|
197781
|
5.4 |
MEDIUM
Network
|
rukovoditel
|
rukovoditel
|
A stored cross site scripting (XSS) vulnerability in the 'Users Access Groups' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted paylo…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35986
|
2024-11-21 14:28 |
2021-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197782
|
5.4 |
MEDIUM
Network
|
rukovoditel
|
rukovoditel
|
A stored cross site scripting (XSS) vulnerability in the 'Global Lists" feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload ente…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35985
|
2024-11-21 14:28 |
2021-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197783
|
5.4 |
MEDIUM
Network
|
rukovoditel
|
rukovoditel
|
A stored cross site scripting (XSS) vulnerability in the 'Users Alerts' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload ente…
|
CWE-79
Cross-site Scripting
|
CVE-2020-35984
|
2024-11-21 14:28 |
2021-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197784
|
6.1 |
MEDIUM
Network
|
qnap
|
qulog_center
|
A stored XSS vulnerability has been reported to affect QNAP NAS running QuLog Center. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc.…
|
CWE-79
Cross-site Scripting
|
CVE-2020-36196
|
2024-11-21 14:28 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197785
|
6.1 |
MEDIUM
Network
|
qnap
|
quts_hero qts
|
An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. …
|
CWE-79
Cross-site Scripting
|
CVE-2020-36194
|
2024-11-21 14:28 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197786
|
2.7 |
LOW
Network
|
bloofox
|
bloofoxcms
|
bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files.
|
CWE-22
Path Traversal
|
CVE-2020-35762
|
2024-11-21 14:28 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197787
|
5.4 |
MEDIUM
Network
|
bloofox
|
bloofoxcms
|
bloofoxCMS 0.5.2.1 is infected with XSS that allows remote attackers to execute arbitrary JS/HTML Code.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35761
|
2024-11-21 14:28 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197788
|
9.8 |
CRITICAL
Network
|
bloofox
|
bloofoxcms
|
bloofoxCMS 0.5.2.1 is infected with Unrestricted File Upload that allows attackers to upload malicious files (ex: php files).
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-35760
|
2024-11-21 14:28 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197789
|
6.5 |
MEDIUM
Network
|
bloofox
|
bloofoxcms
|
bloofoxCMS 0.5.2.1 is infected with a CSRF Attack that leads to an attacker editing any file content (Locally/Remotely).
|
CWE-352
Origin Validation Error
|
CVE-2020-35759
|
2024-11-21 14:28 |
2021-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197790
|
6.5 |
MEDIUM
Network
|
bloofox
|
bloofoxcms
|
BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.
|
CWE-22
Path Traversal
|
CVE-2020-36142
|
2024-11-21 14:28 |
2021-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|