|
208971
|
7.5 |
HIGH
Network
|
rconfig
|
rconfig
|
The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injection and obtain sensitive information via a crafted POST request.
|
CWE-74
Injection
|
CVE-2020-23148
|
2024-11-21 14:13 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208972
|
6.1 |
MEDIUM
Network
|
intelliants
|
subrion
|
Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22330
|
2024-11-21 14:13 |
2021-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208973
|
5.4 |
MEDIUM
Network
|
intelliants
|
subrion_cms
|
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22392
|
2024-11-21 14:13 |
2021-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208974
|
4.8 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker..
|
CWE-79
Cross-site Scripting
|
CVE-2020-22732
|
2024-11-21 14:13 |
2021-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208975
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
The gf_dash_segmenter_probe_input function in GPAC v0.8 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-22352
|
2024-11-21 14:13 |
2021-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208976
|
6.1 |
MEDIUM
Network
|
nukeviet
|
nukeviet
|
Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22765
|
2024-11-21 14:13 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208977
|
8.8 |
HIGH
Network
|
flatpress
|
flatpress
|
Cross Site Request Forgery (CSRF) vulnerability in FlatPress 1.1 via the DeleteFile function in flat/admin.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-22761
|
2024-11-21 14:13 |
2021-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208978
|
4.8 |
MEDIUM
Network
|
naviwebs
|
navigatecms
|
Cross Site Scripting (XSS) vulnerability in NavigateCMS NavigateCMS 2.9 via the name="wrong_path_redirect" feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23243
|
2024-11-21 14:13 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208979
|
4.8 |
MEDIUM
Network
|
naviwebs
|
navigatecms
|
Cross Site Scripting (XSS) vulnerability in NavigateCMS 2.9 when performing a Create or Edit via the Tools feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23242
|
2024-11-21 14:13 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208980
|
4.8 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
Cross Site Scripting (XSS) vulnerability in CMS Made Simple 2.2.14 in "Extra" via 'News > Article" feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23241
|
2024-11-21 14:13 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|