|
208541
|
7.5 |
HIGH
Network
|
h96tvbox
|
h96_pro_plus_firmware
|
An issue was discovered in H96 Smart TV Box H96 Pro Plus allows attackers to corrupt files via calls to the saveDeepColorAttr service.unk
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-21405
|
2024-11-21 14:12 |
2022-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208542
|
4.8 |
MEDIUM
Network
|
prestashop
|
prestashop
|
File upload vulnerability in the Catalog feature in Prestashop 1.7.6.7 allows remote attackers to run arbitrary code via the add new file page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21967
|
2024-11-21 14:12 |
2022-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208543
|
6.1 |
MEDIUM
Network
|
ruckuswireless
|
zonedirector_firmware
|
Cross Site Scripting (XSS) vulnerability in Ruckus Wireless ZoneDirector 9.8.3.0.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21161
|
2024-11-21 14:12 |
2022-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208544
|
7.8 |
HIGH
Local
|
softonic
|
eagleget
|
A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in EagleGet Downloader version 2.1.5.20 Stable. This issue allows authenticated no…
|
CWE-269
Improper Privilege Management
|
CVE-2020-21046
|
2024-11-21 14:12 |
2022-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208545
|
8.8 |
HIGH
Network
|
pbootcms
|
pbootcms
|
Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index.
|
CWE-352
Origin Validation Error
|
CVE-2020-20971
|
2024-11-21 14:12 |
2022-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208546
|
8.1 |
HIGH
Network
|
tinyrise
|
tinyshop
|
A File Deletion vulnerability exists in TinyShop 3.1.1 in the back_list parameter in controllers\admin.php, which could let a malicious user delete any file such as install.lock to reinstall cms.
|
NVD-CWE-noinfo
|
CVE-2020-21554
|
2024-11-21 14:12 |
2022-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208547
|
9.8 |
CRITICAL
Network
|
chshcms
|
cscms
|
An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-21238
|
2024-11-21 14:12 |
2021-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208548
|
9.8 |
CRITICAL
Network
|
8cms
|
ljcms
|
An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-21237
|
2024-11-21 14:12 |
2021-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208549
|
8.8 |
HIGH
Network
|
damicms
|
damicms
|
A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtaining a user's session cookie.
|
CWE-352
Origin Validation Error
|
CVE-2020-21236
|
2024-11-21 14:12 |
2021-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208550
|
7.5 |
HIGH
Network
|
jeecg
|
jeecg
|
An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-20948
|
2024-11-21 14:12 |
2021-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|