|
209481
|
8.8 |
HIGH
Network
|
hdfgroup
|
hdf5
|
Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-18232
|
2024-11-21 14:08 |
2023-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209482
|
9.8 |
CRITICAL
Network
|
sem-cms
|
semcms
|
File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-18432
|
2024-11-21 14:08 |
2023-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209483
|
4.8 |
MEDIUM
Network
|
chaoji_cms_project
|
chaoji_cms
|
Stored cross site scripting (XSS) vulnerability in Chaoji CMS v2.18 that allows attackers to execute arbitrary code via /index.php?admin-master-webset.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18414
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209484
|
6.8 |
MEDIUM
Network
|
catfishcms_project
|
catfishcms
|
Cross Site Request Forgery (CSRF) vulnerability was discovered in CatfishCMS 4.8.63 that would allow attackers to obtain administrator permissions via /index.php/admin/index/modifymanage.html.
|
CWE-352
Origin Validation Error
|
CVE-2020-18409
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209485
|
4.8 |
MEDIUM
Network
|
ecisp
|
espcms
|
An issue was discovered in espcms version P8.18101601. There is a cross site scripting (XSS) vulnerability that allows arbitrary code to be executed via the title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18404
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209486
|
6.8 |
MEDIUM
Network
|
jyuu
|
jymusic
|
An cross site request forgery (CSRF) vulnerability discovered in Jymusic v2.0.0.,that allows attackers to execute arbitrary code via /admin.php?s=/addons/config.html&id=6 to modify payment informatio…
|
CWE-352
Origin Validation Error
|
CVE-2020-18416
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209487
|
4.8 |
MEDIUM
Network
|
chaoji_cms_project
|
chaoji_cms
|
Stored cross site scripting (XSS) vulnerability in /index.php?admin-master-navmenu-add of Chaoji CMS v2.18 that allows attackers to execute arbitrary code.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18413
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209488
|
4.8 |
MEDIUM
Network
|
chaoji_cms_project
|
chaoji_cms
|
A stored cross site scripting (XSS) vulnerability in /index.php?admin-master-article-edit of Chaoji CMS v2.18 that allows attackers to obtain administrator privileges.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18410
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209489
|
7.5 |
HIGH
Network
|
cmseasy
|
cmseasy
|
An issue was discovered in cmseasy v7.0.0 that allows user credentials to be sent in clear text due to no encryption of form data.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-18406
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209490
|
8.8 |
HIGH
Network
|
feifeicms
|
feifeicms
|
A Cross site request forgery (CSRF) vulnerability was discovered in FeiFeiCMS v4.1.190209, which allows attackers to create administrator accounts via /index.php?s=Admin-Admin-Insert.
|
CWE-352
Origin Validation Error
|
CVE-2020-18418
|
2024-11-21 14:08 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|