|
208511
|
9.8 |
CRITICAL
Network
|
8cms
|
ljcms
|
File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20735
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208512
|
8.8 |
HIGH
Network
|
gilacms
|
gila_cms
|
Cross Site Request Forgery vulnerability in Gila GilaCMS v.1.11.4 allows a remote attacker to execute arbitrary code via the cm/update_rows/user parameter.
|
CWE-352
Origin Validation Error
|
CVE-2020-20726
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208513
|
9.8 |
CRITICAL
Network
|
pluck-cms
|
pluckcms
|
File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20718
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208514
|
9.8 |
CRITICAL
Network
|
vim
|
vim
|
Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-20703
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208515
|
7.5 |
HIGH
Network
|
joyplus-cms_project
|
joyplus-cms
|
SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function.
|
CWE-89
SQL Injection
|
CVE-2020-20636
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208516
|
6.5 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
Cross Site Request Forgery found in yzCMS v.2.0 allows a remote attacker to execute arbitrary code via the token check function.
|
CWE-352
Origin Validation Error
|
CVE-2020-20502
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208517
|
7.2 |
HIGH
Network
|
opencart
|
opencart
|
SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the Fba plugin function in upload/admin/index.php.
|
CWE-89
SQL Injection
|
CVE-2020-20491
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208518
|
9.8 |
CRITICAL
Network
|
wuzhicms
|
wuzhicms
|
SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.
|
CWE-89
SQL Injection
|
CVE-2020-20413
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208519
|
7.5 |
HIGH
Network
|
kilo_project
|
kilo
|
Buffer Overflow vulnerability in Antirez Kilo before commit 7709a04ae8520c5b04d261616098cebf742f5a23 allows a remote attacker to cause a denial of service via the editorUpdateRow function in kilo.c.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-20335
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208520
|
6.1 |
MEDIUM
Network
|
typecho
|
typecho
|
Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.
|
CWE-601
Open Redirect
|
CVE-2020-21038
|
2024-11-21 14:12 |
2023-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|