|
209031
|
7.5 |
HIGH
Network
|
phpok
|
phpok
|
Directory traversal vulnerability in qinggan phpok 5.1, allows attackers to disclose sensitive information, via the title parameter to admin.php.
|
CWE-22
Path Traversal
|
CVE-2020-18438
|
2024-11-21 14:08 |
2021-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209032
|
5.3 |
MEDIUM
Network
|
liftoffsoftware
|
gate_one
|
An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2020-19003
|
2024-11-21 14:08 |
2021-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209033
|
9.8 |
CRITICAL
Network
|
atlassian
|
floodlight
|
Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of unchecked prerequisites related to TCP or UDP ports, or group or table IDs.
|
CWE-20
Improper Input Validation
|
CVE-2020-18685
|
2024-11-21 14:08 |
2021-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209034
|
9.8 |
CRITICAL
Network
|
atlassian
|
floodlight
|
Floodlight through 1.2 has an integer overflow in checkFlow in StaticFlowEntryPusherResource.java via priority or port number.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-18684
|
2024-11-21 14:08 |
2021-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209035
|
9.8 |
CRITICAL
Network
|
atlassian
|
floodlight
|
Floodlight through 1.2 has poor input validation in checkFlow in StaticFlowEntryPusherResource.java because of undefined fields mishandling.
|
CWE-20
Improper Input Validation
|
CVE-2020-18683
|
2024-11-21 14:08 |
2021-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209036
|
8.8 |
HIGH
Network
|
laiketui
|
laiketui
|
Cross Site Request Forgery (CSRF) in LaikeTui v3 allows remote attackers to execute arbitrary code via the component '/index.php?module=member&action=add'.
|
CWE-352
Origin Validation Error
|
CVE-2020-19159
|
2024-11-21 14:08 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209037
|
5.4 |
MEDIUM
Network
|
s-cms
|
s-cms
|
Cross Site Scripting (XSS) in S-CMS build 20191014 and earlier allows remote attackers to execute arbitrary code via the 'Site Title' parameter of the component '/data/admin/#/app/config/'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19158
|
2024-11-21 14:08 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209038
|
6.1 |
MEDIUM
Network
|
wenkucms_project
|
wenkucms
|
Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the 'Intro' parameter for the component '/index.php?m=ucenter&a=index'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19157
|
2024-11-21 14:08 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209039
|
5.4 |
MEDIUM
Network
|
ari-soft
|
ari_adminer
|
Cross Site Scripting (XSS) in Ari Adminer v1 allows remote attackers to execute arbitrary code via the 'Title' parameter of the 'Add New Connections' component when the 'save()' function is called.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19156
|
2024-11-21 14:08 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209040
|
8.8 |
HIGH
Network
|
jflyfox
|
jfinal_cms
|
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-19155
|
2024-11-21 14:08 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|