|
211751
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
The gf_dash_segmenter_probe_input function in GPAC v0.8 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-22352
|
2024-11-21 14:13 |
2021-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211752
|
6.1 |
MEDIUM
Network
|
nukeviet
|
nukeviet
|
Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22765
|
2024-11-21 14:13 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211753
|
8.8 |
HIGH
Network
|
flatpress
|
flatpress
|
Cross Site Request Forgery (CSRF) vulnerability in FlatPress 1.1 via the DeleteFile function in flat/admin.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-22761
|
2024-11-21 14:13 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211754
|
4.8 |
MEDIUM
Network
|
naviwebs
|
navigatecms
|
Cross Site Scripting (XSS) vulnerability in NavigateCMS NavigateCMS 2.9 via the name="wrong_path_redirect" feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23243
|
2024-11-21 14:13 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211755
|
4.8 |
MEDIUM
Network
|
naviwebs
|
navigatecms
|
Cross Site Scripting (XSS) vulnerability in NavigateCMS 2.9 when performing a Create or Edit via the Tools feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23242
|
2024-11-21 14:13 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211756
|
4.8 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.14 in "Extra" via 'News > Article" feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23241
|
2024-11-21 14:13 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211757
|
4.8 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
Cross Site Scripting (XSS) vulnerablity in CMS Made Simple 2.2.14 via the Logic field in the Content Manager feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23240
|
2024-11-21 14:13 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211758
|
4.8 |
MEDIUM
Network
|
textpattern
|
textpattern
|
Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23239
|
2024-11-21 14:13 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211759
|
5.4 |
MEDIUM
Network
|
evo
|
evolution_cms
|
Cross Site Scripting (XSS) vulnerability in Evolution CMS 2.0.2 via the Document Manager feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23238
|
2024-11-21 14:13 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211760
|
4.8 |
MEDIUM
Network
|
lavalite
|
lavalite
|
Cross Site Scripting (XSS) vulnerabiity exists in LavaLite CMS 5.8.0 via the Menu Blocks feature, which can be bypassed by using HTML event handlers, such as "ontoggle,".
|
CWE-79
Cross-site Scripting
|
CVE-2020-23234
|
2024-11-21 14:13 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|