|
213161
|
7.5 |
HIGH
Network
|
libiec_iccp_mod_project
|
libiec_iccp_mod
|
A heap buffer-overflow in the client_example1.c component of libiec_iccp_mod v1.5 leads to a denial of service (DOS).
|
CWE-787
Out-of-bounds Write
|
CVE-2020-20490
|
2024-11-21 14:12 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213162
|
7.5 |
HIGH
Network
|
iec104_project
|
iec104
|
IEC104 v1.0 contains a stack-buffer overflow in the parameter Iec10x_Sta_Addr.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-20486
|
2024-11-21 14:12 |
2021-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213163
|
9.8 |
CRITICAL
Network
|
nuishop
|
nuishop
|
Nuishop v2.3 contains a SQL injection vulnerability in /goods/getGoodsListByConditions/.
|
CWE-89
SQL Injection
|
CVE-2020-20675
|
2024-11-21 14:12 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213164
|
5.4 |
MEDIUM
Network
|
eyoucms
|
eyoucms
|
Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20645
|
2024-11-21 14:12 |
2021-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213165
|
8.8 |
HIGH
Network
|
eyoucms
|
eyoucms
|
Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admin&c=Filemanager&a=newfile&lang=cn.
|
CWE-352
Origin Validation Error
|
CVE-2020-20642
|
2024-11-21 14:12 |
2021-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213166
|
6.5 |
MEDIUM
Network
|
axiosys
|
bento4
|
An issue was discovered in Bento4 v1.5.1.0. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a denial of service (program crash), as demonstrated by mp42aa…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21066
|
2024-11-21 14:12 |
2021-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213167
|
5.4 |
MEDIUM
Network
|
domainmod
|
domainmod
|
A cross site scripting (XSS) vulnerability in the /segments/edit.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via the Segment Name parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20990
|
2024-11-21 14:12 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213168
|
4.3 |
MEDIUM
Network
|
domainmod
|
domainmod
|
A cross-site request forgery (CSRF) in /admin/maintenance/ of Domainmod 4.13 allows attackers to arbitrarily delete logs.
|
CWE-352
Origin Validation Error
|
CVE-2020-20989
|
2024-11-21 14:12 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213169
|
5.4 |
MEDIUM
Network
|
domainmod
|
domainmod
|
A cross site scripting (XSS) vulnerability in the /domains/cost-by-owner.php component of Domainmod 4.13 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the "or Exp…
|
CWE-79
Cross-site Scripting
|
CVE-2020-20988
|
2024-11-21 14:12 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213170
|
7.5 |
HIGH
Network
|
metinfo
|
metinfo
|
A SQL injection in the /admin/?n=logs&c=index&a=dolist component of Metinfo 7.0 allows attackers to access sensitive database information.
|
CWE-89
SQL Injection
|
CVE-2020-20981
|
2024-11-21 14:12 |
2021-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|