Show filters
461 Total Results
Displaying 151-160 of 461
Sort by:
Attacker Value
Unknown

CVE-2020-28688

Disclosure Date: November 17, 2020 (last updated February 22, 2025)
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
Attacker Value
Unknown

CVE-2020-28687

Disclosure Date: November 17, 2020 (last updated February 22, 2025)
The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
Attacker Value
Unknown

CVE-2020-7032

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.
Attacker Value
Unknown

CVE-2020-7033

Disclosure Date: November 10, 2020 (last updated February 22, 2025)
A Cross Site Scripting (XSS) Vulnerability on the Unified Portal Client (web client) used in Avaya Equinox Conferencing can allow an authenticated user to perform XSS attacks. The affected versions of Equinox Conferencing includes all 9.x versions before 9.1.10.
Attacker Value
Unknown

CVE-2020-26124

Disclosure Date: October 02, 2020 (last updated February 22, 2025)
openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not used in config/databasebackend.inc. Successful exploitation allows arbitrary command execution on the underlying operating system as root.
Attacker Value
Unknown

CVE-2020-25289

Disclosure Date: September 13, 2020 (last updated February 22, 2025)
The VPN service in AVAST SecureLine before 5.6.4982.470 allows local users to write to arbitrary files via an Object Manager symbolic link from the log directory (which has weak permissions).
Attacker Value
Unknown

CVE-2020-15024

Disclosure Date: September 10, 2020 (last updated February 22, 2025)
An issue was discovered in the Login Password feature of the Password Manager component in Avast Antivirus 20.1.5069.562. An entered password continues to be stored in Windows main memory after a logout, and after a Lock Vault operation.
Attacker Value
Unknown

CVE-2020-25022

Disclosure Date: September 04, 2020 (last updated February 22, 2025)
An issue was discovered in Noise-Java through 2020-08-27. AESGCMFallbackCipherState.encryptWithAd() allows out-of-bounds access.
Attacker Value
Unknown

CVE-2020-25023

Disclosure Date: September 04, 2020 (last updated February 22, 2025)
An issue was discovered in Noise-Java through 2020-08-27. AESGCMOnCtrCipherState.encryptWithAd() allows out-of-bounds access.
Attacker Value
Unknown

CVE-2020-25021

Disclosure Date: September 04, 2020 (last updated February 22, 2025)
An issue was discovered in Noise-Java through 2020-08-27. ChaChaPolyCipherState.encryptWithAd() allows out-of-bounds access.