|
209161
|
9.8 |
CRITICAL
Network
|
thinkadmin
|
thinkadmin
|
An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wechat/controller/api/Push.php, which may lead to arbitrary …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-23653
|
2024-11-21 14:13 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209162
|
6.1 |
MEDIUM
Network
|
wdja
|
wdja_cms
|
Cross-site request forgery (CSRF) in admin/global/manage.php in WDJA CMS 1.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via the tongji parameter.
|
CWE-352
Origin Validation Error
|
CVE-2020-23631
|
2024-11-21 14:13 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209163
|
8.8 |
HIGH
Network
|
zzcms
|
zzcms
|
A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
|
CWE-89
SQL Injection
|
CVE-2020-23630
|
2024-11-21 14:13 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209164
|
6.1 |
MEDIUM
Network
|
jizhicms
|
jizhicms
|
XSS exists in JIZHICMS 1.7.1 via index.php/Error/index?msg={XSS] to Home/c/ErrorController.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23644
|
2024-11-21 14:13 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209165
|
6.1 |
MEDIUM
Network
|
jizhicms
|
jizhicms
|
XSS exists in JIZHICMS 1.7.1 via index.php/Wechat/checkWeixin?signature=1&echostr={XSS] to Home/c/WechatController.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23643
|
2024-11-21 14:13 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209166
|
2.3 |
LOW
Local
|
gigamon
|
gigavue-os
|
GigaVUE-OS (GVOS) 5.4 - 5.9 uses a weak algorithm for a hash stored in internal database.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-23250
|
2024-11-21 14:13 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209167
|
4.7 |
MEDIUM
Network
|
gigamon
|
gigavue-os
|
GigaVUE-OS (GVOS) 5.4 - 5.9 stores a Redis database password in plaintext.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-23249
|
2024-11-21 14:13 |
2021-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209168
|
7.5 |
HIGH
Network
|
veno_file_manager_project
|
veno_file_manager
|
Veno File Manager 3.5.6 is affected by a directory traversal vulnerability. Using the traversal allows an attacker to download sensitive files from the server.
|
CWE-22
Path Traversal
|
CVE-2020-22550
|
2024-11-21 14:13 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209169
|
9.8 |
CRITICAL
Network
|
jsonpickle_project
|
jsonpickle
|
jsonpickle through 1.4.1 allows remote code execution during deserialization of a malicious payload through the decode() function. Note: It has been argued that this is expected and clearly documente…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-22083
|
2024-11-21 14:13 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209170
|
7.2 |
HIGH
Network
|
txjia
|
imcat
|
imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-23520
|
2024-11-21 14:13 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|