|
208651
|
7.2 |
HIGH
Network
|
rgcms_project
|
rgcms
|
An arbitrary file write vulnerability in RGCMS v1.06 allows attackers to execute arbitrary code via a crafted PHP file.
|
NVD-CWE-noinfo
|
CVE-2020-21480
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208652
|
9.8 |
CRITICAL
Network
|
feehi
|
feehicms
|
An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21322
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208653
|
4.3 |
MEDIUM
Network
|
emlog
|
emlog
|
emlog v6.0 contains a Cross-Site Request Forgery (CSRF) via /admin/link.php?action=addlink, which allows attackers to arbitrarily add articles.
|
CWE-352
Origin Validation Error
|
CVE-2020-21321
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208654
|
9.8 |
CRITICAL
Network
|
metinfo
|
metinfo
|
MetInfo 7.0.0 contains a SQL injection vulnerability via admin/?n=logs&c=index&a=dodel.
|
CWE-89
SQL Injection
|
CVE-2020-21127
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208655
|
8.8 |
HIGH
Network
|
metinfo
|
metinfo
|
MetInfo 7.0.0 contains a Cross-Site Request Forgery (CSRF) via admin/?n=admin&c=index&a=doSaveInfo.
|
CWE-352
Origin Validation Error
|
CVE-2020-21126
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208656
|
9.8 |
CRITICAL
Network
|
ureport_project
|
ureport
|
An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code.
|
NVD-CWE-noinfo
|
CVE-2020-21125
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208657
|
9.8 |
CRITICAL
Network
|
ureport_project
|
ureport
|
UReport 2.2.9 allows attackers to execute arbitrary code due to a lack of access control to the designer page.
|
CWE-863
Incorrect Authorization
|
CVE-2020-21124
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208658
|
5.3 |
MEDIUM
Network
|
ureport_project
|
ureport
|
UReport v2.2.9 contains a Server-Side Request Forgery (SSRF) in the designer page which allows attackers to detect intranet device ports.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-21122
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208659
|
9.8 |
CRITICAL
Network
|
kliqqi
|
kliqqi_cms
|
Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_module_widgets.php file.
|
CWE-89
SQL Injection
|
CVE-2020-21121
|
2024-11-21 14:12 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208660
|
6.1 |
MEDIUM
Network
|
maccms
|
maccms
|
A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows attackers to steal administrator and user cookies via crafted payloads in the…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21082
|
2024-11-21 14:12 |
2021-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|