|
208981
|
4.8 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
Cross Site Scripting (XSS) vulnerablity in CMS Made Simple 2.2.14 via the Logic field in the Content Manager feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23240
|
2024-11-21 14:13 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208982
|
4.8 |
MEDIUM
Network
|
textpattern
|
textpattern
|
Cross Site Scripting (XSS) vulnerability in Textpattern CMS 4.8.1 via Custom fields in the Menu Preferences feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23239
|
2024-11-21 14:13 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208983
|
5.4 |
MEDIUM
Network
|
evo
|
evolution_cms
|
Cross Site Scripting (XSS) vulnerability in Evolution CMS 2.0.2 via the Document Manager feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23238
|
2024-11-21 14:13 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208984
|
4.8 |
MEDIUM
Network
|
lavalite
|
lavalite
|
Cross Site Scripting (XSS) vulnerabiity exists in LavaLite CMS 5.8.0 via the Menu Blocks feature, which can be bypassed by using HTML event handlers, such as "ontoggle,".
|
CWE-79
Cross-site Scripting
|
CVE-2020-23234
|
2024-11-21 14:13 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208985
|
7.5 |
HIGH
Network
|
lwip_project
|
lwip
|
A buffer overflow vulnerability in the zepif_linkoutput() function of Free Software Foundation lwIP git head version and version 2.1.2 allows attackers to access sensitive information via a crafted 6…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-22284
|
2024-11-21 14:13 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208986
|
7.5 |
HIGH
Network
|
lwip_project
|
lwip
|
A buffer overflow vulnerability in the icmp6_send_response_with_addrs_and_netif() function of Free Software Foundation lwIP version git head allows attackers to access sensitive information via a cra…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-22283
|
2024-11-21 14:13 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208987
|
6.1 |
MEDIUM
Network
|
piwigo
|
piwigo
|
A cross site scripting (XSS) vulnerability in /admin.php?page=permalinks of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22150
|
2024-11-21 14:13 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208988
|
6.1 |
MEDIUM
Network
|
piwigo
|
piwigo
|
A stored cross site scripting (XSS) vulnerability in /admin.php?page=tags of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22148
|
2024-11-21 14:13 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208989
|
7.5 |
HIGH
Network
|
mv
|
mconnect
|
Information disclosure in Logon Page in MV's mConnect application v02.001.00 allows an attacker to know valid users from the application's database via brute force.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-23283
|
2024-11-21 14:13 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208990
|
7.5 |
HIGH
Network
|
mv
|
mconnect
|
SQL injection in Logon Page in MV's mConnect application, v02.001.00, allows an attacker to use a non existing user with a generic password to connect to the application and get access to unauthorize…
|
CWE-89
SQL Injection
|
CVE-2020-23282
|
2024-11-21 14:13 |
2021-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|