|
208571
|
8.1 |
HIGH
Network
|
jenkins
|
amazon_ec2
|
A missing permission check in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL within the AWS region using attacker-spe…
|
CWE-862
Missing Authorization
|
CVE-2020-2091
|
2024-11-21 14:24 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208572
|
8.8 |
HIGH
Network
|
jenkins
|
amazon_ec2
|
A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers to connect to an attacker-specified URL within the AWS region using attacker-specified creden…
|
CWE-352
Origin Validation Error
|
CVE-2020-2090
|
2024-11-21 14:24 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208573
|
9.8 |
CRITICAL
Network
|
leeco
|
letv_x43_firmware
|
An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).
|
NVD-CWE-noinfo
|
CVE-2020-28715
|
2024-11-21 14:23 |
2023-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208574
|
5.4 |
MEDIUM
Network
|
churchcrm
|
churchcrm
|
Cross Site Scripting (XSS) vulnerability in ChurchCRM version 4.2.1, allows remote attckers to execute arbitrary code and gain sensitive information via crafted payload in Add New Deposit field in Vi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-28849
|
2024-11-21 14:23 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208575
|
8.8 |
HIGH
Network
|
churchcrm
|
churchcrm
|
CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file.
|
CWE-74
Injection
|
CVE-2020-28848
|
2024-11-21 14:23 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208576
|
7.8 |
HIGH
Local
|
matthiaswandel
|
jhead
|
Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-28840
|
2024-11-21 14:23 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208577
|
6.1 |
MEDIUM
Network
|
kindsoft
|
kindeditor
|
Cross Site Scripting (XSS) vulnerability in content1 parameter in demo.jsp in kindsoft kindeditor version 4.1.12, allows attackers to execute arbitrary code.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28717
|
2024-11-21 14:23 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208578
|
9.8 |
CRITICAL
Network
|
mediawiki
|
score
|
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit artic…
|
CWE-94
Code Injection
|
CVE-2020-29007
|
2024-11-21 14:23 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208579
|
9.8 |
CRITICAL
Network
|
zend
|
zend_framework
|
An issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has been disputed by third parties as incomplete and inc…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-29312
|
2024-11-21 14:23 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208580
|
9.8 |
CRITICAL
Network
|
online_doctor_appointment_booking_system_php_and_mysql_project
|
online_doctor_appointment_booking_system_php_and_mysql
|
SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint.
|
CWE-89
SQL Injection
|
CVE-2020-29168
|
2024-11-21 14:23 |
2023-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|