Show filters
733 Total Results
Displaying 261-270 of 733
Sort by:
Attacker Value
Unknown
CVE-2020-20138
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulnerability in the Showtime2 Slideshow module in CMS Made Simple (CMSMS) 2.2.4.
0
Attacker Value
Unknown
CVE-2020-29455
Disclosure Date: December 11, 2020 (last updated February 22, 2025)
A cross-Site Scripting (XSS) vulnerability in this.showInvalid and this.showInvalidCountry in SmartyStreets liveAddressPlugin.js 3.2 allows remote attackers to inject arbitrary web script or HTML via any address parameter (e.g., street or country).
0
Attacker Value
Unknown
CVE-2020-13526
Disclosure Date: December 10, 2020 (last updated February 22, 2025)
SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. The reportTables_Ajax and clientSetupAjax pages are vulnerable to SQL injection in the sort parameter.An attacker can make an authenticated HTTP request to trigger these vulnerabilities.
0
Attacker Value
Unknown
CVE-2020-13525
Disclosure Date: December 03, 2020 (last updated February 22, 2025)
The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2020-15481
Disclosure Date: November 13, 2020 (last updated November 28, 2024)
An issue was discovered in PassMark BurnInTest v9.1 Build 1008, OSForensics v7.1 Build 1012, and PerformanceTest v10.0 Build 1008. The kernel driver exposes IOCTL functionality that allows low-privilege users to map arbitrary physical memory into the address space of the calling process. This could lead to arbitrary Ring-0 code execution and escalation of privileges. This affects DirectIo32.sys and DirectIo64.sys drivers. This issue is fixed in BurnInTest v9.2, PerformanceTest v10.0 Build 1009, OSForensics v8.0.
0
Attacker Value
Unknown
CVE-2020-27996
Disclosure Date: October 29, 2020 (last updated November 28, 2024)
An issue was discovered in SmartStoreNET before 4.0.1. It does not properly consider the need for a CustomModelPartAttribute decoration in certain ModelBase.CustomProperties situations.
0
Attacker Value
Unknown
CVE-2020-15243
Disclosure Date: October 08, 2020 (last updated February 22, 2025)
Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activated the Web API plugin. Users of Smartstore 4.0.0 and 4.0.1 must merge their repository with 4.0.x or overwrite the file SmartStore.Web.Framework in the */bin* directory of the deployed shop with this file. As a workaround without updating uninstall the Web API plugin to close this vulnerability.
0
Attacker Value
Unknown
CVE-2020-15501
Disclosure Date: October 07, 2020 (last updated November 08, 2023)
Smarter Coffee Maker before 2nd generation allows firmware replacement without authentication or authorization. User interaction is required to press a button. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
0
Attacker Value
Unknown
CVE-2020-7709
Disclosure Date: October 05, 2020 (last updated February 22, 2025)
This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.
0
Attacker Value
Unknown
CVE-2020-24860
Disclosure Date: October 01, 2020 (last updated February 22, 2025)
CMS Made Simple 2.2.14 allows an authenticated user with access to the Content Manager to edit content and put persistent XSS payload in the affected text fields. The user can get cookies from every authenticated user who visits the website.
0