|
209251
|
7.5 |
HIGH
Network
|
ninjateam
|
video_downloader_for_tiktok
|
Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk…
|
CWE-22
Path Traversal
|
CVE-2020-24143
|
2024-11-21 14:14 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209252
|
9.8 |
CRITICAL
Network
|
ninjateam
|
video_downloader_for_tiktok
|
Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web app…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-24142
|
2024-11-21 14:14 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209253
|
5.3 |
MEDIUM
Network
|
wp-downloadmanager_project
|
wp-downloadmanager
|
Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the file_remote p…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-24141
|
2024-11-21 14:14 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209254
|
6.5 |
MEDIUM
Network
|
eram
|
myfax150_firmware myfax250_firmware myfax450_firmware
|
myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-24038
|
2024-11-21 14:14 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209255
|
5.4 |
MEDIUM
Network
|
monstra
|
monstra_cms
|
Cross Site Scripting vulnerabilty in Monstra CMS 3.0.4 via the page feature in admin/index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23697
|
2024-11-21 14:14 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209256
|
8.6 |
HIGH
Network
|
webport_cms_project
|
webport_cms
|
Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download.
|
CWE-22
Path Traversal
|
CVE-2020-23715
|
2024-11-21 14:14 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209257
|
9.8 |
CRITICAL
Network
|
naviwebs
|
navigate_cms
|
SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php.
|
CWE-89
SQL Injection
|
CVE-2020-23711
|
2024-11-21 14:14 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209258
|
5.4 |
MEDIUM
Network
|
limesurvey
|
limesurvey
|
Cross Site Scripting (XSS) vulneraiblity in LimeSurvey 4.2.5 on textbox via the Notifications & data feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23710
|
2024-11-21 14:14 |
2021-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209259
|
6.1 |
MEDIUM
Network
|
catfish-cms
|
catfish_cms
|
A cross site scripting (XSS) vulnerability in Catfish CMS 4.9.90 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "announcement_gonggao" parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23962
|
2024-11-21 14:14 |
2021-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209260
|
5.5 |
MEDIUM
Local
|
intel
|
baseboard_management_controller_firmware
|
Improper initialization in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable deni…
|
CWE-665
Improper Initialization
|
CVE-2020-24475
|
2024-11-21 14:14 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|