|
210351
|
9.8 |
CRITICAL
Network
|
ureport_project
|
ureport
|
UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page.
|
CWE-863
Incorrect Authorization
|
CVE-2020-21124
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210352
|
5.3 |
MEDIUM
Network
|
ureport_project
|
ureport
|
UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-21122
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210353
|
9.8 |
CRITICAL
Network
|
kliqqi
|
kliqqi_cms
|
Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_module_widgets.php file.
|
CWE-89
SQL Injection
|
CVE-2020-21121
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210354
|
6.1 |
MEDIUM
Network
|
maccms
|
maccms
|
A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows attackers to steal administrator and user cookies via crafted payloads in the…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21082
|
2024-11-21 14:12 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210355
|
6.5 |
MEDIUM
Network
|
maccms
|
maccms
|
A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.
|
CWE-352
Origin Validation Error
|
CVE-2020-21081
|
2024-11-21 14:12 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210356
|
7.8 |
HIGH
Local
|
kitesky
|
kitecms
|
An arbitrary file upload vulnerability in /admin/upload/uploadfile of KiteCMS V1.1 allows attackers to getshell via a crafted PHP file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20672
|
2024-11-21 14:12 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210357
|
8.8 |
HIGH
Network
|
kitesky
|
kitecms
|
A cross-site request forgery (CSRF) in KiteCMS V1.1 allows attackers to arbitrarily add an administrator account.
|
CWE-352
Origin Validation Error
|
CVE-2020-20671
|
2024-11-21 14:12 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210358
|
8.8 |
HIGH
Network
|
zkea
|
zkeacms
|
An arbitrary file upload vulnerability in /admin/media/upload of ZKEACMS V3.2.0 allows attackers to execute arbitrary code via a crafted HTML file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20670
|
2024-11-21 14:12 |
2021-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210359
|
5.4 |
MEDIUM
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link address field under the background links module.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20349
|
2024-11-21 14:12 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210360
|
5.4 |
MEDIUM
Network
|
wtcms_project
|
wtcms
|
WTCMS 1.0 contains a stored cross-site scripting (XSS) vulnerability in the link field under the background menu management module.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20348
|
2024-11-21 14:12 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|