|
209191
|
9.8 |
CRITICAL
Network
|
textpattern
|
textpattern
|
Textpattern 4.7.3 contains an aribtrary file load via the file_insert function in include/txp_file.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19510
|
2024-11-21 14:09 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209192
|
5.4 |
MEDIUM
Network
|
ipfire
|
ipfire
|
An authenticated Stored XSS (Cross-site Scripting) exists in the "captive.cgi" Captive Portal via the "Title of Login Page" text box or "TITLE" parameter in IPFire 2.21 (x86_64) - Core Update 130. It…
|
CWE-79
Cross-site Scripting
|
CVE-2020-19202
|
2024-11-21 14:09 |
2021-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209193
|
5.4 |
MEDIUM
Network
|
issuehunt
|
boostnote
|
In Boostnote 0.12.1, exporting to PDF contains opportunities for XSS attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19924
|
2024-11-21 14:09 |
2021-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209194
|
5.3 |
MEDIUM
Network
|
dhcms_project
|
dhcms
|
An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal interface, which causes an error that will leak the physical path.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-19275
|
2024-11-21 14:09 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209195
|
6.1 |
MEDIUM
Network
|
dhcms_project
|
dhcms
|
A Cross SIte Scripting (XSS) vulnerability exists in Dhcms 2017-09-18 in guestbook via the message board, which could let a remote malicious user execute arbitrary code.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19274
|
2024-11-21 14:09 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209196
|
8.8 |
HIGH
Network
|
phpok
|
phpok
|
A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious user execute arbitrary code.
|
CWE-352
Origin Validation Error
|
CVE-2020-19199
|
2024-11-21 14:09 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209197
|
9.8 |
CRITICAL
Network
|
shopxo
|
shopxo
|
Incorrect Access Control in Shopxo v1.4.0 and v1.5.0 allows remote attackers to gain privileges in "/index.php" by manipulating the parameter "user_id" in the HTML request.
|
NVD-CWE-Other
|
CVE-2020-19778
|
2024-11-21 14:09 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209198
|
9.8 |
CRITICAL
Network
|
coreftp
|
core_ftp
|
Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-19596
|
2024-11-21 14:09 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209199
|
7.5 |
HIGH
Network
|
coreftp
|
core_ftp
|
Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-19595
|
2024-11-21 14:09 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209200
|
5.4 |
MEDIUM
Network
|
mblog_project
|
mblog
|
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19619
|
2024-11-21 14:09 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|