|
210361
|
4.8 |
MEDIUM
Network
|
rockoa
|
rockoa
|
RockOA V1.9.8 is affected by a cross-site scripting (XSS) vulnerability which allows remote attackers to send malicious code to the administrator and execute JavaScript code, because webmain/flow/inp…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21147
|
2024-11-21 14:12 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210362
|
6.1 |
MEDIUM
Network
|
feehi
|
feehi_cms
|
Feehi CMS 2.0.8 is affected by a cross-site scripting (XSS) vulnerability. When the user name is inserted as JavaScript code, browsing the post will trigger the XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-21146
|
2024-11-21 14:12 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210363
|
5.9 |
MEDIUM
Network
|
st ietf
|
stm32cubemx stm32cubeide stm32cubeprogrammer stm32cubemonitor stm32cubel1 stm32cubel0 stm32cubel4 stm32cubel5 stm32cubef0 stm32cubef1 stm32cubef2 stm32cubef3 stm32…
|
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's orac…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-20949
|
2024-11-21 14:12 |
2021-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210364
|
5.9 |
MEDIUM
Network
|
ietf microchip
|
public_key_cryptography_standards_\#1 microchip_libraries_for_applications
|
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack …
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-20950
|
2024-11-21 14:12 |
2021-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210365
|
6.5 |
MEDIUM
Network
|
xiph.org stepmania
|
libvorbis stepmania
|
lib/codebook.c in libvorbis before 1.3.6, as used in StepMania 5.0.12 and other products, has insufficient array bounds checking via a crafted OGG file. NOTE: this may overlap CVE-2018-5146.
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-20412
|
2024-11-21 14:12 |
2020-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210366
|
9.8 |
CRITICAL
Network
|
seacms
|
seacms
|
SQL injection vulnerability in SeaCMS 10.1 (2020.02.08) via the id parameter in an edit action to admin_members_group.php.
|
CWE-89
SQL Injection
|
CVE-2020-21378
|
2024-11-21 14:12 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210367
|
9.8 |
CRITICAL
Network
|
yunyecms
|
yunyecms
|
SQL injection vulnerability in yunyecms V2.0.1 via the selcart parameter.
|
CWE-89
SQL Injection
|
CVE-2020-21377
|
2024-11-21 14:12 |
2020-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210368
|
9.8 |
CRITICAL
Network
|
weiphp
|
weiphp
|
SQL injection vulnerability in the wp_where function in WeiPHP 5.0.
|
CWE-89
SQL Injection
|
CVE-2020-20300
|
2024-11-21 14:12 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210369
|
7.5 |
HIGH
Network
|
weiphp
|
weiphp
|
WeiPHP 5.0 does not properly restrict access to pages, related to using POST.
|
NVD-CWE-noinfo
|
CVE-2020-20299
|
2024-11-21 14:12 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210370
|
9.8 |
CRITICAL
Network
|
zzzcms
|
zzzphp
|
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.
|
CWE-94
Code Injection
|
CVE-2020-20298
|
2024-11-21 14:12 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|