Skip to content

Commit a90de4f

Browse files
Update Tue Jul 14 12:46:48 UTC 2026
1 parent 3485145 commit a90de4f

333 files changed

Lines changed: 3465 additions & 100 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

2011/CVE-2011-4203.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
### [CVE-2011-4203](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4203)
2+
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
3+
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen)
4+
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen)
5+
6+
### Description
7+
8+
CRLF injection vulnerability in calendar/set.php in the Calendar component in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, 2.1.x before 2.1.3, and 2.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors involving the url variable.
9+
10+
### POC
11+
12+
#### Reference
13+
- http://tracker.moodle.org/browse/MDL-24808
14+
15+
#### Github
16+
No PoCs found on GitHub currently.
17+

2017/CVE-2017-6920.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary
1010
### POC
1111

1212
#### Reference
13-
No PoCs from references.
13+
- https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-06-21/drupal-core-multiple
1414

1515
#### Github
1616
- https://github.com/ARPSyndicate/cvemon

2017/CVE-2017-6921.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
### [CVE-2017-6921](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6921)
2+
![](https://img.shields.io/static/v1?label=Product&message=Drupal%20Core&color=blue)
3+
![](https://img.shields.io/static/v1?label=Version&message=Drupal%208%20&color=brightgreen)
4+
![](https://img.shields.io/static/v1?label=Vulnerability&message=Access%20Bypass&color=brightgreen)
5+
6+
### Description
7+
8+
In Drupal 8 prior to 8.3.4; The file REST resource does not properly validate some fields when manipulating files. A site is only affected by this if the site has the RESTful Web Services (rest) module enabled, the file REST resource is enabled and allows PATCH requests, and an attacker can get or register a user account on the site with permissions to upload files and to modify the file resource.
9+
10+
### POC
11+
12+
#### Reference
13+
- https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-06-21/drupal-core-multiple
14+
15+
#### Github
16+
No PoCs found on GitHub currently.
17+

2017/CVE-2017-6922.md

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
### [CVE-2017-6922](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6922)
2+
![](https://img.shields.io/static/v1?label=Product&message=Drupal%20Core&color=blue)
3+
![](https://img.shields.io/static/v1?label=Version&message=Drupal%207%20&color=brightgreen)
4+
![](https://img.shields.io/static/v1?label=Version&message=Drupal%208%20&color=brightgreen)
5+
![](https://img.shields.io/static/v1?label=Vulnerability&message=Access%20Bypass&color=brightgreen)
6+
7+
### Description
8+
9+
In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site should only be visible to the anonymous user that uploaded them, rather than all anonymous users. Drupal core did not previously provide this protection, allowing an access bypass vulnerability to occur. This issue is mitigated by the fact that in order to be affected, the site must allow anonymous users to upload files into a private file system.
10+
11+
### POC
12+
13+
#### Reference
14+
- https://www.drupal.org/forum/newsletters/security-advisories-for-drupal-core/2017-06-21/drupal-core-multiple
15+
16+
#### Github
17+
No PoCs found on GitHub currently.
18+

2018/CVE-2018-25340.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@ Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated a
1010
### POC
1111

1212
#### Reference
13+
- https://github.com/smakosh/Smartshop/archive/master.zip
1314
- https://www.exploit-db.com/exploits/44823
1415

1516
#### Github

2018/CVE-2018-25341.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@ Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated a
1010
### POC
1111

1212
#### Reference
13+
- https://github.com/smakosh/Smartshop/archive/master.zip
1314
- https://www.exploit-db.com/exploits/44823
1415

1516
#### Github

2018/CVE-2018-25342.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@ Smartshop 1 contains a time-based blind SQL injection vulnerability that allows
1010
### POC
1111

1212
#### Reference
13+
- https://github.com/smakosh/Smartshop/archive/master.zip
1314
- https://www.exploit-db.com/exploits/44823
1415

1516
#### Github

2018/CVE-2018-25343.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@ Smartshop 1 contains a cross-site request forgery vulnerability that allows atta
1010
### POC
1111

1212
#### Reference
13+
- https://github.com/smakosh/Smartshop/archive/master.zip
1314
- https://www.exploit-db.com/exploits/44824
1415

1516
#### Github

2020/CVE-2020-25900.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
### [CVE-2020-25900](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25900)
2+
![](https://img.shields.io/static/v1?label=Product&message=HelloTalk&color=blue)
3+
![](https://img.shields.io/static/v1?label=Version&message=0%20&color=brightgreen)
4+
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-359%20Exposure%20of%20Private%20Personal%20Information%20to%20an%20Unauthorized%20Actor&color=brightgreen)
5+
6+
### Description
7+
8+
HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, these coordinates are placed into a database on the client of other users. (The client side was changed in 2019 to encrypt that database.)
9+
10+
### POC
11+
12+
#### Reference
13+
- https://isopach.dev/CVE-2020-25900/
14+
15+
#### Github
16+
No PoCs found on GitHub currently.
17+

2020/CVE-2020-35803.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
### [CVE-2020-35803](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35803)
2+
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
3+
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen)
4+
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen)
5+
6+
### Description
7+
8+
Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D6200 before 1.1.00.40, D7000 before 1.0.1.78, R6020 before 1.0.0.46, R6080 before 1.0.0.46, R6120 before 1.0.0.72, R6220 before 1.1.0.100, R6230 before 1.1.0.100, R6260 before 1.1.0.76, R6700v2 before 1.2.0.74, R6800 before 1.2.0.74, R6900v2 before 1.2.0.74, R7450 before 1.2.0.74, AC2100 before 1.2.0.74, AC2400 before 1.2.0.74, and AC2600 before 1.2.0.74.
9+
10+
### POC
11+
12+
#### Reference
13+
- https://kb.netgear.com/000062732/Security-Advisory-for-Sensitive-Information-Disclosure-on-Some-Routers-PSV-2019-0110
14+
15+
#### Github
16+
No PoCs found on GitHub currently.
17+

0 commit comments

Comments
 (0)