|
209021
|
7.5 |
HIGH
Network
|
ftpshell
|
ftpshell_server
|
A buffer overflow vulnerability in the Virtual Path Mapping component of FTPShell v6.83 allows attackers to cause a denial of service (DoS).
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-18077
|
2024-11-21 14:08 |
2021-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209022
|
6.1 |
MEDIUM
Network
|
synacor
|
zimbra_collaboration_suite
|
An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing.
|
CWE-601
Open Redirect
|
CVE-2020-18985
|
2024-11-21 14:08 |
2021-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209023
|
6.1 |
MEDIUM
Network
|
synacor
|
zimbra_collaboration_suite
|
A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated attackers to execute arbitrary web scr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18984
|
2024-11-21 14:08 |
2021-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209024
|
6.1 |
MEDIUM
Network
|
zzcms
|
zzcms
|
Cross Site Scripting (XSS) vulnerability exists in zzcms 2019 XSS via a modify action in user/adv.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19042
|
2024-11-21 14:08 |
2021-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209025
|
7.5 |
HIGH
Network
|
php-cms_project
|
php-cms
|
PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability in the component search.php via the search parameter. This vulnerability allows attackers to access sensitive database information.
|
CWE-89
SQL Injection
|
CVE-2020-18263
|
2024-11-21 14:08 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209026
|
9.8 |
CRITICAL
Network
|
ed01-cms_project
|
ed01-cms
|
ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter.
|
CWE-89
SQL Injection
|
CVE-2020-18262
|
2024-11-21 14:08 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209027
|
9.8 |
CRITICAL
Network
|
ed01-cms_project
|
ed01-cms
|
An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-18261
|
2024-11-21 14:08 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209028
|
6.1 |
MEDIUM
Network
|
ed01-cms_project
|
ed01-cms
|
ED01-CMS v1.0 was discovered to contain a reflective cross-site scripting (XSS) vulnerability in the component sposts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18259
|
2024-11-21 14:08 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209029
|
9.8 |
CRITICAL
Network
|
phpok
|
phpok
|
Buffer overflow vulnerability in framework/init.php in qinggan phpok 5.1, allows attackers to execute arbitrary code.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-18440
|
2024-11-21 14:08 |
2021-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209030
|
9.1 |
CRITICAL
Network
|
phpok
|
phpok
|
An issue was discoverered in in function edit_save_f in framework/admin/tpl_control.php in qinggan phpok 5.1, allows attackers to write arbitrary files or get a shell.
|
NVD-CWE-noinfo
|
CVE-2020-18439
|
2024-11-21 14:08 |
2021-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|