|
208941
|
9.8 |
CRITICAL
Network
|
projectworlds
|
online_book_store_project_in_php
|
SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote malicious user execute arbitrary code.
|
CWE-89
SQL Injection
|
CVE-2020-19107
|
2024-11-21 14:08 |
2021-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208942
|
6.1 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into the "referer" field of a POST request to the component "/member/index/login.html…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18084
|
2024-11-21 14:08 |
2021-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208943
|
9.1 |
CRITICAL
Network
|
idreamsoft
|
icms
|
Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP request to the "do_del()" method of the component "database.admincp.php".
|
CWE-22
Path Traversal
|
CVE-2020-18070
|
2024-11-21 14:08 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208944
|
6.1 |
MEDIUM
Network
|
jeesns
|
jeesns
|
Cross Site Scripting (XSS) in Jeesns v1.4.2 allows remote attackers to execute arbitrary code by injecting commands into the "CKEditorFuncNum" parameter in the component "CkeditorUploadController.jav…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18035
|
2024-11-21 14:08 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208945
|
7.8 |
HIGH
Local
|
graphviz debian fedoraproject
|
graphviz debian_linux fedora
|
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-18032
|
2024-11-21 14:08 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208946
|
6.1 |
MEDIUM
Network
|
qibosoft
|
qibocms
|
Cross Site Scripting (XSS) in Qibosoft QiboCMS v7 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information by injecting arbitrary commands in a HTTP request to th…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18022
|
2024-11-21 14:08 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208947
|
6.1 |
MEDIUM
Network
|
1234n
|
minicms
|
Cross Site Scripting (XSS) in MiniCMS v1.10 allows remote attackers to execute arbitrary code by injecting commands via a crafted HTTP request to the component "/mc-admin/post-edit.php".
|
CWE-79
Cross-site Scripting
|
CVE-2020-17999
|
2024-11-21 14:08 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208948
|
9.8 |
CRITICAL
Network
|
phpshe
|
mall_system
|
SQL Injection in PHPSHE Mall System v1.7 allows remote attackers to execute arbitrary code by injecting SQL commands into the "user_phone" parameter of a crafted HTTP request to the "admin.php" compo…
|
CWE-89
SQL Injection
|
CVE-2020-18020
|
2024-11-21 14:08 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208949
|
7.5 |
HIGH
Network
|
xinfu
|
oa_system
|
SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary commands into the "typeid" variable of the "createfolderAjax" function in the "m…
|
CWE-89
SQL Injection
|
CVE-2020-18019
|
2024-11-21 14:08 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208950
|
7.5 |
HIGH
Network
|
apache
|
ozone
|
The S3 buckets and keys in a secure Apache Ozone Cluster must be inaccessible to anonymous access by default. The current security vulnerability allows access to keys and buckets through a curl comma…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-17517
|
2024-11-21 14:08 |
2021-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|