|
210341
|
5.5 |
MEDIUM
Local
|
xfig_project debian
|
fig2dev debian_linux
|
fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21529
|
2024-11-21 14:12 |
2021-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210342
|
7.2 |
HIGH
Network
|
jizhicms
|
jizhicms
|
An arbitrary file upload vulnerability in Jizhicms v1.5 allows attackers to execute arbitrary code via a crafted .jpg file which is later changed to a PHP file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21483
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210343
|
5.4 |
MEDIUM
Network
|
rgcms_project
|
rgcms
|
A cross-site scripting (XSS) vulnerability in RGCMS v1.06 allows attackers to obtain the administrator's cookie via a crafted payload in the Name field under the Message Board module
|
CWE-79
Cross-site Scripting
|
CVE-2020-21482
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210344
|
7.2 |
HIGH
Network
|
rgcms_project
|
rgcms
|
An arbitrary file upload vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted .txt file which is later changed to a PHP file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21481
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210345
|
7.2 |
HIGH
Network
|
rgcms_project
|
rgcms
|
An arbitrary file write vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted PHP file.
|
NVD-CWE-noinfo
|
CVE-2020-21480
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210346
|
9.8 |
CRITICAL
Network
|
feehi
|
feehicms
|
An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21322
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210347
|
4.3 |
MEDIUM
Network
|
emlog
|
emlog
|
emlog v6.0 contains a Cross-Site Request Forgery (CSRF) via /admin/link.php?action=addlink, which allows attackers to arbitrarily add articles.
|
CWE-352
Origin Validation Error
|
CVE-2020-21321
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210348
|
9.8 |
CRITICAL
Network
|
metinfo
|
metinfo
|
MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel.
|
CWE-89
SQL Injection
|
CVE-2020-21127
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210349
|
8.8 |
HIGH
Network
|
metinfo
|
metinfo
|
MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo.
|
CWE-352
Origin Validation Error
|
CVE-2020-21126
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210350
|
9.8 |
CRITICAL
Network
|
ureport_project
|
ureport
|
An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code.
|
NVD-CWE-noinfo
|
CVE-2020-21125
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|