Exploit Database

153,618 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-8424 WRITEUP CRITICAL
ZoneMinder < 1.32.3 - SQL Injection via ajax/status.php sort Parameter
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
CVSS 9.8
CVE-2019-8425 WRITEUP MEDIUM
ZoneMinder < 1.32.3 - Cross-Site Scripting in SQL-ERR Message Construction
includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
CVSS 6.1
CVE-2019-8426 WRITEUP MEDIUM
ZoneMinder < 1.32.3 - Cross-Site Scripting via newControl Parameter
skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the newControl[MinTiltRange] parameter.
CVSS 6.1
CVE-2019-8427 WRITEUP CRITICAL
ZoneMinder < 1.32.3 - OS Command Injection via daemonControl Shell Metacharacters
daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.
CVSS 9.8
CVE-2019-8428 WRITEUP CRITICAL
ZoneMinder < 1.32.3 - SQL Injection via skins/classic/views/control.php groupSql Parameter
ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.
CVSS 9.8
CVE-2019-8429 WRITEUP CRITICAL
ZoneMinder < 1.32.3 - SQL Injection via ajax/status.php filter[Query][terms][0][cnj] Parameter
ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.
CVSS 9.8
CVE-2019-9107 WRITEUP MEDIUM
wuzhicms 4.1.0 - Stored Cross-Site Scripting via Imagecut URL Parameter
XSS exists in WUZHI CMS 4.1.0 via index.php?m=attachment&f=imagecut&v=init&imgurl=[XSS] to coreframe/app/attachment/imagecut.php.
CVSS 6.1
CVE-2019-9108 WRITEUP MEDIUM
wuzhicms 4.1.0 - Cross-Site Scripting via Baidu Map Parameters
XSS exists in WUZHI CMS 4.1.0 via index.php?m=core&f=map&v=baidumap&x=[XSS]&y=[XSS] to coreframe/app/core/map.php.
CVSS 6.1
CVE-2019-9109 WRITEUP MEDIUM
wuzhicms 4.1.0 - Cross-Site Scripting via Message Username Parameter
XSS exists in WUZHI CMS 4.1.0 via index.php?m=message&f=message&v=add&username=[XSS] to coreframe/app/message/message.php.
CVSS 6.1
CVE-2019-9110 WRITEUP MEDIUM
wuzhicms 4.1.0 - Cross-Site Scripting via set_iframe Parameter
XSS exists in WUZHI CMS 4.1.0 via index.php?m=content&f=postinfo&v=listing&set_iframe=[XSS] to coreframe/app/content/postinfo.php.
CVSS 6.1
CVE-2019-9763 WRITEUP MEDIUM
Openfind Mail2000 6.0 and 7.0 - Stored Cross-Site Scripting via Email Message Object Tag
An issue was discovered in Openfind Mail2000 6.0 and 7.0 Webmail. XSS can occur via an '<object data="data:text/html' substring in an e-mail message (The vendor subsequently patched this).
CVSS 6.1
CVE-2020-10511 WRITEUP CRITICAL
HGiga C&Cmail CCMAILQ and CCMAILN - OS Command Injection via Crafted URL
HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure configurations. Attackers can exploit these flaws to access unauthorized functionality via a crafted URL.
CVSS 9.8
CVE-2020-10512 WRITEUP HIGH
HGiga C&Cmail CCMAILQ and CCMAILN - SQL Injection via URL Parameter
HGiga C&Cmail CCMAILQ before olln-calendar-6.0-100.i386.rpm and CCMAILN before olln-calendar-5.0-100.i386.rpm contains a SQL Injection vulnerability which allows attackers to injecting SQL commands in the URL parameter to execute unauthorized commands.
CVSS 8.8
CVE-2020-11673 WRITEUP CRITICAL
Responsive Poll < 1.3.4 - Unauthenticated Poll Manipulation via wp_ajax_nopriv Callback
An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This is due to the usage of the callback wp_ajax_nopriv function in Includes/Total-Soft-Poll-Ajax.php for sensitive operations.
CVSS 9.8
CVE-2020-11694 WRITEUP HIGH
JetBrains PyCharm 2019.2.5 and 2019.3 - Insufficiently Protected Credentials
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.
CVSS 7.5
CVE-2020-11709 WRITEUP HIGH
cpp-httplib <= 0.5.8 - CRLF Injection via Redirect and Header Parameters
cpp-httplib through 0.5.8 does not filter \r\n in parameters passed into the set_redirect and set_header functions, which creates possibilities for CRLF injection and HTTP response splitting in some specific contexts.
CVSS 7.5
CVE-2020-11713 WRITEUP HIGH
wolfSSL 4.3.0 - Timing Side-Channel Attack in ECC Mulmod Operation
wolfSSL 4.3.0 has mulmod code in wc_ecc_mulmod_ex in ecc.c that does not properly resist timing side-channel attacks.
CVSS 7.5
CVE-2020-11734 WRITEUP MEDIUM
CyberSolutions CyberMail >=5.0 - Cross-Site Scripting via ACTION Parameter
cgi-bin/go in CyberSolutions CyberMail 5 or later allows XSS via the ACTION parameter.
CVSS 6.1
CVE-2020-12256 WRITEUP MEDIUM
rConfig 3.9.4 - Reflected Cross-Site Scripting via deviceId Parameter
rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceId GET parameter to devicemgmnt.php.
CVSS 5.4
CVE-2020-12257 WRITEUP HIGH
rConfig 3.9.4 - Cross-Site Request Forgery
rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because it lacks implementation of CSRF protection such as a CSRF token. An attacker can leverage this vulnerability by creating a form (add a user, delete a user, or edit a user).
CVSS 8.8
CVE-2020-12258 WRITEUP CRITICAL
rConfig 3.9.4 - Session Fixation via PHPSESSID
rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application can reuse a session via PHPSESSID. Also, an attacker can exploit this vulnerability in conjunction with CVE-2020-12256 or CVE-2020-12259.
CVSS 9.1
CVE-2020-12259 WRITEUP MEDIUM
rConfig 3.9.4 - Reflected Cross-Site Scripting via rid GET Parameter
rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the rid GET parameter of devicemgmnt.php.
CVSS 5.4
CVE-2020-12679 WRITEUP MEDIUM
Mitel ShoreTel Conference Web App <19.50.1000.0 - XSS
A reflected cross-site scripting (XSS) vulnerability in the Mitel ShoreTel Conference Web Application 19.50.1000.0 before MiVoice Connect 18.7 SP2 allows remote attackers to inject arbitrary JavaScript and HTML via the PATH_INFO to home.php.
CVSS 6.1
CVE-2020-12737 WRITEUP MEDIUM
Maxum Rumpus <8.2.12 - Path Traversal
An issue was discovered in Maxum Rumpus before 8.2.12 on macOS. Authenticated users can perform a path traversal using double escaped characters, enabling read access to arbitrary files on the server.
CVSS 6.5
CVE-2020-13150 WRITEUP HIGH
D-link DSL-2750U ISL2750UEME3.V1E - Info Disclosure
D-link DSL-2750U ISL2750UEME3.V1E devices allow approximately 90 seconds of access to the control panel, after a restart, before MAC address filtering rules become active.
CVSS 7.8