
Look up vulnerabilities by software, product or CVE number.
| CVE | Published | CVSS | ShadowTrackr CVSS | Summary |
|---|---|---|---|---|
CVE: CVE-2020-1819 | Published 2024-12-27 | CVSS: 3.7 | ShadowTrackr CVSS: 2.9 | Summary: There are multiple out of bounds (OOB) read vulnerabilities in the implementation of the Common Open Policy Service (COPS) protocol of some Huawei products. The specific decoding function may occur out-of-bounds read when processes an incoming data packet. Successful exploit of these vulnerabilities may disrupt service on the affected device. (Vulnerability ID: HWPSIRT-2018-12275,HWPSIRT-2018-12276,HWPSIRT-2018-12277,HWPSIRT-2018-12278,HWPSIRT-2018-12279,HWPSIRT-2018-12280 and HWPSIRT-2018-12289)
The seven vulnerabilities have been assigned seven Common Vulnerabilities and Exposures (CVE) IDs: CVE-2020-1818, CVE-2020-1819, CVE-2020-1820, CVE-2020-1821, CVE-2020-1822, CVE-2020-1823 and CVE-2020-1824. |
CVE: CVE-2020-18198 | Published 2021-05-17 | CVSS: 8.8 | ShadowTrackr CVSS: 4.8 | Summary: Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the component " /admin.php?action=images." |
CVE: CVE-2020-18195 | Published 2021-05-17 | CVSS: 8.8 | ShadowTrackr CVSS: 4.8 | Summary: Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via the component " /admin.php?action=page." |
CVE: CVE-2020-18194 | Published 2021-05-17 | CVSS: 6.1 | ShadowTrackr CVSS: 1.2 | Summary: Cross Site Scripting (XSS) in emlog v6.0.0 allows remote attackers to execute arbitrary code by adding a crafted script as a link to a new blog post. |
CVE: CVE-2020-18191 | Published 2020-10-02 | CVSS: 9.1 | ShadowTrackr CVSS: 7.0 | Summary: GetSimpleCMS-3.3.15 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /GetSimpleCMS-3.3.15/admin/log.php |
CVE: CVE-2020-18190 | Published 2020-10-02 | CVSS: 9.1 | ShadowTrackr CVSS: 7.0 | Summary: Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/upload-profile-picture. |