|
208521
|
6.1 |
MEDIUM
Network
|
hongcms_project
|
hongcms
|
Cross Site Scripting (XSS) vulnerability in HongCMS 3.0 allows attackers to run arbitrary code via the callback parameter to /ajax/myshop.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21643
|
2024-11-21 14:12 |
2023-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208522
|
8.8 |
HIGH
Network
|
fluentd
|
fluentd-ui fluentd
|
An issue was discovered in Fluent Fluentd v.1.8.0 and Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default password.
|
NVD-CWE-noinfo
|
CVE-2020-21514
|
2024-11-21 14:12 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208523
|
9.6 |
CRITICAL
Network
|
netgate
|
pfsense pfsense_acme_package
|
Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21487
|
2024-11-21 14:12 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208524
|
8.8 |
HIGH
Network
|
phpmywind
|
phpmywind
|
SQL injection vulnerability found in PHPMyWind v.5.6 allows a remote attacker to gain privileges via the delete function of the administrator management page.
|
CWE-89
SQL Injection
|
CVE-2020-21060
|
2024-11-21 14:12 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208525
|
9.8 |
CRITICAL
Network
|
publiccms
|
publiccms
|
SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl.
|
CWE-89
SQL Injection
|
CVE-2020-20915
|
2024-11-21 14:12 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208526
|
9.8 |
CRITICAL
Network
|
publiccms
|
publiccms
|
SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.
|
CWE-89
SQL Injection
|
CVE-2020-20914
|
2024-11-21 14:12 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208527
|
9.8 |
CRITICAL
Network
|
mingsoft
|
mcms
|
SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter.
|
CWE-89
SQL Injection
|
CVE-2020-20913
|
2024-11-21 14:12 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208528
|
6.1 |
MEDIUM
Network
|
kitesky
|
kitecms
|
Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the registering user parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20522
|
2024-11-21 14:12 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208529
|
6.1 |
MEDIUM
Network
|
kitesky
|
kitecms
|
Cross Site Scripting vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the comment parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-20521
|
2024-11-21 14:12 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208530
|
9.8 |
CRITICAL
Network
|
uqcms
|
uqcms
|
SQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the cookie_cart parameter to /index.php/cart/num.
|
CWE-89
SQL Injection
|
CVE-2020-21120
|
2024-11-21 14:12 |
2023-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|