|
209161
|
6.1 |
MEDIUM
Network
|
dzzoffice
|
dzzoffice
|
A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19703
|
2024-11-21 14:09 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209162
|
6.5 |
MEDIUM
Network
|
popojicms
|
popojicms
|
Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php.
|
CWE-22
Path Traversal
|
CVE-2020-19547
|
2024-11-21 14:09 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209163
|
8.8 |
HIGH
Network
|
eyoucms
|
eyoucms
|
Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang=cn.
|
CWE-352
Origin Validation Error
|
CVE-2020-19669
|
2024-11-21 14:09 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209164
|
9.8 |
CRITICAL
Network
|
metinfo
|
metinfo
|
An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowing attackers to escalate privileges.
|
CWE-22
Path Traversal
|
CVE-2020-19305
|
2024-11-21 14:09 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209165
|
7.5 |
HIGH
Network
|
metinfo
|
metinfo
|
An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory traversal and access sensitive information.
|
CWE-22
Path Traversal
|
CVE-2020-19304
|
2024-11-21 14:09 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209166
|
7.8 |
HIGH
Local
|
houdunren
|
hdcms
|
An arbitrary file upload vulnerability in /fileupload.php of hdcms 5.7 allows attackers to execute arbitrary code via a crafted file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19303
|
2024-11-21 14:09 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209167
|
9.8 |
CRITICAL
Network
|
vaethink
|
vaethink
|
An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing uploaded file suffixes to ".php".
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19302
|
2024-11-21 14:09 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209168
|
9.8 |
CRITICAL
Network
|
vaethink
|
vaethink
|
A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a crafted payload in the condition parameter.
|
CWE-863
Incorrect Authorization
|
CVE-2020-19301
|
2024-11-21 14:09 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209169
|
8.8 |
HIGH
Network
|
struktur
|
libheif
|
An issue was discovered in heif::Box_iref::get_references in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impact due to an invalid memory read.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-19499
|
2024-11-21 14:09 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209170
|
8.8 |
HIGH
Network
|
struktur
|
libheif
|
Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impacts.
|
NVD-CWE-noinfo
|
CVE-2020-19498
|
2024-11-21 14:09 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|