|
209061
|
9.8 |
CRITICAL
Network
|
wcms
|
wcms
|
Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter.
|
CWE-22
Path Traversal
|
CVE-2020-19902
|
2024-11-21 14:09 |
2023-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209062
|
6.1 |
MEDIUM
Network
|
ipandao
|
editor.md
|
Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url values.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19660
|
2024-11-21 14:09 |
2023-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209063
|
8.8 |
HIGH
Network
|
doyocms_project
|
doyocms
|
Cross Site Request Forgery vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the background system settings.
|
CWE-352
Origin Validation Error
|
CVE-2020-19803
|
2024-11-21 14:09 |
2023-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209064
|
9.8 |
CRITICAL
Network
|
doyocms_project
|
doyocms
|
File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the upload file type parameter.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-19802
|
2024-11-21 14:09 |
2023-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209065
|
6.5 |
MEDIUM
Network
|
monospace
|
directus
|
An issue found in Directus API v.2.2.0 allows a remote attacker to cause a denial of service via a great amount of HTTP requests.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-19850
|
2024-11-21 14:09 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209066
|
6.1 |
MEDIUM
Network
|
kiftd_project
|
kiftd
|
Cross Site Scripting vulnerability found in KOHGYLW Kiftd v.1.0.18 allows a remote attacker to execute arbitrary code via the <ifram> tag in the upload file page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19699
|
2024-11-21 14:09 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209067
|
6.1 |
MEDIUM
Network
|
ipandao
|
editor.md
|
Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the editor parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19698
|
2024-11-21 14:09 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209068
|
9.8 |
CRITICAL
Network
|
nginx
|
njs
|
Buffer Overflow found in Nginx NJS allows a remote attacker to execute arbitrary code via the njs_object_property parameter of the njs/njs_vm.c function.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-19695
|
2024-11-21 14:09 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209069
|
9.8 |
CRITICAL
Network
|
espruino
|
espruino
|
An issue found in Espruino Espruino 6ea4c0a allows an attacker to execute arbitrrary code via oldFunc parameter of the jswrap_object.c:jswrap_function_replacewith endpoint.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-19693
|
2024-11-21 14:09 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209070
|
9.8 |
CRITICAL
Network
|
nginx
|
njs
|
Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-19692
|
2024-11-21 14:09 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|