|
215001
|
6.1 |
MEDIUM
Network
|
dhcms_project
|
dhcms
|
A Cross SIte Scripting (XSS) vulnerability exists in Dhcms 2017-09-18 in guestbook via the message board, which could let a remote malicious user execute arbitrary code.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19274
|
2024-11-21 14:09 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215002
|
8.8 |
HIGH
Network
|
phpok
|
phpok
|
A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious user execute arbitrary code.
|
CWE-352
Origin Validation Error
|
CVE-2020-19199
|
2024-11-21 14:09 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215003
|
9.8 |
CRITICAL
Network
|
shopxo
|
shopxo
|
Incorrect Access Control in Shopxo v1.4.0 and v1.5.0 allows remote attackers to gain privileges in "/index.php" by manipulating the parameter "user_id" in the HTML request.
|
NVD-CWE-Other
|
CVE-2020-19778
|
2024-11-21 14:09 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215004
|
9.8 |
CRITICAL
Network
|
coreftp
|
core_ftp
|
Buffer overflow vulnerability in Core FTP Server v1.2 Build 583, via a crafted username.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-19596
|
2024-11-21 14:09 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215005
|
7.5 |
HIGH
Network
|
coreftp
|
core_ftp
|
Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-19595
|
2024-11-21 14:09 |
2021-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215006
|
5.4 |
MEDIUM
Network
|
mblog_project
|
mblog
|
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19619
|
2024-11-21 14:09 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215007
|
5.4 |
MEDIUM
Network
|
mblog_project
|
mblog
|
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19618
|
2024-11-21 14:09 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215008
|
5.4 |
MEDIUM
Network
|
mblog_project
|
mblog
|
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19617
|
2024-11-21 14:09 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215009
|
5.4 |
MEDIUM
Network
|
mblog_project
|
mblog
|
Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing.
|
CWE-79
Cross-site Scripting
|
CVE-2020-19616
|
2024-11-21 14:09 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215010
|
7.5 |
HIGH
Network
|
flycms_project
|
flycms
|
Server Side Request Forgery (SSRF) vulnerability in saveUrlAs function in ImagesService.java in sunkaifei FlyCMS version 20190503.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-19613
|
2024-11-21 14:09 |
2021-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|