|
196511
|
8.8 |
HIGH
Network
|
cutephp
|
cutenews
|
CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2020-5558
|
2024-11-21 14:34 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196512
|
6.1 |
MEDIUM
Network
|
cutephp
|
cutenews
|
Cross-site scripting vulnerability in CuteNews 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5557
|
2024-11-21 14:34 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196513
|
9.8 |
CRITICAL
Network
|
shihonkanri_plus_goout_project
|
shihonkanri_plus_goout
|
Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2020-5556
|
2024-11-21 14:34 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196514
|
9.1 |
CRITICAL
Network
|
shihonkanri_plus_goout_project
|
shihonkanri_plus_goout
|
Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to read and write data of the files placed in the same directory where it is placed via unspecified vector due to the improper in…
|
CWE-20
Improper Input Validation
|
CVE-2020-5555
|
2024-11-21 14:34 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196515
|
9.1 |
CRITICAL
Network
|
shihonkanri_plus_goout_project
|
shihonkanri_plus_goout
|
Directory traversal vulnerability in Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to read and write arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2020-5554
|
2024-11-21 14:34 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196516
|
9.8 |
CRITICAL
Network
|
mailform
|
mailform
|
mailform version 1.04 allows remote attackers to execute arbitrary PHP code via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2020-5553
|
2024-11-21 14:34 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196517
|
6.1 |
MEDIUM
Network
|
mailform
|
mailform
|
Cross-site scripting vulnerability in mailform version 1.04 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5552
|
2024-11-21 14:34 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196518
|
9.8 |
CRITICAL
Network
|
grandstream
|
ucm6200_firmware
|
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. An attacker can use this vulnerability to execute shell command…
|
CWE-89
SQL Injection
|
CVE-2020-5722
|
2024-11-21 14:34 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196519
|
7.2 |
HIGH
Network
|
artica
|
pandora_fms
|
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators to upload malicious PHP scripts, and execute them via base64 decoding of the fil…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-5844
|
2024-11-21 14:34 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196520
|
9.8 |
CRITICAL
Network
|
mitsubishielectric
|
iu1-1m20-d_firmware
|
Resource Management Errors vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows remote attackers to sto…
|
NVD-CWE-noinfo
|
CVE-2020-5547
|
2024-11-21 14:34 |
2020-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|