Search Results (325056 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-19957 1 Zzcms 1 Zzcms 2024-11-21 7.5 High
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the id parameter on the /dl/dl_print.php page.
CVE-2020-19954 1 S-cms 1 S-cms 2024-11-21 7.5 High
An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.
CVE-2020-19952 1 Jbt 1 Live \(github-flavored\) Markdown Editor 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in Rendering Engine in jbt Markdown Editor thru commit 2252418c27dffbb35147acd8ed324822b8919477, allows remote attackers to execute arbirary code via crafted payload or opening malicious .md file.
CVE-2020-19951 1 Yzmcms 1 Yzmcms 2024-11-21 8.8 High
A cross-site request forgery (CSRF) in /controller/pay.class.php of YzmCMS v5.5 allows attackers to access sensitive components of the application.
CVE-2020-19950 1 Yzmcms 1 Yzmcms 2024-11-21 4.8 Medium
A cross-site scripting (XSS) vulnerability in the /banner/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.
CVE-2020-19949 1 Yzmcms 1 Yzmcms 2024-11-21 4.8 Medium
A cross-site scripting (XSS) vulnerability in the /link/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.
CVE-2020-19924 1 Issuehunt 1 Boostnote 2024-11-21 5.4 Medium
In Boostnote 0.12.1, exporting to PDF contains opportunities for XSS attacks.
CVE-2020-19915 1 Wuzhicms 1 Wuzhicms 2024-11-21 6.1 Medium
Cross Site Scripting (XSS vulnerability exists in WUZHI CMS 4.1.0 via the mailbox username in index.php.
CVE-2020-19914 1 Xiuno 1 Xiunobbs 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) in xiunobbs 4.0.4 allows remote attackers to execute arbitrary web script or HTML via the attachment upload function.
CVE-2020-19909 1 Haxx 1 Curl 2024-11-21 3.3 Low
Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large value as the retry delay. NOTE: many parties report that this has no direct security impact on the curl user; however, it may (in theory) cause a denial of service to associated systems or networks if, for example, --retry-delay is misinterpreted as a value much smaller than what was intended. This is not especially plausible because the overflow only happens if the user was trying to specify that curl should wait weeks (or longer) before trying to recover from a transient error.
CVE-2020-19907 1 Mitre 1 Caldera 2024-11-21 8.8 High
A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.
CVE-2020-19896 1 1234n 1 Minicms 2024-11-21 9.8 Critical
File inclusion vulnerability in Minicms v1.9 allows remote attackers to execute arbitary PHP code via post-edit.php.
CVE-2020-19891 1 Dbhcms Project 1 Dbhcms 2024-11-21 7.2 High
DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename and $_POST['tinymce_content'] is file content, there is no filter function for security. A remote authenticated admin user can exploit this vulnerability to get a webshell.
CVE-2020-19890 1 Dbhcms Project 1 Dbhcms 2024-11-21 4.9 Medium
DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter function for security, you can read any file's content.
CVE-2020-19889 1 Dbhcms Project 1 Dbhcms 2024-11-21 8.8 High
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.
CVE-2020-19888 1 Dbhcms Project 1 Dbhcms 2024-11-21 5.9 Medium
DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php for empty cache operation. This vulnerability can be exploited to empty a table.
CVE-2020-19887 1 Dbhcms Project 1 Dbhcms 2024-11-21 4.8 Medium
DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
CVE-2020-19886 1 Dbhcms Project 1 Dbhcms 2024-11-21 8.1 High
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can delete any menu.
CVE-2020-19885 1 Dbhcms Project 1 Dbhcms 2024-11-21 4.8 Medium
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
CVE-2020-19884 1 Dbhcms Project 1 Dbhcms 2024-11-21 4.8 Medium
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php line 119.