|
210061
|
6.1 |
MEDIUM
Network
|
5none
|
nonecms
|
Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remote attackers to inject arbitrary web script or HTML via the…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23371
|
2024-11-21 14:13 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210062
|
5.4 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected wit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23370
|
2024-11-21 14:13 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210063
|
6.1 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
In YzmCMS 5.6, XSS was discovered in member/member_content/init.html via the SRC attribute of an IFRAME element because of using UEditor 1.4.3.3.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23369
|
2024-11-21 14:13 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210064
|
7.8 |
HIGH
Local
|
windscribe
|
windscribe
|
In Windscribe v1.83 Build 20, 'WindscribeService' has an Unquoted Service Path that facilitates privilege escalation.
|
CWE-428
Unquoted Search Path or Element
|
CVE-2020-22809
|
2024-11-21 14:13 |
2021-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210065
|
8.8 |
HIGH
Network
|
fork-cms
|
fork_cms
|
Cross-site request forgery (CSRF) in Fork-CMS before 5.8.2 allow remote attackers to hijack the authentication of logged administrators.
|
CWE-352
Origin Validation Error
|
CVE-2020-23264
|
2024-11-21 14:13 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210066
|
6.1 |
MEDIUM
Network
|
fork-cms
|
fork_cms
|
Persistent Cross-site scripting vulnerability on Fork CMS version 5.8.2 allows remote attackers to inject arbitrary Javascript code via the "navigation_title" parameter and the "title" parameter in /…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23263
|
2024-11-21 14:13 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210067
|
4.9 |
MEDIUM
Network
|
chamilo
|
chamilo_lms
|
Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to …
|
CWE-269
Improper Privilege Management
|
CVE-2020-23128
|
2024-11-21 14:13 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210068
|
8.8 |
HIGH
Network
|
chamilo
|
chamilo_lms
|
Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.
|
CWE-352
Origin Validation Error
|
CVE-2020-23127
|
2024-11-21 14:13 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210069
|
4.8 |
MEDIUM
Network
|
solarwinds
|
serv-u_ftp_server serv-u_mft_server
|
SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22428
|
2024-11-21 14:13 |
2021-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210070
|
9.8 |
CRITICAL
Network
|
guojusoft
|
jeecg
|
Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?common…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-23083
|
2024-11-21 14:13 |
2021-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|