|
209651
|
5.4 |
MEDIUM
Network
|
create-project_manager_project
|
create-project_manager
|
Create-Project Manager 1.07 has Multi Persistent Cross-site Scripting and HTML injection in via Online chat, Social feed,Message(title-tag), Add new client (all-tags).
|
CWE-79
Cross-site Scripting
|
CVE-2020-23974
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209652
|
9.8 |
CRITICAL
Network
|
kandnconcepts_club_cms_project
|
kandnconcepts_club_cms
|
KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.
|
CWE-89
SQL Injection
|
CVE-2020-23973
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209653
|
7.5 |
HIGH
Network
|
gmapfp
|
gmapfp
|
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricte…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-23972
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209654
|
9.8 |
CRITICAL
Network
|
designmasterevents
|
conference_management
|
DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.
|
CWE-89
SQL Injection
|
CVE-2020-23980
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209655
|
5.3 |
MEDIUM
Network
|
ericom
|
access_server
|
Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and provides "Cannot connect to" error messages to infor…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-24548
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209656
|
6.1 |
MEDIUM
Network
|
admin_menu_project
|
admin_menu
|
WP Plugin Rednumber Admin Menu v1.1 and lower does not sanitize the value of the "role" GET parameter before echoing it back out to the user. This results in a reflected XSS vulnerability that attack…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24316
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209657
|
7.5 |
HIGH
Network
|
wordpress_poll_project
|
wordpress_poll
|
Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to a lack of user input escaping. This allows users who craft specific SQL stateme…
|
CWE-89
SQL Injection
|
CVE-2020-24315
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209658
|
5.3 |
MEDIUM
Network
|
umanni
|
human_resources
|
Umanni RH 1.0 has a user enumeration vulnerability. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabli…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-24008
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209659
|
9.8 |
CRITICAL
Network
|
umanni
|
human_resources
|
Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-24007
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209660
|
6.1 |
MEDIUM
Network
|
rss_feed_widget_project
|
rss_feed_widget
|
Fahad Mahmood RSS Feed Widget Plugin v2.7.9 and lower does not sanitize the value of the "t" GET parameter before echoing it back out inside an input tag. This results in a reflected XSS vulnerabilit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24314
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|