|
209211
|
6.1 |
MEDIUM
Network
|
synacor
|
zimbra_collaboration_suite
|
A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated attackers to execute arbitrary web scr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18984
|
2024-11-21 14:08 |
2021-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209212
|
6.1 |
MEDIUM
Network
|
zzcms
|
zzcms
|
Cross Site Scripting (XSS) vulnerability exists in zzcms 2019 XSS via a modify action in user/adv.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19042
|
2024-11-21 14:08 |
2021-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209213
|
7.5 |
HIGH
Network
|
php-cms_project
|
php-cms
|
PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability in the component search.php via the search parameter. This vulnerability allows attackers to access sensitive database information.
|
CWE-89
SQL Injection
|
CVE-2020-18263
|
2024-11-21 14:08 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209214
|
9.8 |
CRITICAL
Network
|
ed01-cms_project
|
ed01-cms
|
ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter.
|
CWE-89
SQL Injection
|
CVE-2020-18262
|
2024-11-21 14:08 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209215
|
9.8 |
CRITICAL
Network
|
ed01-cms_project
|
ed01-cms
|
An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-18261
|
2024-11-21 14:08 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209216
|
6.1 |
MEDIUM
Network
|
ed01-cms_project
|
ed01-cms
|
ED01-CMS v1.0 was discovered to contain a reflective cross-site scripting (XSS) vulnerability in the component sposts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML…
|
CWE-79
Cross-site Scripting
|
CVE-2020-18259
|
2024-11-21 14:08 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209217
|
9.8 |
CRITICAL
Network
|
phpok
|
phpok
|
Buffer overflow vulnerability in framework/init.php in qinggan phpok 5.1, allows attackers to execute arbitrary code.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-18440
|
2024-11-21 14:08 |
2021-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209218
|
9.1 |
CRITICAL
Network
|
phpok
|
phpok
|
An issue was discoverered in in function edit_save_f in framework/admin/tpl_control.php in qinggan phpok 5.1, allows attackers to write arbitrary files or get a shell.
|
NVD-CWE-noinfo
|
CVE-2020-18439
|
2024-11-21 14:08 |
2021-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209219
|
7.5 |
HIGH
Network
|
phpok
|
phpok
|
Directory traversal vulnerability in qinggan phpok 5.1, allows attackers to disclose sensitive information, via the title parameter to admin.php.
|
CWE-22
Path Traversal
|
CVE-2020-18438
|
2024-11-21 14:08 |
2021-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209220
|
5.3 |
MEDIUM
Network
|
liftoffsoftware
|
gate_one
|
An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2020-19003
|
2024-11-21 14:08 |
2021-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|