Unknown · CVSS Not scored
controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS.
Published Aug 31, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Sliced Invoices plugin for WordPress 3.8.2 and earlier allows unauthenticated information disclosure and authenticated SQL injection via core/class-sliced.php.
Published Aug 31, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The includes/gateways/stripe/includes/admin/admin-actions.php in GiveWP plugin through 2.5.9 for WordPress allows unauthenticated settings change.
Published Aug 31, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.
Published Aug 21, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Nuishop v2.3 contains a SQL injection vulnerability in /goods/getGoodsListByConditions/.
Published Aug 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admin&c=Filemanager&a=newfile&lang=cn.
Published Aug 19, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
lara-google-analytics.php in Lara Google Analytics plugin through 2.0.4 for WordPress allows authenticated stored XSS.
Published Aug 31, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
IEC104 v1.0 contains a stack-buffer overflow in the parameter Iec10x_Sta_Addr.
Published Aug 31, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A heap buffer-overflow in the client_example1.c component of libiec_iccp_mod v1.5 leads to a denial of service (DOS).
Published Aug 31, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.
Published Aug 31, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can delete any menu.
Published Aug 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.
Published Aug 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DBHcms v1.2.0 has an unauthorized operation vulnerability because there's no access control at line 175 of dbhcms\page.php for empty cache operation. This vulnerability can be exploited to empty a table.
Published Aug 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in dbhcms\mod\mod.menus.edit.php line 83 and in dbhcms\mod\mod.menus.view.php line 111, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
Published Aug 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A SQL injection vulnerability in admin.php of DOYOCMS 2.3 allows attackers to execute arbitrary SQL commands via the orders[] parameter.
Published Aug 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stored cross-site scripting (XSS) vulnerability via ResourceController.java in spring-boot-admin as of 20190710 allows attackers to execute arbitrary web scripts or HTML.
Published Aug 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DBHcms v1.2.0 has a reflected xss vulnerability as there is no security filter in dbhcms\mod\mod.selector.php line 108 for $_GET['return_name'] parameter, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
Published Aug 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
thinkphp-zcms as of 20190715 allows SQL injection via index.php?m=home&c=message&a=add.
Published Aug 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function form 'Name' in dbhcms\types.php, A remote unauthenticated attacker can exploit this vulnerability to hijack other users.
Published Aug 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.
Published Aug 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
Published Aug 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
Published Aug 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter of $_GET['dbhcms_pid'] variable in dbhcms\page.php line 107,
Published Aug 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter function for security, you can read any file's content.
Published Aug 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename and $_POST['tinymce_content'] is file content, there is no filter function for security. A remote authenticated admin user can exploit this vulnerability to get a webshell.
Published Aug 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php line 119.
Published Aug 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.
Published Aug 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for user_login, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
Published Aug 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Published Aug 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for index.php?dbhcms_pid=-70 can add a user.
Published Aug 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
DBHcms v1.2.0 has a sensitive information leaks vulnerability as there is no security access control in /dbhcms/ext/news/ext.news.be.php, A remote unauthenticated attacker can exploit this vulnerability to get path information.
Published Aug 24, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability exists in Eyoucms 1.3.6 that can add an admin account via /login.php?m=admin&c=Admin&a=admin_add&lang=cn.
Published Aug 18, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php.
Published Aug 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Published Aug 22, 2023 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A vulnerability in the vae_admin_rule database table of vaeThink v1.0.1 allows attackers to execute arbitrary code via a crafted payload in the condition parameter.
Published Aug 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowing attackers to escalate privileges.
Published Aug 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in /fileupload.php of hdcms 5.7 allows attackers to execute arbitrary code via a crafted file.
Published Aug 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in the avatar upload function of vaeThink v1.0.1 allows attackers to open a webshell via changing uploaded file suffixes to ".php".
Published Aug 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file.
Published Aug 23, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.
Published Aug 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Title" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-management&action=add'.
Published Aug 31, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
EARCLINK ESPCMS-P8 was discovered to contain a SQL injection vulnerability in the espcms_web/Search.php component via the attr_array parameter. This vulnerability allows attackers to access sensitive database information.
Published Aug 24, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file.
Published Aug 23, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Request Forgey (CSRF) in iWebShop v5.3 allows remote atatckers to execute arbitrary code via malicious POST request to the component '/index.php?controller=system&action=admin_edit_act'.
Published Aug 31, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Published Aug 22, 2023 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory traversal and access sensitive information.
Published Aug 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/PdfDictionary.cpp:65'.
Published Aug 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Published Aug 22, 2023 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Description" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-management&action=add'.
Published Aug 31, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Directory Traversal in Skycaiji v1.3 allows remote attackers to obtain sensitive information via the component 'index.php?m=admin&c=Tool&a=log&file=D%3A%5CphpStudy%5CWWW%5Cindex.php'.
Published Aug 20, 2021 · Updated Aug 4, 2024