Show filters
733 Total Results
Displaying 261-270 of 733
Sort by:
Attacker Value
Unknown

CVE-2020-20138

Disclosure Date: December 17, 2020 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4.
Attacker Value
Unknown

CVE-2020-29455

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
A cross-Site Scripting (XSS) vulnerability in this.showInvalid and this.showInvalidCountry in SmartyStreets liveAddressPlugin.js 3.2 allows remote attackers to inject arbitrary web script or HTML via any address parameter (e.g., street or country).
Attacker Value
Unknown

CVE-2020-13526

Disclosure Date: December 10, 2020 (last updated February 22, 2025)
SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. The reportTables_Ajax and clientSetupAjax pages are vulnerable to SQL injection in the sort parameter.An attacker can make an authenticated HTTP request to trigger these vulnerabilities.
Attacker Value
Unknown

CVE-2020-13525

Disclosure Date: December 03, 2020 (last updated February 22, 2025)
The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2020-15481

Disclosure Date: November 13, 2020 (last updated November 28, 2024)
An issue was discovered in PassMark BurnInTest v9.1 Build 1008, OSForensics v7.1 Build 1012, and PerformanceTest v10.0 Build 1008. The kernel driver exposes IOCTL functionality that allows low-privilege users to map arbitrary physical memory into the address space of the calling process. This could lead to arbitrary Ring-0 code execution and escalation of privileges. This affects DirectIo32.sys and DirectIo64.sys drivers. This issue is fixed in BurnInTest v9.2, PerformanceTest v10.0 Build 1009, OSForensics v8.0.
Attacker Value
Unknown

CVE-2020-27996

Disclosure Date: October 29, 2020 (last updated November 28, 2024)
An issue was discovered in SmartStoreNET before 4.0.1. It does not properly consider the need for a CustomModelPartAttribute decoration in certain ModelBase.CustomProperties situations.
Attacker Value
Unknown

CVE-2020-15243

Disclosure Date: October 08, 2020 (last updated February 22, 2025)
Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartstore 4.0.0 and 4.0.1 must merge their repository with 4.0.x or overwrite the file SmartStore.Web.Framework in the */bin* directory of the deployed shop with this file. As a workaround without updating uninstall the Web API plugin to close this vulnerability.
Attacker Value
Unknown

CVE-2020-15501

Disclosure Date: October 07, 2020 (last updated November 08, 2023)
Smarter Coffee Maker before 2nd generation allows firmware replacement without authentication or authorization. User interaction is required to press a button. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Attacker Value
Unknown

CVE-2020-7709

Disclosure Date: October 05, 2020 (last updated February 22, 2025)
This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.
Attacker Value
Unknown

CVE-2020-24860

Disclosure Date: October 01, 2020 (last updated February 22, 2025)
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.