
Look up vulnerabilities by software, product or CVE number.
| CVE | Published | CVSS | ShadowTrackr CVSS | Summary |
|---|---|---|---|---|
CVE: CVE-2020-36829 | Published 2024-04-07 | CVSS: 7.5 | ShadowTrackr CVSS: 4.6 | Summary: The Mojolicious module before 8.65 for Perl is vulnerable to secure_compare timing attacks that allow an attacker to guess the length of a secret string. Only versions after 1.74 are affected. |
CVE: CVE-2020-36828 | Published 2024-03-31 | CVSS: 3.5 | ShadowTrackr CVSS: 0.4 | Summary: A vulnerability was found in DiscuzX up to 3.4-20200818. It has been classified as problematic. Affected is the function show_next_step of the file upload/install/include/install_function.php. The manipulation of the argument uchidden leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 3.4-20210119 is able to address this issue. The name of the patch is 4a9673624f46f7609486778ded9653733020c567. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-258612. |
CVE: CVE-2020-36826 | Published 2024-03-25 | CVSS: 3.5 | ShadowTrackr CVSS: 0.4 | Summary: A vulnerability was found in AwesomestCode LiveBot. It has been classified as problematic. Affected is the function parseSend of the file js/parseMessage.js. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. Upgrading to version 0.1 is able to address this issue. The name of the patch is 57505527f838d1e46e8f93d567ba552a30185bfa. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-257784. |
CVE: CVE-2020-36825 | Published 2024-03-24 | CVSS: 5.3 | ShadowTrackr CVSS: 2.1 | Summary: ** UNSUPPORTED WHEN ASSIGNED ** ** DISPUTED ** A vulnerability has been found in cyberaz0r WebRAT up to 20191222 and classified as critical. This vulnerability affects the function download_file of the file Server/api.php. The manipulation of the argument name leads to unrestricted upload. The attack can be initiated remotely. The real existence of this vulnerability is still doubted at the moment. The patch is identified as 0c394a795b9c10c07085361e6fcea286ee793701. It is recommended to apply a patch to fix this issue. VDB-257782 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: The issue, discovered in a 20-stars GitHub project (now private) by its author, had CVE requested by a third party 4 years post-resolution, referencing the fix commit (now a broken link). Due to minimal attention and usage, it should not be eligible for CVE according to the project maintainer. |
CVE: CVE-2020-36827 | Published 2024-03-24 | CVSS: 5.4 | ShadowTrackr CVSS: 1.3 | Summary: The XAO::Web module before 1.84 for Perl mishandles < and > characters in JSON output during use of json-embed in Web::Action. |
CVE: CVE-2020-3682 | Published 2021-12-20 | CVSS: - | ShadowTrackr CVSS: 0.0 | Summary: |
CVE: CVE-2020-36820 | Published | CVSS: - | ShadowTrackr CVSS: 0.0 | Summary: |
CVE: CVE-2020-36821 | Published | CVSS: - | ShadowTrackr CVSS: 0.0 | Summary: |
CVE: CVE-2020-36824 | Published | CVSS: - | ShadowTrackr CVSS: 0.0 | Summary: |
CVE: CVE-2020-36823 | Published | CVSS: - | ShadowTrackr CVSS: 0.0 | Summary: |
CVE: CVE-2020-36822 | Published | CVSS: - | ShadowTrackr CVSS: 0.0 | Summary: |