|
211041
|
5.4 |
MEDIUM
Network
|
seeyon
|
g6_government_collaborative_system
|
Cross-Site Scripting (XSS) vulnerability in Zhiyuan G6 Government Collaboration System V6.1SP1, via the 'method' parameter to 'seeyon/hrSalary.do'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20545
|
2024-11-21 14:12 |
2021-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211042
|
9.8 |
CRITICAL
Network
|
inspur
|
clusterengine
|
A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control server
|
CWE-88
Argument Injection
|
CVE-2020-21224
|
2024-11-21 14:12 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211043
|
9.8 |
CRITICAL
Network
|
koa2-blog_project
|
koa2-blog
|
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signup page.
|
CWE-89
SQL Injection
|
CVE-2020-21180
|
2024-11-21 14:12 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211044
|
9.8 |
CRITICAL
Network
|
koa2-blog_project
|
koa2-blog
|
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signin page.
|
CWE-89
SQL Injection
|
CVE-2020-21179
|
2024-11-21 14:12 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211045
|
9.8 |
CRITICAL
Network
|
thinkjs
|
thinkjs
|
SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitrary SQL commands via the step parameter.
|
CWE-89
SQL Injection
|
CVE-2020-21176
|
2024-11-21 14:12 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211046
|
9.8 |
CRITICAL
Network
|
cmswing
|
cmswing
|
An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance parameter, malicious parameters can execute arbitrary SQL commands.
|
CWE-89
SQL Injection
|
CVE-2020-20296
|
2024-11-21 14:12 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211047
|
9.8 |
CRITICAL
Network
|
cmswing
|
cmswing
|
An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands.
|
CWE-89
SQL Injection
|
CVE-2020-20295
|
2024-11-21 14:12 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211048
|
9.8 |
CRITICAL
Network
|
cmswing
|
cmswing
|
An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands.
|
CWE-89
SQL Injection
|
CVE-2020-20294
|
2024-11-21 14:12 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211049
|
7.5 |
HIGH
Network
|
yccms
|
yccms
|
Directory traversal vulnerability in the yccms 3.3 project. The delete, deletesite, and deleteAll functions' improper judgment of the request parameters, triggers a directory traversal vulnerability.
|
CWE-22
Path Traversal
|
CVE-2020-20290
|
2024-11-21 14:12 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211050
|
9.8 |
CRITICAL
Network
|
yccms
|
yccms
|
Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters, triggers a sql injection vulnerability.
|
CWE-89
SQL Injection
|
CVE-2020-20289
|
2024-11-21 14:12 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|