|
208241
|
9.8 |
CRITICAL
Network
|
yunyecms
|
yunyecms
|
SQL injection vulnerability in yunyecms V2.0.1 via the selcart parameter.
|
CWE-89
SQL Injection
|
CVE-2020-21377
|
2024-11-21 14:12 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208242
|
9.8 |
CRITICAL
Network
|
weiphp
|
weiphp
|
SQL injection vulnerability in the wp_where function in WeiPHP 5.0.
|
CWE-89
SQL Injection
|
CVE-2020-20300
|
2024-11-21 14:12 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208243
|
7.5 |
HIGH
Network
|
weiphp
|
weiphp
|
WeiPHP 5.0 does not properly restrict access to pages, related to using POST.
|
NVD-CWE-noinfo
|
CVE-2020-20299
|
2024-11-21 14:12 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208244
|
9.8 |
CRITICAL
Network
|
zzzcms
|
zzzphp
|
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.
|
CWE-94
Code Injection
|
CVE-2020-20298
|
2024-11-21 14:12 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208245
|
7.8 |
HIGH
Local
|
pdfresurrect_project debian fedoraproject
|
pdfresurrect debian_linux fedora
|
PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version().
|
CWE-787
Out-of-bounds Write
|
CVE-2020-20740
|
2024-11-21 14:12 |
2020-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208246
|
5.3 |
MEDIUM
Network
|
libvips debian fedoraproject
|
libvips debian_linux fedora
|
im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
|
CWE-909
Missing Initialization of Resource
|
CVE-2020-20739
|
2024-11-21 14:12 |
2020-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208247
|
7.2 |
HIGH
Network
|
fastadmin
|
fastadmin
|
In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be passed for SQL injection in URL /admin/ajax/weigh.
|
CWE-89
SQL Injection
|
CVE-2020-21665
|
2024-11-21 14:12 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208248
|
7.2 |
HIGH
Network
|
fastadmin-tp6_project
|
fastadmin-tp6
|
In fastadmin-tp6 v1.0, in the file app/admin/controller/Ajax.php the 'table' parameter passed is not filtered so a malicious parameter can be passed for SQL injection.
|
CWE-89
SQL Injection
|
CVE-2020-21667
|
2024-11-21 14:12 |
2020-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208249
|
6.1 |
MEDIUM
Network
|
broadleafcommerce
|
broadleaf_commerce
|
Broadleaf Commerce 5.1.14-GA is affected by cross-site scripting (XSS) due to a slow HTTP post vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21266
|
2024-11-21 14:12 |
2020-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208250
|
6.5 |
MEDIUM
Network
|
libarchive
|
libarchive
|
Heap-based buffer overflow in archive_string_append_from_wcs() (archive_string.c) in libarchive-3.4.1dev allows remote attackers to cause a denial of service (out-of-bounds write in heap memory resul…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21674
|
2024-11-21 14:12 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|