|
208741
|
6.1 |
MEDIUM
Network
|
kandnconcepts_club_cms_project
|
kandnconcepts_club_cms
|
KandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23977
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208742
|
9.8 |
CRITICAL
Network
|
webexcels
|
ecommerce_cms
|
Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.
|
CWE-89
SQL Injection
|
CVE-2020-23976
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208743
|
6.1 |
MEDIUM
Network
|
webexcels
|
ecommerce_cms
|
Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has cross site scripting via the 'search.php' id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23975
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208744
|
5.4 |
MEDIUM
Network
|
create-project_manager_project
|
create-project_manager
|
Create-Project Manager 1.07 has Multi Persistent Cross-site Scripting and HTML injection in via Online chat, Social feed,Message(title-tag), Add new client (all-tags).
|
CWE-79
Cross-site Scripting
|
CVE-2020-23974
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208745
|
9.8 |
CRITICAL
Network
|
kandnconcepts_club_cms_project
|
kandnconcepts_club_cms
|
KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.
|
CWE-89
SQL Injection
|
CVE-2020-23973
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208746
|
7.5 |
HIGH
Network
|
gmapfp
|
gmapfp
|
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricte…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-23972
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208747
|
9.8 |
CRITICAL
Network
|
designmasterevents
|
conference_management
|
DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.
|
CWE-89
SQL Injection
|
CVE-2020-23980
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208748
|
5.3 |
MEDIUM
Network
|
ericom
|
access_server
|
Ericom Access Server 9.2.0 (for AccessNow and Ericom Blaze) allows SSRF to make outbound WebSocket connection requests on arbitrary TCP ports, and provides "Cannot connect to" error messages to infor…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-24548
|
2024-11-21 14:14 |
2020-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208749
|
6.1 |
MEDIUM
Network
|
admin_menu_project
|
admin_menu
|
WP Plugin Rednumber Admin Menu v1.1 and lower does not sanitize the value of the "role" GET parameter before echoing it back out to the user. This results in a reflected XSS vulnerability that attack…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24316
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208750
|
7.5 |
HIGH
Network
|
wordpress_poll_project
|
wordpress_poll
|
Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to a lack of user input escaping. This allows users who craft specific SQL stateme…
|
CWE-89
SQL Injection
|
CVE-2020-24315
|
2024-11-21 14:14 |
2020-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|