|
210901
|
8.8 |
HIGH
Network
|
ayacms_project
|
ayacms
|
Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified impacts.
|
CWE-352
Origin Validation Error
|
CVE-2020-23686
|
2024-11-21 14:14 |
2021-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210902
|
9.8 |
CRITICAL
Network
|
vtimecn
|
188jianzhan
|
SQL Injection vulnerability in 188Jianzhan v2.1.0, allows attackers to execute arbitrary code and gain escalated privileges, via the username parameter to login.php.
|
CWE-89
SQL Injection
|
CVE-2020-23685
|
2024-11-21 14:14 |
2021-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210903
|
5.3 |
MEDIUM
Network
|
discourse
|
discourse
|
Server Side Request Forgery (SSRF) vulnerability exists in Discourse 2.3.2 and 2.6 via the email function. When writing an email in an editor, you can upload pictures of remote websites.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-24327
|
2024-11-21 14:14 |
2021-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210904
|
8.1 |
HIGH
Network
|
ponzu-cms
|
ponzu
|
A cross site request forgery (CSRF) vulnerability in the configure.html component of Ponzu 0.11.0 allows attackers to change user and administrator credentials, and add or delete administrator accoun…
|
CWE-352
Origin Validation Error
|
CVE-2020-24130
|
2024-11-21 14:14 |
2021-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210905
|
6.5 |
MEDIUM
Network
|
ok-file-formats_project
|
ok-file-formats
|
A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_progressive() at ok_jpg.c:1054 of ok-file-formats through 2020-06-26 allows attackers to cause a Denial of Service (DOS)…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23707
|
2024-11-21 14:14 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210906
|
6.5 |
MEDIUM
Network
|
ok-file-formats_project
|
ok-file-formats
|
A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_subsequent_scan() ok_jpg.c:1102 of ok-file-formats through 2020-06-26 allows attackers to cause a Denial of Service (DOS…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23706
|
2024-11-21 14:14 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210907
|
6.5 |
MEDIUM
Network
|
rockcarry
|
ffjpeg
|
A global buffer overflow vulnerability in jfif_encode at jfif.c:701 of ffjpeg through 2020-06-22 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg file.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-23705
|
2024-11-21 14:14 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210908
|
9.8 |
CRITICAL
Network
|
radare
|
radare2-extras
|
A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-24133
|
2024-11-21 14:14 |
2021-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210909
|
4.8 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
Cross Site Scripting (XSS) vulnerability in PHP-Fusion 9.03.60 via 'New Shout' in /infusions/shoutbox_panel/shoutbox_admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23702
|
2024-11-21 14:14 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210910
|
4.8 |
MEDIUM
Network
|
lavalite
|
lavalite
|
Cross Site Scripting (XSS) vulnerability in LavaLite-CMS 5.8.0 via the Menu Links feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23700
|
2024-11-21 14:14 |
2021-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|