|
208921
|
9.8 |
CRITICAL
Network
|
tp-shop
|
tp-shop
|
SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.
|
CWE-89
SQL Injection
|
CVE-2020-18164
|
2024-11-21 14:08 |
2021-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208922
|
9.8 |
CRITICAL
Network
|
quokka_project
|
quokka
|
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'.
|
CWE-611
XXE
|
CVE-2020-18705
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208923
|
9.8 |
CRITICAL
Network
|
fusionbox
|
widgy
|
Unrestricted Upload of File with Dangerous Type in Django-Widgy v0.8.4 allows remote attackers to execute arbitrary code via the 'image' widget in the component 'Change Widgy Page'.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-18704
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208924
|
9.8 |
CRITICAL
Network
|
quokka_project
|
quokka
|
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'.
|
CWE-611
XXE
|
CVE-2020-18703
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208925
|
6.1 |
MEDIUM
Network
|
quokka_project
|
quokka
|
Cross Site Scripting (XSS) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the 'Username' parameter in the component 'quokka/admin/actions.py'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18702
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208926
|
9.8 |
CRITICAL
Network
|
talelin
|
lin-cms-flask
|
Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token u…
|
CWE-863
Incorrect Authorization
|
CVE-2020-18701
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208927
|
6.1 |
MEDIUM
Network
|
talelin
|
lin-cms-flask
|
Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18699
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208928
|
9.8 |
CRITICAL
Network
|
talelin
|
lin-cms-flask
|
Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-18698
|
2024-11-21 14:08 |
2021-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208929
|
7.5 |
HIGH
Network
|
dcce
|
mac1100_plc_firmware
|
An information disclosure vulnerability exists in the EPA protocol of Dut Computer Control Engineering Co.'s PLC MAC1100.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-18759
|
2024-11-21 14:08 |
2021-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208930
|
9.8 |
CRITICAL
Network
|
dcce
|
mac1100_plc_firmware
|
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code.
|
CWE-77
Command Injection
|
CVE-2020-18758
|
2024-11-21 14:08 |
2021-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|