|
209541
|
6.1 |
MEDIUM
Network
|
admin_menu_project
|
admin_menu
|
WP Plugin Rednumber Admin Menu v1.1 and lower does not sanitize the value of the "role" GET parameter before echoing it back out to the user. This results in a reflected XSS vulnerability that attack…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24316
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209542
|
7.5 |
HIGH
Network
|
wordpress_poll_project
|
wordpress_poll
|
Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to a lack of user input escaping. This allows users who craft specific SQL stateme…
|
CWE-89
SQL Injection
|
CVE-2020-24315
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209543
|
5.3 |
MEDIUM
Network
|
umanni
|
human_resources
|
Umanni RH 1.0 has a user enumeration vulnerability. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabli…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-24008
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209544
|
9.8 |
CRITICAL
Network
|
umanni
|
human_resources
|
Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-24007
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209545
|
6.1 |
MEDIUM
Network
|
rss_feed_widget_project
|
rss_feed_widget
|
Fahad Mahmood RSS Feed Widget Plugin v2.7.9 and lower does not sanitize the value of the "t" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerabilit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24314
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209546
|
6.1 |
MEDIUM
Network
|
etoilewebdesign
|
ultimate_appointment_booking_\&_scheduling
|
Etoile Web Design Ultimate Appointment Booking & Scheduling WordPress Plugin v1.1.9 and lower does not sanitize the value of the "Appointment_ID" GET parameter before echoing it back out inside an in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24313
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209547
|
7.5 |
HIGH
Network
|
webdesi9
|
file_manager
|
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and do…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2020-24312
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209548
|
5.5 |
MEDIUM
Local
|
nasm
|
netwide_assembler
|
In Netwide Assembler (NASM) 2.15rc10, SEGV can be triggered in tok_text in asm/preproc.c by accessing READ memory.
|
NVD-CWE-noinfo
|
CVE-2020-24242
|
2024-11-21 14:14 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209549
|
5.5 |
MEDIUM
Local
|
nasm
|
netwide_assembler
|
In Netwide Assembler (NASM) 2.15rc10, there is heap use-after-free in saa_wbytes in nasmlib/saa.c.
|
CWE-416
Use After Free
|
CVE-2020-24241
|
2024-11-21 14:14 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209550
|
5.5 |
MEDIUM
Local
|
gnu
|
bison
|
GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input,…
|
CWE-416
Use After Free
|
CVE-2020-24240
|
2024-11-21 14:14 |
2020-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|