Exploit Database

149,740 exploits tracked across all sources.

Sort: Activity Stars
CVE-2020-13343 WRITEUP HIGH
GitLab 11.2.0-13.4.2 - Unauthorized Custom Project Template Exposure
An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template
CVSS 7.5
CVE-2020-15489 WRITEUP CRITICAL
Wavlink WL-WN530HG4 M30HG4.V5030.191116 - Remote Code Execution via CGI Script Shell Metacharacter Injection
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges.
CVSS 9.8
CVE-2020-15490 WRITEUP CRITICAL
Wavlink WL-WN530HG4 M30HG4.V5030.191116 - Remote Code Execution via CGI Script Buffer Overflow
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple buffer overflow vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges. (The set of affected scripts is similar to CVE-2020-12266.)
CVSS 9.8
CVE-2020-15717 WRITEUP MEDIUM
RosarioSIS 6.7.2 - Cross-Site Scripting via Search.inc.php Advanced Parameter
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Search.inc.php script. A remote attacker could exploit this vulnerability using the advanced parameter in a crafted URL.
CVSS 6.1
CVE-2020-15721 WRITEUP MEDIUM
RosarioSIS < 6.8 - Cross-Site Scripting via NotifyParents.php href Attributes
RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.php and User.php.
CVSS 6.1
CVE-2020-16131 WRITEUP MEDIUM
Tiki < 21.2 - Cross-Site Scripting via Improper Input Neutralization in PreventXss.php
Tiki before 21.2 allows XSS because [\s\/"\'] is not properly considered in lib/core/TikiFilter/PreventXss.php.
CVSS 6.1
CVE-2020-16165 WRITEUP CRITICAL
SpringBlade < 2.7.1 - SQL Injection via ORDER BY Clause in Log API
The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.
CVSS 9.8
CVE-2020-20118 WRITEUP MEDIUM
Avast Antivirus < 19.7 - Denial of Service via Crafted Request to aswSnx.sys Driver
Buffer Overflow vulnerability in Avast AntiVirus before v.19.7 allows a local attacker to cause a denial of service via a crafted request to the aswSnx.sys driver.
CVSS 5.5
CVE-2020-25862 WRITEUP HIGH
Wireshark <3.2.7, <3.0.14, <2.6.21 - DoS
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.
CVSS 7.5
CVE-2020-25863 WRITEUP HIGH
Wireshark <3.2.7, <3.0.14, <2.6.21 - Buffer Overflow
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts.
CVSS 7.5
CVE-2020-25866 WRITEUP HIGH
Wireshark 3.0.0-3.0.13 and 3.2.0-3.2.6 - Denial of Service via BLIP Protocol Dissector NULL Pointer Dereference
In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasonable compression ratios and rejecting ZIP bombs.
CVSS 7.5
CVE-2020-25881 WRITEUP MEDIUM
RKCMS - Path Traversal via filename Parameter
A vulnerability was discovered in the filename parameter in pathindex.php?r=cms-backend/attachment/delete&sub=&filename=../../../../111.txt&filetype=image/jpeg of the master version of RKCMS. This vulnerability allows for an attacker to perform a directory traversal via a crafted .txt file.
CVSS 5.5
CVE-2020-25966 WRITEUP HIGH
Sectona Spectra < 3.4.0 - Unauthenticated Sensitive Information Disclosure via SOAP API Endpoint
Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentication. This could be used by unauthorized parties to get configured login credentials of the assets via a modified pAccountID value. NOTE: The vendor has indicated this is not a vulnerability and states "This vulnerability occurred due to wrong configuration of system.
CVSS 7.5
CVE-2020-26407 WRITEUP MEDIUM
GitLab 12.4-13.4.6, 13.5-13.5.4, 13.6-13.6.1 - Stored Cross-Site Scripting via Malicious Project Import
A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project
CVSS 5.5
CVE-2020-26408 WRITEUP MEDIUM
GitLab 12.2.0-13.4.6, 13.5.0-13.5.4, 13.6.0-13.6.1 - Limited Information Disclosure in Private Profile
A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile
CVSS 5.3
CVE-2020-26411 WRITEUP MEDIUM
Gitlab <13.4.7, <13.5.5, <13.6.2 - DoS
A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.
CVSS 4.3
CVE-2020-26414 WRITEUP MEDIUM
GitLab 12.4.0-13.5.5 - Denial of Service via Malicious Package Name Input
An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.
CVSS 4.3
CVE-2020-26416 WRITEUP MEDIUM
GitLab 8.4.0-13.4.6 13.5.0-13.5.4 13.6.0-13.6.1 - Information Disclosure in Advanced Search
Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.
CVSS 4.0
CVE-2020-26418 WRITEUP LOW
Wireshark <3.4.0, 3.2.0-3.2.8 - DoS
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
CVSS 3.1
CVE-2020-26419 WRITEUP LOW
Wireshark 3.4.0 - Denial of Service via Memory Leak in Dissection Engine
Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.
CVSS 3.1
CVE-2020-26420 WRITEUP LOW
Wireshark <3.4.0, 3.2.0-3.2.8 - DoS
Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
CVSS 3.1
CVE-2020-26421 WRITEUP MEDIUM
Wireshark <3.4.0, 3.2.0-3.2.8 - DoS
Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
CVSS 4.2
CVE-2020-26422 WRITEUP LOW
Wireshark 3.4.0-3.4.1 - Denial of Service via QUIC Dissector Buffer Overflow
Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture file
CVSS 3.7
CVE-2020-26575 WRITEUP HIGH
Wireshark < 3.2.7 - Denial of Service via Infinite Loop in FBZERO Dissector
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.
CVSS 7.5
CVE-2020-28030 WRITEUP HIGH
Wireshark 3.2.0-3.2.7 - Denial of Service in GQUIC Dissector
In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.
CVSS 7.5