|
208581
|
5.4 |
MEDIUM
Network
|
xyhcms
|
xyhcms
|
XYHCMS v3.6 contains a stored cross-site scripting (XSS) vulnerability in the component xyhai.php?s=/Link/index.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21656
|
2024-11-21 14:12 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208582
|
7.2 |
HIGH
Network
|
emlog
|
emlog
|
emlog v6.0 contains a vulnerability in the component admin\template.php, which allows attackers to getshell via a crafted Zip file.
|
NVD-CWE-noinfo
|
CVE-2020-21654
|
2024-11-21 14:12 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208583
|
9.1 |
CRITICAL
Network
|
myucms_project
|
myucms
|
Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sj() method.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-21653
|
2024-11-21 14:12 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208584
|
9.8 |
CRITICAL
Network
|
myucms_project
|
myucms
|
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the addqq() method.
|
CWE-94
Code Injection
|
CVE-2020-21652
|
2024-11-21 14:12 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208585
|
9.8 |
CRITICAL
Network
|
myucms_project
|
myucms
|
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() method.
|
CWE-94
Code Injection
|
CVE-2020-21651
|
2024-11-21 14:12 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208586
|
8.8 |
HIGH
Network
|
myucms_project
|
myucms
|
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the add() method.
|
CWE-94
Code Injection
|
CVE-2020-21650
|
2024-11-21 14:12 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208587
|
8.1 |
HIGH
Network
|
myucms_project
|
myucms
|
Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sql() method.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-21649
|
2024-11-21 14:12 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208588
|
9.1 |
CRITICAL
Network
|
wdja
|
wdja_cms
|
WDJA CMS v1.5.2 contains an arbitrary file deletion vulnerability in the component admin/cache/manage.php.
|
NVD-CWE-noinfo
|
CVE-2020-21648
|
2024-11-21 14:12 |
2021-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208589
|
6.1 |
MEDIUM
Network
|
waimai_super_cms_project
|
waimai_super_cms
|
waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php?m=Config&a=add.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21506
|
2024-11-21 14:12 |
2021-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208590
|
6.1 |
MEDIUM
Network
|
waimai_super_cms_project
|
waimai_super_cms
|
waimai Super Cms 20150505 contains a cross-site scripting (XSS) vulnerability in the component /admin.php/Link/addsave.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21505
|
2024-11-21 14:12 |
2021-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|