|
200041
|
6.1 |
MEDIUM
Network
|
appcms
|
appcms
|
AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker to obtain sensitive information of other users.
|
CWE-79
Cross-site Scripting
|
CVE-2020-36007
|
2024-11-21 14:28 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200042
|
6.5 |
MEDIUM
Network
|
appcms
|
appcms
|
AppCMS 2.0.101 in /admin/info.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary files on the site.
|
NVD-CWE-noinfo
|
CVE-2020-36006
|
2024-11-21 14:28 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200043
|
6.5 |
MEDIUM
Network
|
appcms
|
appcms
|
AppCMS 2.0.101 in /admin/app.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary files on the site.
|
NVD-CWE-noinfo
|
CVE-2020-36005
|
2024-11-21 14:28 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200044
|
6.5 |
MEDIUM
Network
|
appcms
|
appcms
|
AppCMS 2.0.101 in /admin/download_frame.php has a SQL injection vulnerability which allows attackers to obtain sensitive database information.
|
CWE-89
SQL Injection
|
CVE-2020-36004
|
2024-11-21 14:28 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200045
|
5.4 |
MEDIUM
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via /user/manage.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35973
|
2024-11-21 14:28 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200046
|
4.3 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
An issue was discovered in YzmCMS V5.8. There is a CSRF vulnerability that can add member user accounts via member/member/add.html.
|
CWE-352
Origin Validation Error
|
CVE-2020-35972
|
2024-11-21 14:28 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200047
|
5.4 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicious XSS on the /admin/system_manage/user_config_edit.html page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35971
|
2024-11-21 14:28 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200048
|
7.5 |
HIGH
Network
|
yzmcms
|
yzmcms
|
An issue was discovered in YzmCMS 5.8. There is a SSRF vulnerability in the background collection management that allows arbitrary file read.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-35970
|
2024-11-21 14:28 |
2021-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200049
|
8.8 |
HIGH
Adjacent
|
qnap
|
music_station
|
An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, this vulnerability allows attackers to compromise the security of the software by…
|
-
|
CVE-2020-36197
|
2024-11-21 14:28 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200050
|
8.1 |
HIGH
Network
|
paxtechnology
|
paxstore
|
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote privilege escalation. PAXSTORE marketplace endpoints allow an authenticated use…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-36126
|
2024-11-21 14:28 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|