|
208391
|
9.8 |
CRITICAL
Network
|
gnuplot_project
|
gnuplot
|
com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-25412
|
2024-11-21 14:17 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208392
|
8.8 |
HIGH
Network
|
blackcat-cms
|
blackcat_cms
|
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote arbitrary code execution.
|
CWE-352
Origin Validation Error
|
CVE-2020-25453
|
2024-11-21 14:17 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208393
|
5.4 |
MEDIUM
Network
|
niftypm
|
nifty
|
Nifty Project Management Web Application 2020-08-26 allows XSS, via Add Task, that is rendered upon a Project Home visit. Note: It has been argued that this is not reproducible. "The original issue w…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25071
|
2024-11-21 14:17 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208394
|
5.4 |
MEDIUM
Network
|
recall-products_project
|
recall-products
|
Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 is affected by: Cross Site Scripting (XSS) via the 'Recall Settings' field in admin.php. An attacker can inject JavaScript code that wil…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25380
|
2024-11-21 14:17 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208395
|
8.8 |
HIGH
Network
|
recall-products_project
|
recall-products
|
Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 fails to sanitize input from the 'Manufacturer[]' parameter which allows an authenticated attacker to inject a malicious SQL query.
|
CWE-89
SQL Injection
|
CVE-2020-25379
|
2024-11-21 14:17 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208396
|
6.1 |
MEDIUM
Network
|
accesspressthemes
|
wp_floating_menu
|
Wordpress Plugin Store / AccessPress Themes WP Floating Menu V1.3.0 is affected by: Cross Site Scripting (XSS) via the id GET parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25378
|
2024-11-21 14:17 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208397
|
5.4 |
MEDIUM
Network
|
softrade
|
wp_smart_crm_\&_invoices
|
Wordpress Plugin Store / SoftradeWeb SNC WP SMART CRM V1.8.7 is affected by: Cross Site Scripting via the Business Name field, Tax Code field, First Name field, Address field, Town field, Phone field…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25375
|
2024-11-21 14:17 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208398
|
7.8 |
HIGH
Local
|
kingsoft
|
wps_office
|
GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Word document. This is related to QBrush::setMatrix in gui/pa…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-25291
|
2024-11-21 14:17 |
2020-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208399
|
5.5 |
MEDIUM
Local
|
avast
|
secureline_vpn
|
The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Manager symbolic link from the log directory (which has weak permissions).
|
CWE-59
Link Following
|
CVE-2020-25289
|
2024-11-21 14:17 |
2020-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208400
|
7.2 |
HIGH
Network
|
pligg_project
|
pligg
|
Pligg 2.0.3 allows remote authenticated users to execute arbitrary commands because the template editor can edit any file, as demonstrated by an admin/admin_editor.php the_file=..%2Findex.php&open=Op…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-25287
|
2024-11-21 14:17 |
2020-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|