|
209251
|
7.2 |
HIGH
Network
|
pluck-cms
|
pluck
|
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.
|
CWE-94
Code Injection
|
CVE-2020-20918
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209252
|
9.8 |
CRITICAL
Network
|
8cms
|
ljcms
|
File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20735
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209253
|
8.8 |
HIGH
Network
|
gilacms
|
gila_cms
|
Cross Site Request Forgery vulnerability in Gila GilaCMS v.1.11.4 allows a remote attacker to execute arbitrary code via the cm/update_rows/user parameter.
|
CWE-352
Origin Validation Error
|
CVE-2020-20726
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209254
|
9.8 |
CRITICAL
Network
|
pluck-cms
|
pluckcms
|
File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20718
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209255
|
9.8 |
CRITICAL
Network
|
vim
|
vim
|
Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-20703
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209256
|
7.5 |
HIGH
Network
|
joyplus-cms_project
|
joyplus-cms
|
SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function.
|
CWE-89
SQL Injection
|
CVE-2020-20636
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209257
|
6.5 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
Cross Site Request Forgery found in yzCMS v.2.0 allows a remote attacker to execute arbitrary code via the token check function.
|
CWE-352
Origin Validation Error
|
CVE-2020-20502
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209258
|
7.2 |
HIGH
Network
|
opencart
|
opencart
|
SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the Fba plugin function in upload/admin/index.php.
|
CWE-89
SQL Injection
|
CVE-2020-20491
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209259
|
9.8 |
CRITICAL
Network
|
wuzhicms
|
wuzhicms
|
SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.
|
CWE-89
SQL Injection
|
CVE-2020-20413
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209260
|
7.5 |
HIGH
Network
|
kilo_project
|
kilo
|
Buffer Overflow vulnerability in Antirez Kilo before commit 7709a04ae8520c5b04d261616098cebf742f5a23 allows a remote attacker to cause a denial of service via the editorUpdateRow function in kilo.c.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-20335
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|