|
210821
|
4.8 |
MEDIUM
Network
|
chaoji_cms_project
|
chaoji_cms
|
Stored cross site scripting (XSS) vulnerability in /index.php?admin-master-navmenu-add of Chaoji CMS v2.18 that allows attackers to execute arbitrary code.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18413
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210822
|
4.8 |
MEDIUM
Network
|
chaoji_cms_project
|
chaoji_cms
|
A stored cross site scripting (XSS) vulnerability in /index.php?admin-master-article-edit of Chaoji CMS v2.18 that allows attackers to obtain administrator privileges.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18410
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210823
|
7.5 |
HIGH
Network
|
cmseasy
|
cmseasy
|
An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-18406
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210824
|
8.8 |
HIGH
Network
|
feifeicms
|
feifeicms
|
A Cross site request forgery (CSRF) vulnerability was discovered in FeiFeiCMS v4.1.190209, which allows attackers to create administrator accounts via /index.php?s=Admin-Admin-Insert.
|
CWE-352
Origin Validation Error
|
CVE-2020-18418
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210825
|
7.5 |
HIGH
Network
|
emlog
|
emlog
|
*File Upload vulnerability found in Emlog EmlogCMS v.6.0.0 allows a remote attacker to gain access to sensitive information via the /admin/plugin.php function.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19028
|
2024-11-21 14:08 |
2023-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210826
|
6.1 |
MEDIUM
Network
|
md_project
|
md
|
Cross Site Scripting vulnerability found in Phodal CMD v.1.0 allows a local attacker to execute arbitrary code via the EMBED SRC function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18280
|
2024-11-21 14:08 |
2023-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210827
|
6.1 |
MEDIUM
Network
|
5none
|
nonecms
|
Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18282
|
2024-11-21 14:08 |
2023-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210828
|
4.8 |
MEDIUM
Network
|
mipcms
|
mipcms
|
Cross Site Scripting (XSS) vulnerability in MIPCMS 3.6.0 allows attackers to execute arbitrary code via the category name field to categoryEdit.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18132
|
2024-11-21 14:08 |
2023-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210829
|
8.8 |
HIGH
Network
|
clanscripts_project
|
clanscripts
|
Cross Site Request Forgery (CSRF) vulnerability in Bluethrust Clan Scripts v4 allows attackers to escilate privledges to an arbitrary account via a crafted request to /members/console.php?cID=5.
|
CWE-352
Origin Validation Error
|
CVE-2020-18131
|
2024-11-21 14:08 |
2023-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210830
|
9.1 |
CRITICAL
Network
|
chinamobileltd
|
gpn2.4p21-c-cn_firmware
|
Directory traversal vulnerability in ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(hardware platform Gpn2.4P21-C_WIFI-V0.05), via the getpage parameter …
|
CWE-22
Path Traversal
|
CVE-2020-18331
|
2024-11-21 14:08 |
2023-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|