|
208131
|
8.8 |
HIGH
Network
|
thedaylightstudio
|
fuel_cms
|
SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbitrary code via the col parameter to function list_items.
|
CWE-89
SQL Injection
|
CVE-2020-24950
|
2024-11-21 14:16 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208132
|
8.8 |
HIGH
Network
|
xuxueli
|
xxl-job
|
Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html …
|
CWE-352
Origin Validation Error
|
CVE-2020-24922
|
2024-11-21 14:16 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208133
|
6.5 |
MEDIUM
Network
|
davesteele
|
gnome-gmail
|
An issue was discovered in attach parameter in GNOME Gmail version 2.5.4, allows remote attackers to gain sensitive information via crafted "mailto" link.
|
NVD-CWE-noinfo
|
CVE-2020-24904
|
2024-11-21 14:16 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208134
|
6.1 |
MEDIUM
Network
|
lepton-cms
|
leptoncms
|
Cross Site Scripting (XSS) vulnerability in backend/pages/modify.php in Lepton-CMS version 4.7.0, allows remote attackers to execute arbitrary code.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24872
|
2024-11-21 14:16 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208135
|
6.5 |
MEDIUM
Network
|
cms-dev
|
cms
|
Plaintext Password vulnerability in AddAdmin.py in cms-dev/cms v1.4.rc1, allows attackers to gain sensitive information via audit logs.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-24804
|
2024-11-21 14:16 |
2023-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208136
|
7.5 |
HIGH
Network
|
nexusphp
|
nexusphp
|
Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.
|
CWE-863
Incorrect Authorization
|
CVE-2020-24771
|
2024-11-21 14:16 |
2022-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208137
|
9.8 |
CRITICAL
Network
|
nexusphp
|
nexusphp
|
SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2020-24770
|
2024-11-21 14:16 |
2022-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208138
|
9.8 |
CRITICAL
Network
|
nexusphp
|
nexusphp
|
SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the classes parameter.
|
CWE-89
SQL Injection
|
CVE-2020-24769
|
2024-11-21 14:16 |
2022-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208139
|
8.8 |
HIGH
Network
|
clash_project
|
clash
|
In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share. …
|
CWE-346
Origin Validation Error
|
CVE-2020-24772
|
2024-11-21 14:16 |
2022-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208140
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_applications_manager
|
An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter.
|
NVD-CWE-noinfo
|
CVE-2020-24743
|
2024-11-21 14:16 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|