|
200531
|
5.4 |
MEDIUM
Network
|
valine.js
|
valine
|
Cross Site Scripting (XSS) vulnerability in xCss Valine v1.4.14 via the nick parameter to /classes/Comment.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28847
|
2024-11-21 14:23 |
2022-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200532
|
7.2 |
HIGH
Network
|
liferay
|
liferay_portal
|
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject commands through the Gogo Shell module to execute any OS command on the Life…
|
CWE-78
OS Command
|
CVE-2020-28885
|
2024-11-21 14:23 |
2022-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200533
|
7.2 |
HIGH
Network
|
liferay
|
liferay_portal
|
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute any OS command on the Liferay Portal Sever. NOTE: T…
|
CWE-78
OS Command
|
CVE-2020-28884
|
2024-11-21 14:23 |
2022-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200534
|
5.4 |
MEDIUM
Network
|
checkmk
|
checkmk
|
A stored cross site scripting (XSS) vulnerability in Checkmk 1.6.0x prior to 1.6.0p19 allows an authenticated remote attacker to inject arbitrary JavaScript via a javascript: URL in a view title.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28919
|
2024-11-21 14:23 |
2022-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200535
|
8.8 |
HIGH
Network
|
zohocorp
|
manageengine_applications_manager
|
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
|
CWE-89
SQL Injection
|
CVE-2020-28679
|
2024-11-21 14:23 |
2022-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200536
|
7.5 |
HIGH
Network
|
sphinxsearch debian
|
sphinx debian_linux
|
SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operation…
|
CWE-22
Path Traversal
|
CVE-2020-29050
|
2024-11-21 14:23 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200537
|
6.5 |
MEDIUM
Network
|
iball
|
wrd12en_firmware
|
iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range for IP addresses.
|
CWE-352
Origin Validation Error
|
CVE-2020-29292
|
2024-11-21 14:23 |
2021-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200538
|
9.1 |
CRITICAL
Network
|
zblogcn
|
z-blogphp
|
Z-BlogPHP v1.6.1.2100 was discovered to contain an arbitrary file deletion vulnerability via \app_del.php.
|
NVD-CWE-Other
|
CVE-2020-29177
|
2024-11-21 14:23 |
2021-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200539
|
7.8 |
HIGH
Local
|
zblogcn
|
z-blogphp
|
An arbitrary file upload vulnerability in Z-BlogPHP v1.6.1.2100 allows attackers to execute arbitrary code via a crafted JPG file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-29176
|
2024-11-21 14:23 |
2021-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200540
|
7.5 |
HIGH
Network
|
pybbs_project
|
pybbs
|
A SQL injection vulnerability in TopicMapper.xml of PybbsCMS v5.2.1 allows attackers to access sensitive database information.
|
CWE-89
SQL Injection
|
CVE-2020-28702
|
2024-11-21 14:23 |
2021-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|