|
210711
|
7.8 |
HIGH
Local
|
freeimage_project
|
freeimage
|
Buffer Overflow vulnerability in function C_IStream::read in PluginEXR.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cause other impacts via crafted image file.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-21426
|
2024-11-21 14:12 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210712
|
5.5 |
MEDIUM
Local
|
elfutils_project
|
elfutils
|
The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787),…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21047
|
2024-11-21 14:12 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210713
|
6.1 |
MEDIUM
Network
|
gilacms
|
gila_cms
|
Cross Site Scripting (XSS) vulnerability in adm_user parameter in Gila CMS version 1.11.3, allows remote attackers to execute arbitrary code during the Gila CMS installation.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20523
|
2024-11-21 14:12 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210714
|
6.1 |
MEDIUM
Network
|
qibosoft
|
qibosoft
|
Cross Site Scripting vulnerability in Qibosoft qibosoft v.7 and before allows a remote attacker to execute arbitrary code via the eindtijd and starttijd parameters of do/search.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20808
|
2024-11-21 14:12 |
2023-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210715
|
6.5 |
MEDIUM
Network
|
duxcms_project
|
duxcms
|
Cross Site Request Forgery (CSRF) vulnerability in admin.php in DuxCMS 2.1 allows remote attackers to modtify application data via article/admin/content/add.
|
CWE-352
Origin Validation Error
|
CVE-2020-21881
|
2024-11-21 14:12 |
2023-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210716
|
9.8 |
CRITICAL
Network
|
yunyecms
|
yunyecms
|
SQL injection vulnerability in yunyecms 2.0.2 allows remote attackers to run arbitrary SQL commands via XFF.
|
CWE-89
SQL Injection
|
CVE-2020-21662
|
2024-11-21 14:12 |
2023-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210717
|
8.1 |
HIGH
Network
|
duxcms_project
|
duxcms
|
Directory traversal vulnerability in DuxCMS 2.1 allows attackers to delete arbitrary files via /admin/AdminBackup/del.
|
CWE-22
Path Traversal
|
CVE-2020-21862
|
2024-11-21 14:12 |
2023-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210718
|
8.8 |
HIGH
Network
|
duxcms_project
|
duxcms
|
File upload vulnerability in DuxCMS 2.1 allows attackers to execute arbitrary php code via duxcms/AdminUpload/upload.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21861
|
2024-11-21 14:12 |
2023-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210719
|
9.8 |
CRITICAL
Network
|
feehi
|
feehicms
|
File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21489
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210720
|
6.1 |
MEDIUM
Network
|
alluxio
|
alluxio
|
Cross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path parameter in the browse board component.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21485
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|