|
209651
|
8.8 |
HIGH
Network
|
juqingcms
|
juqingcms
|
Cross Site Request Forgery (CSRF) in JuQingCMS v1.0 allows remote attackers to gain local privileges via the component "JuQingCMS_v1.0/admin/index.php?c=administrator&a=add".
|
CWE-352
Origin Validation Error
|
CVE-2020-18648
|
2024-11-21 14:08 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209652
|
7.5 |
HIGH
Network
|
5none
|
nonecms
|
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-18647
|
2024-11-21 14:08 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209653
|
7.5 |
HIGH
Network
|
5none
|
nonecms
|
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-18646
|
2024-11-21 14:08 |
2021-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209654
|
3.3 |
LOW
Local
|
zziplib_project debian fedoraproject
|
zziplib debian_linux fedora
|
Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file".
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-18442
|
2024-11-21 14:08 |
2021-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209655
|
6.1 |
MEDIUM
Network
|
zblogcn
|
z-blogphp
|
Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."
|
CWE-601
Open Redirect
|
CVE-2020-18268
|
2024-11-21 14:08 |
2021-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209656
|
8.8 |
HIGH
Network
|
simple-log_project
|
simple-log
|
Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_add_member".
|
CWE-352
Origin Validation Error
|
CVE-2020-18265
|
2024-11-21 14:08 |
2021-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209657
|
8.8 |
HIGH
Network
|
simple-log_project
|
simple-log
|
Cross Site Request Forgery (CSRF) in Simple-Log v1.6 allows remote attackers to gain privilege and execute arbitrary code via the component "Simple-Log/admin/admin.php?act=act_edit_member".
|
CWE-352
Origin Validation Error
|
CVE-2020-18264
|
2024-11-21 14:08 |
2021-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209658
|
8.8 |
HIGH
Network
|
libjpeg-turbo
|
libjpeg-turbo
|
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-17541
|
2024-11-21 14:08 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209659
|
7.5 |
HIGH
Network
|
gnu
|
gama
|
A NULL-pointer deference issue was discovered in GNU_gama::set() in ellipsoid.h in Gama 2.04 which can lead to a denial of service (DOS) via segment faults caused by crafted inputs.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-18395
|
2024-11-21 14:08 |
2021-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209660
|
5.5 |
MEDIUM
Local
|
cesanta
|
mjs
|
Stack overflow vulnerability in parse_array Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
|
CWE-674
Uncontrolled Recursion
|
CVE-2020-18392
|
2024-11-21 14:08 |
2021-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|