|
211211
|
5.3 |
MEDIUM
Network
|
xiuno
|
xiunobbs
|
An issue in the component route\user.php of Xiuno BBS v4.0.4 allows attackers to enumerate usernames.
|
NVD-CWE-noinfo
|
CVE-2020-21493
|
2024-11-21 14:12 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211212
|
5.4 |
MEDIUM
Network
|
maccms
|
maccms
|
Maccms 10 contains a cross-site scripting (XSS) vulnerability in the Editing function under the Member module. This vulnerability is exploited via a crafted payload in the nickname text field.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21434
|
2024-11-21 14:12 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211213
|
6.5 |
MEDIUM
Network
|
hongcms_project
|
hongcms
|
HongCMS v3.0 contains an arbitrary file read and write vulnerability in the component /admin/index.php/template/edit.
|
NVD-CWE-noinfo
|
CVE-2020-21431
|
2024-11-21 14:12 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211214
|
6.1 |
MEDIUM
Network
|
maccms
|
maccms
|
A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and escalate privileges via a crafted payload.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21387
|
2024-11-21 14:12 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211215
|
8.8 |
HIGH
Network
|
maccms
|
maccms
|
A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges.
|
CWE-352
Origin Validation Error
|
CVE-2020-21386
|
2024-11-21 14:12 |
2021-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211216
|
6.1 |
MEDIUM
Network
|
jizhicms
|
jizhicms
|
JIZHICMS 1.5.1 contains a cross-site scripting (XSS) vulnerability in the component /user/release.html, which allows attackers to arbitrarily add an administrator cookie.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21228
|
2024-11-21 14:12 |
2021-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211217
|
6.5 |
MEDIUM
Network
|
emlog
|
emlog
|
emlog v6.0.0 contains an arbitrary file deletion vulnerability in admin/plugin.php.
|
NVD-CWE-noinfo
|
CVE-2020-21014
|
2024-11-21 14:12 |
2021-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211218
|
7.2 |
HIGH
Network
|
emlog
|
emlog
|
emlog v6.0.0 contains a SQL injection via /admin/comment.php.
|
CWE-89
SQL Injection
|
CVE-2020-21013
|
2024-11-21 14:12 |
2021-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211219
|
9.8 |
CRITICAL
Network
|
hotel_and_lodge_booking_management_system_project
|
hotel_and_lodge_booking_management_system
|
Sourcecodester Hotel and Lodge Management System 2.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the email parameter to the edi…
|
CWE-89
SQL Injection
|
CVE-2020-21012
|
2024-11-21 14:12 |
2021-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211220
|
5.4 |
MEDIUM
Network
|
jeecms
|
jeecms
|
JeeCMS 1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the commentText parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20799
|
2024-11-21 14:12 |
2021-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|