|
209091
|
6.1 |
MEDIUM
Network
|
xiuno
|
xiunobbs
|
Cross Site Scripting (XSS) in xiunobbs 4.0.4 allows remote attackers to execute arbitrary web script or HTML via the attachment upload function.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19914
|
2024-11-21 14:09 |
2022-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209092
|
6.1 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19897
|
2024-11-21 14:09 |
2022-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209093
|
9.8 |
CRITICAL
Network
|
1234n
|
minicms
|
File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.
|
NVD-CWE-Other
|
CVE-2020-19896
|
2024-11-21 14:09 |
2022-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209094
|
7.2 |
HIGH
Network
|
bludit
|
bludit
|
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19228
|
2024-11-21 14:09 |
2022-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209095
|
8.8 |
HIGH
Network
|
piwigo
|
piwigo
|
SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.
|
CWE-89
SQL Injection
|
CVE-2020-19217
|
2024-11-21 14:09 |
2022-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209096
|
8.8 |
HIGH
Network
|
piwigo
|
piwigo
|
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.
|
CWE-89
SQL Injection
|
CVE-2020-19216
|
2024-11-21 14:09 |
2022-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209097
|
8.8 |
HIGH
Network
|
piwigo
|
piwigo
|
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.
|
CWE-89
SQL Injection
|
CVE-2020-19215
|
2024-11-21 14:09 |
2022-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209098
|
9.8 |
CRITICAL
Network
|
piwigo
|
piwigo
|
SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.
|
CWE-89
SQL Injection
|
CVE-2020-19213
|
2024-11-21 14:09 |
2022-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209099
|
4.9 |
MEDIUM
Network
|
piwigo
|
piwigo
|
SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.
|
CWE-89
SQL Injection
|
CVE-2020-19212
|
2024-11-21 14:09 |
2022-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209100
|
9.8 |
CRITICAL
Network
|
jeesite
|
jeesite
|
Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an attacker could exploit the vulnerability to execute …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-19229
|
2024-11-21 14:09 |
2022-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|