|
211841
|
6.1 |
MEDIUM
Network
|
blog_mini_project
|
blog_mini
|
Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/custom/blog-plugin/add'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18998
|
2024-11-21 14:08 |
2021-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211842
|
8.8 |
HIGH
Network
|
hucart
|
hucart
|
SQL Injection vulnerability in Hucart CMS 5.7.4 via the purchase enquiry field found in the Message con_content field.
|
CWE-89
SQL Injection
|
CVE-2020-18477
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211843
|
8.8 |
HIGH
Network
|
hucart
|
hucart
|
SQL Injection vulnerability in Hucart CMS 5.7.4 via the basic information field found in the avatar usd_image field.
|
CWE-89
SQL Injection
|
CVE-2020-18476
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211844
|
5.4 |
MEDIUM
Network
|
hucart
|
hucart
|
Cross Site Scripting (XSS) vulnerabilty exists in Hucart CMS 5.7.4 is via the mes_title field. The first user inserts a malicious script into the header field of the outbox and sends it to other user…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18475
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211845
|
5.4 |
MEDIUM
Network
|
rukovoditel
|
rukovoditel
|
Stored cross-site scripting (XSS) vulnerability in the Name of application field found in the General Configuration page in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18470
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211846
|
5.4 |
MEDIUM
Network
|
rukovoditel
|
rukovoditel
|
Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18469
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211847
|
5.4 |
MEDIUM
Network
|
qdpm
|
qdpm
|
Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted website name by doing an authenticated POST HTTP req…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18468
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211848
|
5.4 |
MEDIUM
Network
|
bigtreecms
|
bigtree_cms
|
Cross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under the General menu via a crafted website name by doing an authenticated POST HTTP …
|
CWE-79
Cross-site Scripting
|
CVE-2020-18467
|
2024-11-21 14:08 |
2021-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211849
|
5.4 |
MEDIUM
Network
|
popojicms
|
popojicms
|
Cross Site Scripting (XSS) vulnerability exists in PopojiCMS 2.0.1 in admin.php?mod=menumanager--------- edit menu.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18065
|
2024-11-21 14:08 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211850
|
5.5 |
MEDIUM
Local
|
broadcom
|
tcpreplay
|
Buffer Overflow in Tcpreplay v4.3.2 allows attackers to cause a Denial of Service via the 'do_checksum' function in 'checksum.c'. It can be triggered by sending a crafted pcap file to the 'tcpreplay-…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-18976
|
2024-11-21 14:08 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|