Unknown · CVSS Not scored
Create-Project Manager 1.07 has Multi Persistent Cross-site Scripting and HTML injection in via Online chat, Social feed,Message(title-tag), Add new client (all-tags).
Published Aug 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The management website of the Verint S5120FD Verint_FW_0_42 unit features a CGI endpoint ('ipfilter.cgi') that allows the user to manage network filtering on the unit. This endpoint is vulnerable to a command injection. An authenticated attacker can leverage this issue to execute arbitrary commands as 'root'.
Published Aug 21, 2020 · Updated Aug 4, 2024
Critical · CVSS 10
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.
Published Aug 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.
Published Aug 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol, which requires authentication for some of its operations. It was found that the authentication check for those ONVIF operations can be bypassed. An attacker can abuse this issue to execute privileged operations without authentication, for instance, to create a new Administrator user.
Published Aug 21, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Umanni RH 1.0 has a user enumeration vulnerability. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
Published Aug 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross site request forgery (CSRF) vulnerability in the configure.html component of Ponzu 0.11.0 allows attackers to change user and administrator credentials, and add or delete administrator accounts.
Published Aug 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service implemented in the binary executable '/usr/sbin/DM' that listens on port TCP 6666. The service is vulnerable to a stack buffer overflow. It is worth noting that this service does not require any authentication.
Published Aug 21, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that can spawn a given process repeatedly at a certain time interval as 'root'. One of the limitations of this feature is that it only takes a path to a binary without arguments; however, this can be circumvented using special shell variables, such as '${IFS}'. As a result, an attacker can execute arbitrary commands as 'root' on the units.
Published Aug 21, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DesignMasterEvents Conference management 1.0.0 has cross site scripting via the 'certificate.php'
Published Aug 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter.
Published Aug 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone.
Published Aug 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has cross site scripting via the 'search.php' id parameter.
Published Aug 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
Published Aug 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.
Published Aug 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.
Published Aug 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
13enforme CMS 1.0 has Cross Site Scripting via the "content.php" id parameter.
Published Aug 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Michael-design iChat Realtime PHP Live Support System 1.6 has persistent Cross-site Scripting via chat,text-filed tags.
Published Aug 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.
Published Aug 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
KandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter.
Published Aug 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags.
Published Aug 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"
Published Aug 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".
Published Aug 20, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".
Published Aug 20, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.
Published Aug 22, 2023 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager" section.
Published Aug 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."
Published Aug 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Content."
Published Aug 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue in the UPnP protocol in 4thline cling 2.0.0 through 2.1.2 allows remote attackers to cause a denial of service via an unchecked CALLBACK parameter in the request header
Published Aug 15, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
WebPort-v1.19.17121 is affected by Cross Site Scripting (XSS) on the "connections" feature.
Published Aug 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
webTareas v2.1 is affected by Cross Site Scripting (XSS) on "Search."
Published Aug 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) on module "Configuration."
Published Aug 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NavigateCMS 2.9 is affected by Cross Site Scripting (XSS) via the module "Shop."
Published Aug 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHP-Fusion 9.03.60 is affected by Cross Site Scripting (XSS) via infusions/member_poll_panel/poll_admin.php.
Published Aug 26, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability exists in the phpgurukul Online Marriage Registration System 1.0 allows attackers to run arbitrary code via the wzipcode field.
Published Aug 19, 2022 · Updated Aug 4, 2024
Unknown · CVSS Not scored
When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uploadfile_name1.htm form to a length of 368 or more bytes. This will create a buffer overflow condition, causing the application to crash.
Published Aug 19, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A reflected cross site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor 2.2.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Published Aug 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_Stz2Atom::GetSampleSize component located in /Core/Ap4Stz2Atom.cpp. It allows an attacker to cause a denial of service (DOS).
Published Aug 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Laborator Neon dashboard v3 is affected by stored Cross Site Scripting (XSS) via the chat tab.
Published Aug 27, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A WRITE memory access in the AP4_NullTerminatedStringAtom::AP4_NullTerminatedStringAtom component of Bento4 version 06c39d9 can lead to a segmentation fault.
Published Aug 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) graph_templates.php, (5) graphs.php, (6) reports_admin.php, and (7) data_input.php.
Published Aug 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based buffer overflow exists in the AP4_CttsAtom::AP4_CttsAtom component located in /Core/Ap4Utils.h of Bento4 version 06c39d9. This can lead to a denial of service (DOS).
Published Aug 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap-based buffer overflow exists in the AP4_StdcFileByteStream::ReadPartial component located in /StdC/Ap4StdCFileByteStream.cpp of Bento4 version 06c39d9. This issue can lead to a denial of service (DOS).
Published Aug 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Bento4 version 06c39d9. A NULL pointer dereference exists in the AP4_DescriptorListWriter::Action component located in /Core/Ap4Descriptor.h. It allows an attacker to cause a denial of service (DOS).
Published Aug 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with crafted Zip files due to improper validation of file paths in .zip archives.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files.
Published Aug 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injection and obtain sensitive information via a crafted POST request.
Published Aug 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed directly to the exec function without being escaped.
Published Aug 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-slash characters included in the name of the crafted file.
Published Aug 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A SQL injection vulnerability in config.inc.php of rConfig 3.9.5 allows attackers to access sensitive database information via a crafted GET request to install/lib/ajaxHandlers/ajaxDbInstall.php.
Published Aug 9, 2021 · Updated Aug 4, 2024