|
208531
|
9.8 |
CRITICAL
Network
|
kliqqi
|
kliqqi_cms
|
SQL Injection vulnerability in Kliqqi-CMS 2.0.2 in admin/admin_update_module_widgets.php in recordIDValue parameter, allows attackers to gain escalated privileges and execute arbitrary code.
|
CWE-89
SQL Injection
|
CVE-2020-21119
|
2024-11-21 14:12 |
2023-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208532
|
9.8 |
CRITICAL
Network
|
inxedu
|
inxedu
|
SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunction.
|
CWE-89
SQL Injection
|
CVE-2020-21152
|
2024-11-21 14:12 |
2023-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208533
|
6.1 |
MEDIUM
Network
|
netgate
|
pfsense acme
|
Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remote attackers to to run arbitrary code via the RootFolder field to acme_certific…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21219
|
2024-11-21 14:12 |
2022-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208534
|
6.1 |
MEDIUM
Network
|
feehi
|
feehicms
|
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20589
|
2024-11-21 14:12 |
2022-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208535
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-846_firmware
|
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php.
|
NVD-CWE-noinfo
|
CVE-2020-21016
|
2024-11-21 14:12 |
2022-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208536
|
9.8 |
CRITICAL
Network
|
feehi
|
feehicms
|
There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21516
|
2024-11-21 14:12 |
2022-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208537
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_analytics_plus
|
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.
|
CWE-22
Path Traversal
|
CVE-2020-21642
|
2024-11-21 14:12 |
2022-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208538
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_analytics_plus
|
Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via…
|
CWE-611
XXE
|
CVE-2020-21641
|
2024-11-21 14:12 |
2022-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208539
|
7.5 |
HIGH
Network
|
wkhtmltopdf debian
|
wkhtmltopdf debian_linux
|
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configu…
|
CWE-22
Path Traversal
|
CVE-2020-21365
|
2024-11-21 14:12 |
2022-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208540
|
7.5 |
HIGH
Network
|
v88_smart_tv_box_project rk_max_smart_tv_box_project
|
v88_smart_tv_box_firmware rk_max_smart_tv_box_firmware
|
An issue was discovered in RK Smart TV Box MAX and V88 SmartTV box that allows attackers to cause a denial of service via the switchNextDisplayInterface service.
|
NVD-CWE-noinfo
|
CVE-2020-21406
|
2024-11-21 14:12 |
2022-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|