|
210841
|
8.8 |
HIGH
Network
|
pyres
|
termod4_firmware
|
Remote code execution in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to arbitrary commands as root on the devices.
|
NVD-CWE-noinfo
|
CVE-2020-23160
|
2024-11-21 14:13 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210842
|
5.4 |
MEDIUM
Network
|
apfell_project
|
apfell
|
APfell 1.4 is vulnerable to authenticated reflected cross-site scripting (XSS) in /apiui/command_ through the payloadtypes_callback function, which allows an attacker to steal remote admin/user sessi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23014
|
2024-11-21 14:13 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210843
|
7.2 |
HIGH
Network
|
feehi
|
feehi_cms
|
Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution. After an administrator logs in, open the administrator image upload page to pote…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-22643
|
2024-11-21 14:13 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210844
|
8.8 |
HIGH
Network
|
anchorcms
|
anchor_cms
|
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
|
CWE-352
Origin Validation Error
|
CVE-2020-23342
|
2024-11-21 14:13 |
2021-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210845
|
6.8 |
MEDIUM
Network
|
pixelimity
|
pixelimity
|
Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.
|
CWE-352
Origin Validation Error
|
CVE-2020-23522
|
2024-11-21 14:13 |
2021-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210846
|
9.8 |
CRITICAL
Network
|
thinkadmin
|
thinkadmin
|
An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wechat/controller/api/Push.php, which may lead to arbitrary …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-23653
|
2024-11-21 14:13 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210847
|
6.1 |
MEDIUM
Network
|
wdja
|
wdja_cms
|
Cross-site request forgery (CSRF) in admin/global/manage.php in WDJA CMS 1.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via the tongji parameter.
|
CWE-352
Origin Validation Error
|
CVE-2020-23631
|
2024-11-21 14:13 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210848
|
8.8 |
HIGH
Network
|
zzcms
|
zzcms
|
A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
|
CWE-89
SQL Injection
|
CVE-2020-23630
|
2024-11-21 14:13 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210849
|
6.1 |
MEDIUM
Network
|
jizhicms
|
jizhicms
|
XSS exists in JIZHICMS 1.7.1 via index.php/Error/index?msg={XSS] to Home/c/ErrorController.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23644
|
2024-11-21 14:13 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210850
|
6.1 |
MEDIUM
Network
|
jizhicms
|
jizhicms
|
XSS exists in JIZHICMS 1.7.1 via index.php/Wechat/checkWeixin?signature=1&echostr={XSS] to Home/c/WechatController.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-23643
|
2024-11-21 14:13 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|