Search Results (331262 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-21357 1 Popojicms 1 Popojicms 2024-11-21 6.1 Medium
A stored cross site scripting (XSS) vulnerability in /admin.php?mod=user&act=addnew of PopojiCMS 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the E-Mail field.
CVE-2020-21356 1 Popojicms 1 Popojicms 2024-11-21 5.3 Medium
An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.
CVE-2020-21353 1 Get-simple 1 Getsimplecms 2024-11-21 5.4 Medium
A stored cross site scripting (XSS) vulnerability in /admin/snippets.php of GetSimple CMS 3.4.0a allows attackers to execute arbitrary web scripts or HTML via crafted payload in the Edit Snippets module.
CVE-2020-21345 1 Halo 1 Halo 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in Halo 1.1.3 via post publish components in the manage panel, which lets a remote malicious user execute arbitrary code.
CVE-2020-21342 1 Zzcms 1 Zzcms 2024-11-21 7.5 High
Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.
CVE-2020-21333 1 Publiccms 1 Publiccms 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case.
CVE-2020-21322 1 Feehi 1 Feehicms 2024-11-21 9.8 Critical
An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2020-21321 1 Emlog 1 Emlog 2024-11-21 4.3 Medium
emlog v6.0 contains a Cross-Site Request Forgery (CSRF) via /admin/link.php?action=addlink, which allows attackers to arbitrarily add articles.
CVE-2020-21316 1 Zrlog 1 Zrlog 2024-11-21 6.1 Medium
A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain access to the admin panel.
CVE-2020-21266 1 Broadleafcommerce 1 Broadleaf Commerce 2024-11-21 6.1 Medium
Broadleaf Commerce 5.1.14-GA is affected by cross-site scripting (XSS) due to a slow HTTP post vulnerability.
CVE-2020-21250 1 Cszcms 1 Csz Cms 2024-11-21 9.8 Critical
CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.
CVE-2020-21244 1 Frontaccounting 1 Frontaccounting 2024-11-21 4.9 Medium
An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via admin/inst_lang.php.
CVE-2020-21238 1 Chshcms 1 Cscms 2024-11-21 9.8 Critical
An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.
CVE-2020-21237 1 8cms 1 Ljcms 2024-11-21 9.8 Critical
An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks.
CVE-2020-21236 1 Damicms 1 Damicms 2024-11-21 8.8 High
A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtaining a user's session cookie.
CVE-2020-21228 1 Jizhicms 1 Jizhicms 2024-11-21 6.1 Medium
JIZHICMS 1.5.1 contains a cross-site scripting (XSS) vulnerability in the component /user/release.html, which allows attackers to arbitrarily add an administrator cookie.
CVE-2020-21224 1 Inspur 1 Clusterengine 2024-11-21 9.8 Critical
A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control server
CVE-2020-21180 1 Koa2-blog Project 1 Koa2-blog 2024-11-21 9.8 Critical
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signup page.
CVE-2020-21179 1 Koa2-blog Project 1 Koa2-blog 2024-11-21 9.8 Critical
Sql injection vulnerability in koa2-blog 1.0.0 allows remote attackers to Injecting a malicious SQL statement via the name parameter to the signin page.
CVE-2020-21176 1 Thinkjs 1 Thinkjs 2024-11-21 9.8 Critical
SQL injection vulnerability in the model.increment and model.decrement function in ThinkJS 3.2.10 allows remote attackers to execute arbitrary SQL commands via the step parameter.