|
208501
|
8.8 |
HIGH
Network
|
wuzhicms
|
wuzhicms
|
An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\common.func.php file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21325
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208502
|
6.1 |
MEDIUM
Network
|
easycorp
|
zentao
|
Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21268
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208503
|
8.8 |
HIGH
Network
|
hongcms_project
|
hongcms
|
Cross Site Request Forgery vulnerability in Neeke HongCMS 3.0.0 allows a remote attacker to execute arbitrary code and escalate privileges via the updateusers parameter.
|
CWE-352
Origin Validation Error
|
CVE-2020-21252
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208504
|
5.4 |
MEDIUM
Network
|
yiicms_project
|
yiicms
|
Cross Site Scripting vulnerability in YiiCMS v.1.0 allows a remote attacker to execute arbitrary code via the news function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21246
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208505
|
9.8 |
CRITICAL
Network
|
feehi
|
feehicms
|
File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21174
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208506
|
6.1 |
MEDIUM
Network
|
typora
|
typora
|
Cross Site Scripting vulnerability in Typora v.0.9.79 allows a remote attacker to execute arbitrary code via the mermaid sytax.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21058
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208507
|
6.1 |
MEDIUM
Network
|
zrlog
|
zrlog
|
Cross Site Scripting vulnerability in zrlog zrlog v.2.1.3 allows a remote attacker to execute arbitrary code via the nickame parameter of the /post/addComment function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21052
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208508
|
7.2 |
HIGH
Network
|
pluck-cms
|
pluck
|
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20969
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208509
|
7.2 |
HIGH
Network
|
pluck-cms
|
pluck
|
File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20919
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208510
|
7.2 |
HIGH
Network
|
pluck-cms
|
pluck
|
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.
|
CWE-94
Code Injection
|
CVE-2020-20918
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|