|
210751
|
6.1 |
MEDIUM
Network
|
kitesky
|
kitecms
|
Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the registering user parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20522
|
2024-11-21 14:12 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210752
|
6.1 |
MEDIUM
Network
|
kitesky
|
kitecms
|
Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the comment parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20521
|
2024-11-21 14:12 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210753
|
9.8 |
CRITICAL
Network
|
uqcms
|
uqcms
|
SQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the cookie_cart parameter to /index.php/cart/num.
|
CWE-89
SQL Injection
|
CVE-2020-21120
|
2024-11-21 14:12 |
2023-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210754
|
9.8 |
CRITICAL
Network
|
kliqqi
|
kliqqi_cms
|
SQL Injection vulnerability in Kliqqi-CMS 2.0.2 in admin/admin_update_module_widgets.php in recordIDValue parameter, allows attackers to gain escalated privileges and execute arbitrary code.
|
CWE-89
SQL Injection
|
CVE-2020-21119
|
2024-11-21 14:12 |
2023-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210755
|
9.8 |
CRITICAL
Network
|
inxedu
|
inxedu
|
SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunction.
|
CWE-89
SQL Injection
|
CVE-2020-21152
|
2024-11-21 14:12 |
2023-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210756
|
6.1 |
MEDIUM
Network
|
netgate
|
pfsense acme
|
Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remote attackers to to run arbitrary code via the RootFolder field to acme_certific…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21219
|
2024-11-21 14:12 |
2022-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210757
|
6.1 |
MEDIUM
Network
|
feehi
|
feehicms
|
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20589
|
2024-11-21 14:12 |
2022-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210758
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-846_firmware
|
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php.
|
NVD-CWE-noinfo
|
CVE-2020-21016
|
2024-11-21 14:12 |
2022-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210759
|
9.8 |
CRITICAL
Network
|
feehi
|
feehicms
|
There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21516
|
2024-11-21 14:12 |
2022-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210760
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_analytics_plus
|
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.
|
CWE-22
Path Traversal
|
CVE-2020-21642
|
2024-11-21 14:12 |
2022-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|