRITICAL
Network
|
online_bus_booking_system_project
|
online_bus_booking_system
|
In SourceCodester Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.
|
CWE-89
SQL Injection
|
CVE-2020-25273
|
2024-11-21 14:17 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208357
|
6.1 |
MEDIUM
Network
|
online_bus_booking_system_project
|
online_bus_booking_system
|
In SourceCodester Online Bus Booking System 1.0, there is XSS through the name parameter in book_now.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25272
|
2024-11-21 14:17 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208358
|
5.4 |
MEDIUM
Network
|
phpgurukul
|
hospital_management_system
|
PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25271
|
2024-11-21 14:17 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208359
|
5.4 |
MEDIUM
Network
|
phpgurukul
|
hostel_management_system
|
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, or City.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25270
|
2024-11-21 14:17 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208360
|
7.1 |
HIGH
Network
|
pyrocms
|
pyrocms
|
PyroCMS 3.7 is vulnerable to cross-site request forgery (CSRF) via the admin/addons/uninstall/anomaly.module.blocks URI: an arbitrary plugin will be deleted.
|
CWE-352
Origin Validation Error
|
CVE-2020-25263
|
2024-11-21 14:17 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|