|
210041
|
7.2 |
HIGH
Network
|
pluck-cms
|
pluck
|
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20969
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210042
|
7.2 |
HIGH
Network
|
pluck-cms
|
pluck
|
File upload vulnerability in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary code and access sensitive information via the theme.php file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20919
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210043
|
7.2 |
HIGH
Network
|
pluck-cms
|
pluck
|
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.
|
CWE-94
Code Injection
|
CVE-2020-20918
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210044
|
9.8 |
CRITICAL
Network
|
8cms
|
ljcms
|
File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20735
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210045
|
8.8 |
HIGH
Network
|
gilacms
|
gila_cms
|
Cross Site Request Forgery vulnerability in Gila GilaCMS v.1.11.4 allows a remote attacker to execute arbitrary code via the cm/update_rows/user parameter.
|
CWE-352
Origin Validation Error
|
CVE-2020-20726
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210046
|
9.8 |
CRITICAL
Network
|
pluck-cms
|
pluckcms
|
File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-20718
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210047
|
9.8 |
CRITICAL
Network
|
vim
|
vim
|
Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-20703
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210048
|
7.5 |
HIGH
Network
|
joyplus-cms_project
|
joyplus-cms
|
SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function.
|
CWE-89
SQL Injection
|
CVE-2020-20636
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210049
|
6.5 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
Cross Site Request Forgery found in yzCMS v.2.0 allows a remote attacker to execute arbitrary code via the token check function.
|
CWE-352
Origin Validation Error
|
CVE-2020-20502
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210050
|
7.2 |
HIGH
Network
|
opencart
|
opencart
|
SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the Fba plugin function in upload/admin/index.php.
|
CWE-89
SQL Injection
|
CVE-2020-20491
|
2024-11-21 14:12 |
2023-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|