CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1380, CVE-2020-1570.
SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.
SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.
SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.
We-com OpenData CMS 2.0 allows SQL Injection via the username field on the administrator login page.
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1379, CVE-2020-1477, CVE-2020-1478, CVE-2020-1492, CVE-2020-1525.
SQL injection can occur in We-com Municipality portal CMS 2.1.x via the cerca/ keywords field.
XSS can occur in We-com Municipality portal CMS 2.1.x via the cerca/ search bar.
An issue was discovered in the Vanguard plugin 2.1 for WordPress. XSS can occur via the mails/new title field, a product field to the p/ URI, or the Products Search box.
An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can occur via any of the registration fields.
