|
208831
|
6.1 |
MEDIUM
Network
|
intelliants
|
subrion_cms
|
Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18325
|
2024-11-21 14:08 |
2022-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208832
|
6.1 |
MEDIUM
Network
|
intelliants
|
subrion_cms
|
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.
|
CWE-79
Cross-site Scripting
|
CVE-2020-18324
|
2024-11-21 14:08 |
2022-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208833
|
7.5 |
HIGH
Network
|
sem-cms
|
semcms
|
The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext through a SQL query.
|
CWE-89
SQL Injection
|
CVE-2020-18081
|
2024-11-21 14:08 |
2021-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208834
|
9.8 |
CRITICAL
Network
|
sem-cms
|
semcms
|
A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.
|
NVD-CWE-noinfo
|
CVE-2020-18078
|
2024-11-21 14:08 |
2021-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208835
|
7.5 |
HIGH
Network
|
ftpshell
|
ftpshell_server
|
A buffer overflow vulnerability in the Virtual Path Mapping component of FTPShell v6.83 allows attackers to cause a denial of service (DoS).
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-18077
|
2024-11-21 14:08 |
2021-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208836
|
6.1 |
MEDIUM
Network
|
synacor
|
zimbra_collaboration_suite
|
An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing.
|
CWE-601
Open Redirect
|
CVE-2020-18985
|
2024-11-21 14:08 |
2021-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208837
|
6.1 |
MEDIUM
Network
|
synacor
|
zimbra_collaboration_suite
|
A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated attackers to execute arbitrary web scr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18984
|
2024-11-21 14:08 |
2021-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208838
|
6.1 |
MEDIUM
Network
|
zzcms
|
zzcms
|
Cross Site Scripting (XSS) vulnerability exists in zzcms 2019 XSS via a modify action in user/adv.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19042
|
2024-11-21 14:08 |
2021-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208839
|
7.5 |
HIGH
Network
|
php-cms_project
|
php-cms
|
PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability in the component search.php via the search parameter. This vulnerability allows attackers to access sensitive database information.
|
CWE-89
SQL Injection
|
CVE-2020-18263
|
2024-11-21 14:08 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208840
|
9.8 |
CRITICAL
Network
|
ed01-cms_project
|
ed01-cms
|
ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter.
|
CWE-89
SQL Injection
|
CVE-2020-18262
|
2024-11-21 14:08 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|