‼ CVE-2020-36493 ‼
📖 Read
via "National Vulnerability Database".
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component media_main.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36490 ‼
📖 Read
via "National Vulnerability Database".
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-28955 ‼
📖 Read
via "National Vulnerability Database".
SugarCRM v6.5.18 was discovered to contain a cross-site scripting (XSS) vulnerability in the Create Employee module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the First Name or Last Name input fields.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-23047 ‼
📖 Read
via "National Vulnerability Database".
Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a cross-site scripting (XSS) vulnerability in the search input field of the search module.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-23037 ‼
📖 Read
via "National Vulnerability Database".
Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-23061 ‼
📖 Read
via "National Vulnerability Database".
Dropouts Technologies LLP Super Backup v2.0.5 was discovered to contain an issue in the path parameter of the `list` and `download` module which allows attackers to perform a directory traversal via a change to the path variable to request the local list command.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-23046 ‼
📖 Read
via "National Vulnerability Database".
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component tpl.php via the `filename`, `mid`, `userid`, and `templet' parameters.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36502 ‼
📖 Read
via "National Vulnerability Database".
Swift File Transfer Mobile v1.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the devicename parameter which allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered as the device name itself.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36489 ‼
📖 Read
via "National Vulnerability Database".
Dropouts Technologies LLP Air Share v1.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the devicename parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the devicename information.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-28961 ‼
📖 Read
via "National Vulnerability Database".
Perfex CRM v2.4.4 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component ./clients/client via the company name parameter.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36498 ‼
📖 Read
via "National Vulnerability Database".
Macrob7 Macs Framework Content Management System - 1.14f contains a cross-site scripting (XSS) vulnerability in the account reset function, which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the e-mail input field.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-28969 ‼
📖 Read
via "National Vulnerability Database".
Aplioxio PDF ShapingUp 5.0.0.139 contains a buffer overflow which allows attackers to cause a denial of service (DoS) via a crafted PDF file.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-23049 ‼
📖 Read
via "National Vulnerability Database".
Fork CMS Content Management System v5.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the `Displayname` field when using the `Add`, `Edit` or `Register' functions. This vulnerability allows attackers to execute arbitrary web scripts or HTML.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-23042 ‼
📖 Read
via "National Vulnerability Database".
Dropouts Technologies LLP Super Backup v2.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability in the path parameter of the `list` and `download` module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted GET request.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36495 ‼
📖 Read
via "National Vulnerability Database".
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_manage_view.php via the `filename`, `mid`, `userid`, and `templet' parameters.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36496 ‼
📖 Read
via "National Vulnerability Database".
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component sys_admin_user_edit.php via the `filename`, `mid`, `userid`, and `templet' parameters.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36497 ‼
📖 Read
via "National Vulnerability Database".
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component makehtml_homepage.php via the `filename`, `mid`, `userid`, and `templet' parameters.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36499 ‼
📖 Read
via "National Vulnerability Database".
TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a cross-site scripting (XSS) vulnerability in the content parameter of the Rubric Block (Add) module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the rubric name value.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36501 ‼
📖 Read
via "National Vulnerability Database".
Multiple cross-site scripting (XSS) vulnerabilities in the Support module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML via crafted payloads entered into the primary address state or alternate address state input fields.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-42258 ‼
📖 Read
via "National Vulnerability Database".
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to execute arbitrary code as MSSQLSERVER$ via xp_cmdshell.📖 Read
via "National Vulnerability Database".
📢 Kaspersky Internet Security review: Powerful, highly configurable protection 📢
📖 Read
via "ITPro".
Easy to use, efficient and accurate malware defense for users who want to personalise their protection📖 Read
via "ITPro".
IT PRO
Kaspersky Internet Security review: Powerful, highly configurable protection | IT PRO
Easy to use, efficient and accurate malware defense for users who want to personalise their protection