• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors

CWE-79

CVE-2020-25163

February 26, 2023 by

A remote attacker with write access to PI ProcessBook files could inject code that is imported into OSIsoft PI Vision 2020 versions prior to 3.5.0. Unauthorized information disclosure, modification, or deletion is also possible if a victim views or interacts with the infected display. This vulnerability affects PI System data and other data accessible with victim’s user permissions.

CVE-2020-25102

February 26, 2023 by

silverstripe-advancedreports (aka the Advanced Reports module for SilverStripe) 1.0 through 2.0 is vulnerable to Cross-Site Scripting (XSS) because it is possible to inject and store malicious JavaScript code. The affects admin/advanced-reports/DataObjectReport/EditForm/field/DataObjectReport/item (aka report preview) when an SVG document is provided in the Description parameter.

CVE-2020-25104

February 26, 2023 by

eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For example, the filename has a complete XSS payload followed by the .png extension.

CVE-2020-25115

February 26, 2023 by

The Admin CP in vBulletin 5.6.3 allows XSS via an Occupation Title or Description to User Profile Field Manager.

CVE-2020-25116

February 26, 2023 by

The Admin CP in vBulletin 5.6.3 allows XSS via an Announcement Title to Channel Manager.

CVE-2020-25117

February 26, 2023 by

The Admin CP in vBulletin 5.6.3 allows XSS via a Junior Member Title to User Title Manager.

  • « Go to Previous Page
  • Go to page 1
  • Interim pages omitted …
  • Go to page 755
  • Go to page 756
  • Go to page 757
  • Go to page 758
  • Go to page 759
  • Interim pages omitted …
  • Go to page 2216
  • Go to Next Page »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE