|
208561
|
8.0 |
HIGH
Network
|
rockoa
|
rockoa
|
A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account.
|
CWE-352
Origin Validation Error
|
CVE-2020-20593
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208562
|
6.1 |
MEDIUM
Network
|
s-cms
|
s-cms
|
S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in /function/booksave.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20426
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208563
|
6.1 |
MEDIUM
Network
|
s-cms
|
s-cms
|
S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in the search function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20425
|
2024-11-21 14:12 |
2021-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208564
|
6.1 |
MEDIUM
Network
|
ruijie
|
rg-uac_6000-e50_firmware
|
Ruijie RG-UAC 6000-E50 commit 9071227 was discovered to contain a cross-site scripting (XSS) vulnerability via the rule_name parameter. This vulnerability allows attackers to execute arbitrary web sc…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21639
|
2024-11-21 14:12 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208565
|
7.5 |
HIGH
Network
|
ruijie
|
rg-uac_firmware
|
Ruijie RG-UAC commit 9071227 was discovered to contain a vulnerability in the component /current_action.php?action=reboot, which allows attackers to cause a denial of service (DoS) via unspecified ve…
|
NVD-CWE-noinfo
|
CVE-2020-21627
|
2024-11-21 14:12 |
2021-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208566
|
8.8 |
HIGH
Network
|
idreamsoft
|
icms
|
iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add.
|
CWE-352
Origin Validation Error
|
CVE-2020-21141
|
2024-11-21 14:12 |
2021-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208567
|
6.5 |
MEDIUM
Network
|
ec_cloud_e-commerce_system_project
|
ec_cloud_e-commerce_system
|
EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin accounts via /admin.html?do=user&act=add.
|
CWE-352
Origin Validation Error
|
CVE-2020-21139
|
2024-11-21 14:12 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208568
|
9.6 |
CRITICAL
Network
|
wdja
|
wdja_cms
|
Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain escalated privileges, via the backurl parameter to /php/passport/index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20982
|
2024-11-21 14:12 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208569
|
7.5 |
HIGH
Network
|
c-http_project
|
c-http
|
Buffer overflow vulnerability in YotsuyaNight c-http v0.1.0, allows attackers to cause a denial of service via a long url request which is passed to the delimitedread function.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-21574
|
2024-11-21 14:12 |
2021-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208570
|
5.5 |
MEDIUM
Local
|
image-processing_project
|
image-processing
|
An issue was discoverered in in abhijitnathwani image-processing v0.1.0, allows local attackers to cause a denial of service via a crafted image file.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-21573
|
2024-11-21 14:12 |
2021-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|