|
209611
|
5.4 |
MEDIUM
Network
|
ibexa
|
ezpublish_legacy ezpublish_platform
|
Cross Site Scripting vulnerabiltiy in eZ Systems AS eZPublish Platform v.5.4 and eZ Publish Legacy v.5.4 allows a remote authenticated attacker to execute arbitrary code via the video-js.swf.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23065
|
2024-11-21 14:13 |
2023-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209612
|
6.1 |
MEDIUM
Network
|
alinto
|
sogo_web_mail
|
Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user reads an email containing malicious code.
|
CWE-79
Cross-site Scripting
|
CVE-2020-22402
|
2024-11-21 14:13 |
2023-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209613
|
7.1 |
HIGH
Network
|
yershop_project
|
yershop
|
Insecure Permissons vulnerability found in Shop_CMS YerShop all versions allows a remote attacker to escalate privileges via the cover_id parameter.
|
CWE-269
Improper Privilege Management
|
CVE-2020-23362
|
2024-11-21 14:13 |
2023-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209614
|
8.8 |
HIGH
Network
|
mingsoft
|
mcms
|
File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-22755
|
2024-11-21 14:13 |
2023-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209615
|
6.5 |
MEDIUM
Network
|
beescms
|
beescms
|
Cross Site Request Forgery (CSRF) vulnerability in beescms v4 allows attackers to delete the administrator account via crafted request to /admin/admin_admin.php.
|
CWE-352
Origin Validation Error
|
CVE-2020-22334
|
2024-11-21 14:13 |
2023-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209616
|
7.8 |
HIGH
Local
|
redox-os
|
redox
|
redox-os v0.1.0 was discovered to contain a use-after-free bug via the gethostbyaddr() function at /src/header/netdb/mod.rs.
|
CWE-416
Use After Free
|
CVE-2020-22429
|
2024-11-21 14:13 |
2023-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209617
|
6.1 |
MEDIUM
Network
|
boxbilling
|
boxbilling
|
Cross Site Scripting (XSS) vulnerability in BoxBilling 4.19, 4.19.1, 4.20, and 4.21 allows remote attackers to run arbitrary code via the message field on the submit new ticket form.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23647
|
2024-11-21 14:13 |
2023-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209618
|
6.1 |
MEDIUM
Network
|
zblogcn
|
zblogphp
|
Cross Site Scripting vulnerability found in ZblogCN ZblogPHP v.1.0 allows a local attacker to execute arbitrary code via a crafted payload in title parameter of the module management model.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23327
|
2024-11-21 14:13 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209619
|
7.5 |
HIGH
Network
|
jsish
|
jsish
|
An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the StringReplaceCmd function in the src/jsiChar.c file.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-23260
|
2024-11-21 14:13 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209620
|
7.5 |
HIGH
Network
|
jsish
|
jsish
|
An issue found in Jsish v.3.0.11 and before allows an attacker to cause a denial of service via the Jsi_Strlen function in the src/jsiChar.c file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-23259
|
2024-11-21 14:13 |
2023-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|