|
208491
|
6.1 |
MEDIUM
Network
|
qibosoft
|
qibosoft
|
Cross Site Scripting vulnerability in Qibosoft qibosoft v.7 and before allows a remote attacker to execute arbitrary code via the eindtijd and starttijd parameters of do/search.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20808
|
2024-11-21 14:12 |
2023-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208492
|
6.5 |
MEDIUM
Network
|
duxcms_project
|
duxcms
|
Cross Site Request Forgery (CSRF) vulnerability in admin.php in DuxCMS 2.1 allows remote attackers to modtify application data via article/admin/content/add.
|
CWE-352
Origin Validation Error
|
CVE-2020-21881
|
2024-11-21 14:12 |
2023-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208493
|
9.8 |
CRITICAL
Network
|
yunyecms
|
yunyecms
|
SQL injection vulnerability in yunyecms 2.0.2 allows remote attackers to run arbitrary SQL commands via XFF.
|
CWE-89
SQL Injection
|
CVE-2020-21662
|
2024-11-21 14:12 |
2023-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208494
|
8.1 |
HIGH
Network
|
duxcms_project
|
duxcms
|
Directory traversal vulnerability in DuxCMS 2.1 allows attackers to delete arbitrary files via /admin/AdminBackup/del.
|
CWE-22
Path Traversal
|
CVE-2020-21862
|
2024-11-21 14:12 |
2023-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208495
|
8.8 |
HIGH
Network
|
duxcms_project
|
duxcms
|
File upload vulnerability in DuxCMS 2.1 allows attackers to execute arbitrary php code via duxcms/AdminUpload/upload.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21861
|
2024-11-21 14:12 |
2023-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208496
|
9.8 |
CRITICAL
Network
|
feehi
|
feehicms
|
File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21489
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208497
|
6.1 |
MEDIUM
Network
|
alluxio
|
alluxio
|
Cross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path parameter in the browse board component.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21485
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208498
|
9.8 |
CRITICAL
Network
|
nucleuscms
|
nucleuscms
|
File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21474
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208499
|
7.2 |
HIGH
Network
|
phpmywind
|
phpmywind
|
SQL injection vulnerability in gaozhifeng PHPMyWind v.5.6 allows a remote attacker to execute arbitrary code via the id variable in the modify function.
|
CWE-89
SQL Injection
|
CVE-2020-21400
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208500
|
8.0 |
HIGH
Network
|
njtech
|
greencms
|
Cross Site Request Forgery vulnerability in GreenCMS v.2.3 allows an attacker to gain privileges via the adduser function of index.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-21366
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|