|
208701
|
5.5 |
MEDIUM
Local
|
fig2dev_project debian
|
fig2dev debian_linux
|
A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into pstricks format.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21676
|
2024-11-21 14:12 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208702
|
5.5 |
MEDIUM
Local
|
fig2dev_project debian
|
fig2dev debian_linux
|
A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via converting a xfig file into ptk format.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21675
|
2024-11-21 14:12 |
2021-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208703
|
6.5 |
MEDIUM
Network
|
wagecms_project
|
wage-cms
|
A cross site request forgery (CSRF) in Wage-CMS 1.5.x-dev allows attackers to arbitrarily add users.
|
CWE-352
Origin Validation Error
|
CVE-2020-21358
|
2024-11-21 14:12 |
2021-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208704
|
6.1 |
MEDIUM
Network
|
popojicms
|
popojicms
|
A stored cross site scripting (XSS) vulnerability in /admin.php?mod=user&act=addnew of PopojiCMS 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the E-Mail fiel…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21357
|
2024-11-21 14:12 |
2021-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208705
|
5.3 |
MEDIUM
Network
|
popojicms
|
popojicms
|
An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-21356
|
2024-11-21 14:12 |
2021-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208706
|
5.4 |
MEDIUM
Network
|
get-simple
|
getsimplecms
|
A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets mod…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21353
|
2024-11-21 14:12 |
2021-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208707
|
6.1 |
MEDIUM
Network
|
tidesec
|
wdscanner
|
Cross Site Scripting vulnerabiity exists in WDScanner 1.1 in the system management page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21854
|
2024-11-21 14:12 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208708
|
9.8 |
CRITICAL
Network
|
nukeviet
|
nukeviet
|
SQL Injection vulnerability in NukeViet CMS module Shops 4.0.29 and 4.3 via the (1) listid parameter in detail.php and the (2) group_price or groupid parameters in search_result.php.
|
CWE-89
SQL Injection
|
CVE-2020-21809
|
2024-11-21 14:12 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208709
|
9.8 |
CRITICAL
Network
|
nukeviet
|
nukeviet
|
SQL Injection vulnerability in NukeViet CMS 4.0.10 - 4.3.07 via:the topicsid parameter in modules/news/admin/addtotopics.php.
|
CWE-89
SQL Injection
|
CVE-2020-21808
|
2024-11-21 14:12 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208710
|
9.8 |
CRITICAL
Network
|
ectouch
|
ectouch
|
SQL Injection Vulnerability in ECTouch v2 via the shop page in index.php..
|
CWE-89
SQL Injection
|
CVE-2020-21806
|
2024-11-21 14:12 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|