|
210001
|
7.5 |
HIGH
Network
|
phpok
|
phpok
|
SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file.
|
CWE-89
SQL Injection
|
CVE-2020-21486
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210002
|
6.1 |
MEDIUM
Network
|
taogogo
|
taocms
|
Cross Site Scripting vulnerability in taogogo taoCMS v.2.5 beta5.1 allows remote attacker to execute arbitrary code via the name field in admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20725
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210003
|
4.8 |
MEDIUM
Network
|
nodcms
|
nodcms
|
Cross Site Scripting vulnerability in khodakhah NodCMS v.3.0 allows a remote attacker to execute arbitrary code and gain access to senstivie information via a crafted script to the address parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20697
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210004
|
7.5 |
HIGH
Network
|
portfoliocms_project
|
portfoliocms
|
Westbrookadmin portfolioCMS v1.05 allows attackers to bypass password validation and access sensitive information via session fixation.
|
CWE-287
Improper Authentication
|
CVE-2020-20402
|
2024-11-21 14:12 |
2023-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210005
|
8.8 |
HIGH
Network
|
ibarn_project
|
ibarn
|
File upload vulnerability in function upload in action/Core.class.php in zhimengzhe iBarn 1.5 allows remote attackers to run arbitrary code via avatar upload to index.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20588
|
2024-11-21 14:12 |
2022-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210006
|
5.5 |
MEDIUM
Local
|
artifex
|
mupdf
|
A Use After Free vulnerability in svg_dev_text_span_as_paths_defs function in source/fitz/svg-device.c in Artifex Software MuPDF 1.16.0 allows remote attackers to cause a denial of service via openin…
|
CWE-416
Use After Free
|
CVE-2020-21896
|
2024-11-21 14:12 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210007
|
7.8 |
HIGH
Local
|
artifex
|
ghostscript
|
Buffer Overflow vulnerability in clj_media_size function in devices/gdevclj.c in Artifex Ghostscript 9.50 allows remote attackers to cause a denial of service or other unspecified impact(s) via openi…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21890
|
2024-11-21 14:12 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210008
|
5.5 |
MEDIUM
Local
|
ogg_video_tools_project
|
ogg_video_tools
|
A Segmentation Fault issue discovered StreamSerializer::extractStreams function in streamSerializer.cpp in oggvideotools 0.9.1 allows remote attackers to cause a denial of service (crash) via opening…
|
NVD-CWE-noinfo
|
CVE-2020-21723
|
2024-11-21 14:12 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210009
|
7.8 |
HIGH
Local
|
ogg_video_tools_project
|
ogg_video_tools
|
Buffer Overflow vulnerability in oggvideotools 0.9.1 allows remote attackers to run arbitrary code via opening of crafted ogg file.
|
CWE-416
Use After Free
|
CVE-2020-21722
|
2024-11-21 14:12 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210010
|
5.5 |
MEDIUM
Local
|
artifex
|
ghostscript
|
A divide by zero issue discovered in eps_print_page in gdevepsn.c in Artifex Software GhostScript 9.50 allows remote attackers to cause a denial of service via opening of crafted PDF file.
|
CWE-369
Divide By Zero
|
CVE-2020-21710
|
2024-11-21 14:12 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|