петък, 24 септември 2021 г.

Weekly Update: New diabetes clinical trial (18 items)

New diabetes clinical trial: Food as Medicine for HIV and Diabetes

Published on: August 30, 2021 at 07:00PM
Conditions:   Diabetes Mellitus, Type 2;   HIV Infections
Interventions:   Behavioral: MTM + ILI;   Behavioral: Standard MTM
Sponsors:   University of North Carolina, Chapel Hill;   Community Servings;   Massachusetts General Hospital;   National Institute of Diabetes and Digestive and Kidney Diseases (NIDDK)
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05026723?term=diabetes&sfpd_d=14 August 30, 2021 at 08:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Glycemic Response in Adults With Diabetes

Published on: August 30, 2021 at 07:00PM
Condition:   Diabetes Mellitus, Type 2
Interventions:   Other: Oral nutrition supplement - control;   Other: Oral nutrition supplement - test
Sponsor:   Nestlé
Enrolling by invitation
https://clinicaltrials.gov/ct2/show/NCT05026424?term=diabetes&sfpd_d=14 August 30, 2021 at 08:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Self-Management of Type-2 Diabetes Using a Mobile Application

Published on: August 30, 2021 at 07:00PM
Condition:   Diabetes Mellitus
Intervention:   Other: DiaMon - Mobile Application for Type 2 Diabetes mellitus and pre-diabetes
Sponsor:   University of Mauritius
Completed
https://clinicaltrials.gov/ct2/show/NCT05027334?term=diabetes&sfpd_d=14 August 30, 2021 at 08:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Randomized Controlled Trial of Digital Diabetes Self Management Education and Support for Patients With Type 2 Diabetes

Published on: August 30, 2021 at 07:00PM
Condition:   Type 2 Diabetes
Intervention:   Other: Digital diabetes self management education and support system
Sponsors:   Region Jönköping County;   Linkoeping University;   Region Östergötland;   Uppsala County Council, Sweden;   The Swedish Diabetes Foundation;   Medical Research Council of Southeast Sweden
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05026528?term=diabetes&sfpd_d=14 August 30, 2021 at 08:22PM

via ClinicalTrials.gov


New diabetes clinical trial: The Effect of SGLT-2 Inhibitor in Patient With Atrial Fibrillation and Diabetes Mellitus

Published on: August 31, 2021 at 07:00PM
Conditions:   SGLT-2 Inhibitor;   Atrial Fibrillation;   Diabetes Mellitus, Type 2
Intervention:   Drug: SGLT2 inhibitor
Sponsor:   Ewha Womans University Mokdong Hospital
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05029115?term=diabetes&sfpd_d=14 August 31, 2021 at 05:22PM

via ClinicalTrials.gov


New diabetes clinical trial: InPen User Experience

Published on: August 31, 2021 at 07:00PM
Condition:   Diabetes Type 1
Intervention:   Device: InPen with Guardian 4 System
Sponsor:   Medtronic Diabetes
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05029271?term=diabetes&sfpd_d=14 August 31, 2021 at 05:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Clinical Outcomes From Enhanced SCREENing Strategies for Advanced NASH in Type 2 Diabetes (SCREEN NASH T2D)

Published on: August 31, 2021 at 07:00PM
Conditions:   Nonalcoholic Steatohepatitis;   Type 2 Diabetes
Interventions:   Other: routine screening;   Other: physician-driven screening
Sponsor:   LMC Diabetes & Endocrinology Ltd.
Recruiting
https://clinicaltrials.gov/ct2/show/NCT05029583?term=diabetes&sfpd_d=14 August 31, 2021 at 05:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Efficacy and Safety of Piemonte Association in the Treatment of Type II Diabetes Mellitus

Published on: August 31, 2021 at 07:00PM
Condition:   Type II Diabetes
Interventions:   Drug: PIEMONTE;   Other: PIEMONTE PLACEBO;   Drug: EMPAGLIFLOZIN;   Other: PLACEBO EMPAGLIFLOZIN;   Drug: PIOGLITAZONE;   Other: PLACEBO PIOGLITAZONE
Sponsor:   EMS
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05028140?term=diabetes&sfpd_d=14 August 31, 2021 at 05:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Blood Glucose Monitoring Systems: Discounter Versus Brand

Published on: September 01, 2021 at 07:00PM
Condition:   Diabetes Mellitus
Interventions:   Diagnostic Test: blood glucose measurement: POCT;   Diagnostic Test: blood glucose measurement: reference
Sponsor:   Institut fur Diabetes Karlsburg GmbH
Enrolling by invitation
https://clinicaltrials.gov/ct2/show/NCT05031000?term=diabetes&sfpd_d=14 September 01, 2021 at 05:29PM

via ClinicalTrials.gov


New diabetes clinical trial: Time Limited Eating in Type 1 Diabetes

Published on: September 01, 2021 at 07:00PM
Condition:   Type 1 Diabetes
Intervention:   Other: Time Limited Eating
Sponsor:   Children's Hospital Los Angeles
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05031429?term=diabetes&sfpd_d=14 September 01, 2021 at 05:29PM

via ClinicalTrials.gov


New diabetes clinical trial: Effect of Walking Exercise Training on Adherence to Disease Management and Metabolic Control in Diabetes

Published on: September 01, 2021 at 07:00PM
Conditions:   Diabetes Mellitus, Type 2;   Exercise;   Walking Pneumonia;   Diabetes
Intervention:   Other: Education
Sponsor:   Ege University
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05029804?term=diabetes&sfpd_d=14 September 01, 2021 at 05:29PM

via ClinicalTrials.gov


New diabetes clinical trial: The Effect of IMB Model-Based Nursing Interventions on Care Outcomes in Adults With Type 2 Diabetes

Published on: September 01, 2021 at 07:00PM
Conditions:   Type2 Diabetes;   HbA1c;   BMI;   Self Efficacy;   Self Management
Intervention:   Behavioral: Diabetes Education and Video Call-based Motivational Interviewing
Sponsor:   Pamukkale University
Recruiting
https://clinicaltrials.gov/ct2/show/NCT05030844?term=diabetes&sfpd_d=14 September 01, 2021 at 05:29PM

via ClinicalTrials.gov


New diabetes clinical trial: Screening for Sacral Agenesis in Offspring of Mothers With Diabetes in Pregnancy

Published on: September 02, 2021 at 07:00PM
Conditions:   Infant of Diabetic Mother;   Sacral Agenesis
Intervention:  
Sponsor:   University of Missouri-Columbia
Recruiting
https://clinicaltrials.gov/ct2/show/NCT05033275?term=diabetes&sfpd_d=14 September 02, 2021 at 05:22PM

via ClinicalTrials.gov


New diabetes clinical trial: ORAL ANTIDIABETICS EFFECT ON VISCERAL FAT IN TYPE 2 DIABETES PATIENTS

Published on: September 02, 2021 at 07:00PM
Conditions:   Abdominal Obesity;   Type 2 Diabetes
Intervention:   Drug: Biguanide, DPP4 inhibitors, SGLT2 inhibitors
Sponsor:   Metabolic Research Unit
Enrolling by invitation
https://clinicaltrials.gov/ct2/show/NCT05032001?term=diabetes&sfpd_d=14 September 02, 2021 at 05:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Ladarixin as Adjunctive Therapy to Improve Insulin Sensitivity and Glucometabolic Outcomes in Type 1 Diabetes

Published on: September 06, 2021 at 07:00PM
Condition:   Type I Diabetes
Intervention:   Drug: Ladarixin
Sponsor:   Dompé Farmaceutici S.p.A
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05035368?term=diabetes&sfpd_d=14 September 05, 2021 at 06:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Comparison of the FGM Profiles in Patients of Type 2 Diabetes Treated With Sitagliptin and Acarbose

Published on: September 06, 2021 at 07:00PM
Condition:   Type 2 Diabetes
Intervention:   Drug: sitagliptin and acarbose
Sponsor:   Nanjing First Hospital, Nanjing Medical University
Completed
https://clinicaltrials.gov/ct2/show/NCT05035849?term=diabetes&sfpd_d=14 September 05, 2021 at 06:22PM

via ClinicalTrials.gov


New diabetes clinical trial: A Research Study Comparing RYBELSUS® to Other Blood Sugar Lowering Tablets in People Living in America With Type 2 Diabetes (REALYSE)

Published on: September 03, 2021 at 07:00PM
Condition:   Diabetes Mellitus, Type 2
Interventions:   Drug: semaglutide;   Drug: oral glucose-lowering medications (commercially available)
Sponsor:   Novo Nordisk A/S
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05035082?term=diabetes&sfpd_d=14 September 05, 2021 at 06:22PM

via ClinicalTrials.gov


New diabetes clinical trial: A Study to Assess the Effect of Smart Insulin Pens on Glycemic Control and Diabetes-related Burdens

Published on: September 06, 2021 at 07:00PM
Condition:   Type 1 Diabetes
Intervention:   Device: InPen®
Sponsor:   Mayo Clinic
Enrolling by invitation
https://clinicaltrials.gov/ct2/show/NCT05036343?term=diabetes&sfpd_d=14 September 05, 2021 at 06:22PM

via ClinicalTrials.gov


Weekly Update: a new vulnerability is published on the National Vulnerability Database (27 items)

New vulnerabilities from the NVD: CVE-2020-15744

Stack-based Buffer Overflow vulnerability in the ONVIF server component of Victure PC420 smart camera allows an attacker to execute remote code on the target device. This issue affects: Victure PC420 firmware version 1.2.2 and prior versions.
Published at: August 30, 2021 at 01:15PM
View on website

August 30, 2021 at 03:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18127

An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.
Published at: August 30, 2021 at 09:15PM
View on website

August 30, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18126

Multiple stored cross-site scripting (XSS) vulnerabilities in the Sections module of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.
Published at: August 30, 2021 at 09:15PM
View on website

August 30, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18125

A reflected cross-site scripting (XSS) vulnerability in the /plugin/ajax.php component of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.
Published at: August 30, 2021 at 09:15PM
View on website

August 30, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18124

A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account passwords.
Published at: August 30, 2021 at 09:15PM
View on website

August 30, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18123

A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily delete admin accounts.
Published at: August 30, 2021 at 09:15PM
View on website

August 30, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18121

A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell.
Published at: August 30, 2021 at 09:15PM
View on website

August 30, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-13639

A stored XSS vulnerability was discovered in the ECT Provider in OutSystems before 2020-09-04, affecting generated applications. It could allow an unauthenticated remote attacker to craft and store malicious Feedback content into /ECT_Provider/, such that when the content is viewed (it can only be viewed by Administrators), attacker-controlled JavaScript will execute in the security context of an administrator's browser. This is fixed in Outsystems 10.0.1005.2, Outsystems 11.9.0 Platform Server, and Outsystems 11.7.0 LifeTime Management Console.
Published at: August 31, 2021 at 07:15AM
View on website

August 31, 2021 at 08:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19049

Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Description" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-management&action=add'.
Published at: August 31, 2021 at 05:15PM
View on website

August 31, 2021 at 07:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19048

Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Title" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-management&action=add'.
Published at: August 31, 2021 at 05:15PM
View on website

August 31, 2021 at 07:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19047

Cross Site Request Forgey (CSRF) in iWebShop v5.3 allows remote atatckers to execute arbitrary code via malicious POST request to the component '/index.php?controller=system&action=admin_edit_act'.
Published at: August 31, 2021 at 05:15PM
View on website

August 31, 2021 at 07:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19046

Cross Site Scripting (XSS) in S-CMS v1.0 allows remote attackers to execute arbitrary code via the component '/admin/tpl.php?page='.
Published at: August 31, 2021 at 05:15PM
View on website

August 31, 2021 at 07:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-20486

IEC104 v1.0 contains a stack-buffer overflow in the parameter Iec10x_Sta_Addr.
Published at: September 01, 2021 at 02:15AM
View on website

September 01, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-20495

bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.
Published at: September 01, 2021 at 03:15AM
View on website

September 01, 2021 at 08:37AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-9002

An issue was discovered in iPortalis iCS 7.1.13.0. An attacker can gain privileges by intercepting a request and changing UserRoleKey=COMPANY_ADMIN to UserRoleKey=DOMAIN_ADMIN (to achieve Domain Administrator access).
Published at: September 01, 2021 at 02:15PM
View on website

September 01, 2021 at 03:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-9000

An issue was discovered in iPortalis iCS 7.1.13.0. Attackers can send a sequence of requests to rapidly cause .NET Input Validation errors. This increases the size of the log file on the remote server until memory is exhausted, therefore consuming the maximum amount of resources (triggering a denial of service condition).
Published at: September 01, 2021 at 02:15PM
View on website

September 01, 2021 at 03:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-20341

YzmCMS v5.5 contains a server-side request forgery (SSRF) in the grab_image() function.
Published at: September 01, 2021 at 11:15PM
View on website

September 02, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-20340

A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive database information.
Published at: September 01, 2021 at 11:15PM
View on website

September 02, 2021 at 01:34AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-20349

WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.
Published at: September 02, 2021 at 01:15AM
View on website

September 02, 2021 at 03:36AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-20348

WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module.
Published at: September 02, 2021 at 01:15AM
View on website

September 02, 2021 at 03:36AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-20347

WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the source field under the article management module.
Published at: September 02, 2021 at 01:15AM
View on website

September 02, 2021 at 03:36AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-20345

WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box.
Published at: September 02, 2021 at 01:15AM
View on website

September 02, 2021 at 03:36AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-20344

WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the keyword search function under the background articles module.
Published at: September 02, 2021 at 01:15AM
View on website

September 02, 2021 at 03:36AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-20343

WTCMS 1.0 contains a cross-site request forgery (CSRF) vulnerability in the index.php?g=admin&m=nav&a=add_post component that allows attackers to arbitrarily add articles in the administrator background.
Published at: September 02, 2021 at 01:15AM
View on website

September 02, 2021 at 03:36AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-13929

Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
Published at: September 02, 2021 at 08:15PM
View on website

September 02, 2021 at 09:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2019-10095

bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
Published at: September 02, 2021 at 08:15PM
View on website

September 02, 2021 at 09:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18048

An issue in craigms/main.php of CraigMS 1.0 allows attackers to execute arbitrary commands via a crafted input entered into the DB Name field.
Published at: September 02, 2021 at 09:15PM
View on website

September 02, 2021 at 11:42PM

via National Vulnerability Database


четвъртък, 23 септември 2021 г.

Weekly Update: New diabetes clinical trial (8 items)

New diabetes clinical trial: Handball-based Exercise and Type 2 Diabetes

Published on: August 23, 2021 at 07:00PM
Condition:   Type 2 Diabetes
Intervention:   Behavioral: Small-sided team handball training
Sponsors:   University College of Northern Denmark;   Danish Handball Federation;   The Danish Diabetes Association;   Research Unit of General Practice, Aalborg
Recruiting
https://clinicaltrials.gov/ct2/show/NCT05015946?term=diabetes&sfpd_d=14 August 23, 2021 at 02:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Culinary Medicine vs. Nutrition Education in Diabetes

Published on: August 24, 2021 at 07:00PM
Condition:   Primary Disease: 1. Type 2 Diabetes
Interventions:   Other: Culinary Medicine Intervention;   Other: Standard of Care Nutrition Visits
Sponsor:   University of Texas Southwestern Medical Center
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05019274?term=diabetes&sfpd_d=14 August 24, 2021 at 03:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Comparing the Compliance to Follow-up in Patients With Diabetic Macular Edema

Published on: August 25, 2021 at 07:00PM
Condition:   Diabetic Macular Edema
Interventions:   Other: WhatsApp group;   Other: Control group
Sponsor:   Lions Club International Foundation
Recruiting
https://clinicaltrials.gov/ct2/show/NCT05019807?term=diabetes&sfpd_d=14 August 25, 2021 at 04:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Fetal Cardiac Function Parameters and HbA1c as Screening for Gestational Diabetes Mellitus

Published on: August 25, 2021 at 07:00PM
Condition:   Gestational Diabetes
Intervention:  
Sponsor:   University of Virginia
Recruiting
https://clinicaltrials.gov/ct2/show/NCT05019508?term=diabetes&sfpd_d=14 August 25, 2021 at 04:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Effectiveness of The Health Care CEO App for T1D

Published on: August 26, 2021 at 07:00PM
Condition:   Type 1 Diabetes Mellitus
Interventions:   Device: Healthcare CEO app- for experimental app intervention;   Device: Healthcare CEO app-for control app intervention
Sponsors:   Chang Gung University;   Chang Gung Memorial Hospital
Recruiting
https://clinicaltrials.gov/ct2/show/NCT05022875?term=diabetes&sfpd_d=14 August 26, 2021 at 03:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Prevention of Heart Failure in Type 2 Diabetes by Exercise Intervention

Published on: August 26, 2021 at 07:00PM
Condition:   Type 2 Diabetes
Intervention:   Other: Cycling
Sponsors:   Hasselt University;   Jessa Hospital;   KU Leuven;   University Ghent
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05023538?term=diabetes&sfpd_d=14 August 26, 2021 at 03:22PM

via ClinicalTrials.gov


New diabetes clinical trial: Study to Evaluate a Prototype Non-Invasive BG Measurement System

Published on: August 27, 2021 at 07:00PM
Conditions:   Diabetes Mellitus, Type 2;   Diabetes Mellitus, Type 1
Intervention:   Device: ATD (device test)
Sponsor:   Afon Technology
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05023798?term=diabetes&sfpd_d=14 August 27, 2021 at 03:22PM

via ClinicalTrials.gov


New diabetes clinical trial: A Study of Tirzepatide (LY3298176) in Chinese Participants Without Type 2 Diabetes Who Have Obesity or Overweight (SURMOUNT-CN)

Published on: August 27, 2021 at 07:00PM
Conditions:   Obesity;   Overweight;   Metabolism and Nutrition Disorder
Interventions:   Drug: Tirzepatide;   Drug: Placebo
Sponsor:   Eli Lilly and Company
Not yet recruiting
https://clinicaltrials.gov/ct2/show/NCT05024032?term=diabetes&sfpd_d=14 August 27, 2021 at 03:22PM

via ClinicalTrials.gov



Weekly Update: a new vulnerability is published on the National Vulnerability Database (40 items)

New vulnerabilities from the NVD: CVE-2020-18735

A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
Published at: August 24, 2021 at 12:15AM
View on website

August 24, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18734

A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
Published at: August 24, 2021 at 12:15AM
View on website

August 24, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18731

A segmentation violation in the Iec104_Deal_FirmUpdate function of IEC104 v1.0 allows attackers to cause a denial of service (DOS).
Published at: August 24, 2021 at 12:15AM
View on website

August 24, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18730

A segmentation violation in the Iec104_Deal_I function of IEC104 v1.0 allows attackers to cause a denial of service (DOS).
Published at: August 24, 2021 at 12:15AM
View on website

August 24, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18778

In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_p_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
Published at: August 24, 2021 at 01:15AM
View on website

August 24, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18776

In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
Published at: August 24, 2021 at 01:15AM
View on website

August 24, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18775

In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
Published at: August 24, 2021 at 01:15AM
View on website

August 24, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18774

A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.
Published at: August 24, 2021 at 01:15AM
View on website

August 24, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18773

An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.
Published at: August 24, 2021 at 01:15AM
View on website

August 24, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18771

Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
Published at: August 24, 2021 at 01:15AM
View on website

August 24, 2021 at 03:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18917

The plus/search.php component in DedeCMS 5.7 SP2 allows remote attackers to execute arbitrary PHP code via the typename parameter because the contents of typename.inc are under an attacker's control.
Published at: August 24, 2021 at 11:15PM
View on website

August 25, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18913

EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers to access sensitive database information.
Published at: August 24, 2021 at 11:15PM
View on website

August 25, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2018-10790

The AP4_CttsAtom class in Core/Ap4CttsAtom.cpp in Bento4 1.5.1.0 allows remote attackers to cause a denial of service (application crash), related to a memory allocation failure, as demonstrated by mp2aac.
Published at: August 25, 2021 at 05:15PM
View on website

August 25, 2021 at 07:35PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18976

Buffer Overflow in Tcpreplay v4.3.2 allows attackers to cause a Denial of Service via the 'do_checksum' function in 'checksum.c'. It can be triggered by sending a crafted pcap file to the 'tcpreplay-edit' binary. This issue is different than CVE-2019-8381.
Published at: August 25, 2021 at 07:15PM
View on website

August 25, 2021 at 09:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18974

Buffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the component 'nasmlib/crc64'. This issue is different than CVE-2019-7147.
Published at: August 25, 2021 at 07:15PM
View on website

August 25, 2021 at 09:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18972

Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.
Published at: August 25, 2021 at 07:15PM
View on website

August 25, 2021 at 09:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18971

Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/PdfDictionary.cpp:65'.
Published at: August 25, 2021 at 07:15PM
View on website

August 25, 2021 at 09:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19547

Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php.
Published at: August 25, 2021 at 11:15PM
View on website

August 26, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18065

Cross Site Scripting (XSS) vulnerability exists in PopojiCMS 2.0.1 in admin.php?mod=menumanager--------- edit menu.
Published at: August 25, 2021 at 11:15PM
View on website

August 26, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19822

A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.
Published at: August 26, 2021 at 06:15AM
View on website

August 26, 2021 at 08:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19821

A SQL injection vulnerability in admin.php of DOYOCMS 2.3 allows attackers to execute arbitrary SQL commands via the orders[] parameter.
Published at: August 26, 2021 at 06:15AM
View on website

August 26, 2021 at 08:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19709

Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.
Published at: August 26, 2021 at 06:15AM
View on website

August 26, 2021 at 08:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19705

thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.
Published at: August 26, 2021 at 06:15AM
View on website

August 26, 2021 at 08:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19704

A stored cross-site scripting (XSS) vulnerability via ResourceController.java in spring-boot-admin as of 20190710 allows attackers to execute arbitrary web scripts or HTML.
Published at: August 26, 2021 at 06:15AM
View on website

August 26, 2021 at 08:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19703

A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Published at: August 26, 2021 at 06:15AM
View on website

August 26, 2021 at 08:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-14161

It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint.
Published at: August 26, 2021 at 02:15PM
View on website

August 26, 2021 at 03:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-14160

An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read local files or fetch intranet resources.
Published at: August 26, 2021 at 02:15PM
View on website

August 26, 2021 at 03:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18477

SQL Injection vulnerability in Hucart CMS 5.7.4 via the purchase enquiry field found in the Message con_content field.
Published at: August 26, 2021 at 09:15PM
View on website

August 26, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18476

SQL Injection vulnerability in Hucart CMS 5.7.4 via the basic information field found in the avatar usd_image field.
Published at: August 26, 2021 at 09:15PM
View on website

August 26, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18475

Cross Site Scripting (XSS) vulnerabilty exists in Hucart CMS 5.7.4 is via the mes_title field. The first user inserts a malicious script into the header field of the outbox and sends it to other users. When other users open the email, the malicious code will be executed.
Published at: August 26, 2021 at 09:15PM
View on website

August 26, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18470

Stored cross-site scripting (XSS) vulnerability in the Name of application field found in the General Configuration page in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to rukovoditel_2.4.1/install/index.php.
Published at: August 26, 2021 at 09:15PM
View on website

August 26, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18469

Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to /rukovoditel_2.4.1/index.php?module=configuration/save&redirect_to=configuration/application.
Published at: August 26, 2021 at 09:15PM
View on website

August 26, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18468

Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted website name by doing an authenticated POST HTTP request to /qdPM_9.1/index.php/configuration.
Published at: August 26, 2021 at 09:15PM
View on website

August 26, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18467

Cross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under the General menu via a crafted website name by doing an authenticated POST HTTP request to admin/tags/create.
Published at: August 26, 2021 at 09:15PM
View on website

August 26, 2021 at 11:34PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-19000

Cross Site Scripting (XSS) in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary code via line 54 of the component 'simiki/blob/master/simiki/generators.py'.
Published at: August 27, 2021 at 10:15PM
View on website

August 27, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18999

Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/submit-articles'.
Published at: August 27, 2021 at 10:15PM
View on website

August 27, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18998

Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/custom/blog-plugin/add'.
Published at: August 27, 2021 at 10:15PM
View on website

August 27, 2021 at 11:33PM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18116

A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL injection.
Published at: August 28, 2021 at 12:15AM
View on website

August 28, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18114

An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
Published at: August 28, 2021 at 12:15AM
View on website

August 28, 2021 at 01:33AM

via National Vulnerability Database


New vulnerabilities from the NVD: CVE-2020-18106

The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection.
Published at: August 27, 2021 at 11:15PM
View on website

August 28, 2021 at 01:33AM

via National Vulnerability Database