|
198121
|
7.5 |
HIGH
Network
|
searchblox
|
searchblox
|
A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated users to read arbitrary files from the operating system via a /searchblox/servlet…
|
CWE-22
Path Traversal
|
CVE-2020-35580
|
2024-11-21 14:27 |
2021-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198122
|
6.1 |
MEDIUM
Network
|
kamalkhan
|
kk_star_ratings
|
Cross Site Scripting (XSS) vulnerability in the kk Star Ratings plugin before 4.1.5.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35438
|
2024-11-21 14:27 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198123
|
7.8 |
HIGH
Local
|
linux netapp
|
linux_kernel cloud_backup solidfire_baseboard_management_controller_firmware h300s_firmware h500s_firmware h700s_firmware h300e_firmware h500e_firmware h700e_firmware h410s…
|
An out-of-bounds (OOB) memory access flaw was found in x25_bind in net/x25/af_x25.c in the Linux kernel version v5.12-rc5. A bounds check failure allows a local attacker with a user account on the sy…
|
-
|
CVE-2020-35519
|
2024-11-21 14:27 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198124
|
9.8 |
CRITICAL
Network
|
inxedu
|
inxedu
|
SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsystem.
|
CWE-89
SQL Injection
|
CVE-2020-35430
|
2024-11-21 14:27 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198125
|
5.4 |
MEDIUM
Network
|
unisys
|
data_exchange_management_studio
|
Unisys Data Exchange Management Studio through 5.0.34 doesn't sanitize the input to a HTML document field. This could be used for an XSS attack.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35542
|
2024-11-21 14:27 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198126
|
9.8 |
CRITICAL
Network
|
wondercms
|
wondercms
|
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary cod…
|
CWE-78
OS Command
|
CVE-2020-35314
|
2024-11-21 14:27 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198127
|
9.8 |
CRITICAL
Network
|
wondercms
|
wondercms
|
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL t…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-35313
|
2024-11-21 14:27 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198128
|
5.4 |
MEDIUM
Network
|
monicahq
|
monica
|
Cross Site Scripting (XSS) in Monica before 2.19.1 via the journal page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35660
|
2024-11-21 14:27 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198129
|
6.1 |
MEDIUM
Network
|
group-office
|
group_office
|
Cross Site Scripting (XSS) in Group Office CRM 6.4.196 via the SET_LANGUAGE parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35419
|
2024-11-21 14:27 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198130
|
5.4 |
MEDIUM
Network
|
group-office
|
group_office
|
Cross Site Scripting (XSS) in the contact page of Group Office CRM 6.4.196 by uploading a crafted svg file.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35418
|
2024-11-21 14:27 |
2021-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|