Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability in bycms v1.3 via admin.php/systems/index/module_id/70/group_id/1.html.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Stored cross-site scripting (XSS) vulnerability in the Copyright Text field found in the Application page under the Configuration menu in Rukovoditel 2.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to /rukovoditel_2.4.1/index.php?module=configuration/save&redirect_to=configuration/application.
Published Aug 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability exists in 711cms v1.0.7 that can add an admin account via admin.php?c=Admin&m=content.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under the General menu via a crafted website name by doing an authenticated POST HTTP request to admin/tags/create.
Published Aug 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in Hucart CMS 5.7.4 via the basic information field found in the avatar usd_image field.
Published Aug 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
File Upload vulnerabilty in AikCms v2.0.0 in poster_edit.php because the background file management office does not verify the uploaded file.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A reflected cross-site scripting (XSS) vulnerability in the /plugin/ajax.php component of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.
Published Aug 30, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability exists in bycms v1.3.0 that can add an admin account via admin.php/ucenter/add.html.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability exists in bycms v3.0.4 via the title parameter in the edit function in Document.php.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability exists in YUNUCMS 1.1.9 via the param parameter in the insertContent function in ContentModel.php.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability in AikCms 2.0.0 in video_list.php, which can let a malicious user delete movie information.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.
Published Aug 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability exists in UKCMS v1.1.10 via data in the index function in Single.php
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in Hucart CMS 5.7.4 via the purchase enquiry field found in the Message con_content field.
Published Aug 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability exists in qdPM 9.1 in the Heading field found in the Login Page page under the General menu via a crafted website name by doing an authenticated POST HTTP request to /qdPM_9.1/index.php/configuration.
Published Aug 26, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Request Forgery (CSRF) vulnerability exists in DamiCMS v6.0.6 that can add an admin account via admin.php?s=/Admin/doadd.
Published Aug 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account passwords.
Published Aug 30, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability exists in PopojiCMS 2.0.1 in admin.php?mod=menumanager--------- edit menu.
Published Aug 25, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Multiple stored cross-site scripting (XSS) vulnerabilities in the Sections module of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.
Published Aug 30, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell.
Published Aug 30, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily delete admin accounts.
Published Aug 30, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL injection.
Published Aug 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform.
Published Aug 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.
Published Aug 30, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.
Published Aug 17, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in the /uploads/dede component of DedeCMS V5.7SP2 allows attackers to upload a webshell in HTM format.
Published Aug 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection.
Published Aug 27, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAPOL Msg4/4.
Published Aug 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.
Published Aug 10, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.
Published Aug 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.
Published Aug 13, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information that does not belong unencrypted in the database.
Published Aug 11, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_parse_algorithmidentifier in libr/util/x509.c. This is due to a malformed object identifier in IMAGE_DIRECTORY_ENTRY_SECURITY.
Published Aug 11, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ECDSA/EC/Point.pm in Crypt::Perl before 0.33 does not properly consider timing attacks against the EC point multiplication algorithm.
Published Aug 10, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in certain configurations of GNOME gnome-shell through 3.36.4. When logging out of an account, the password box from the login dialog reappears with the password still visible. If the user had decided to have the password shown in cleartext at login time, it is then visible for a brief moment upon a logout. (If the password were never shown in cleartext, only the password length is revealed.)
Published Aug 11, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mibew Messenger before 3.2.7 allows XSS via a crafted user name.
Published Aug 10, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
TinyMCE before 4.9.7 and 5.x before 5.1.4 allows XSS in the core parser, the paste plugin, and the visualchars plugin by using the clipboard or APIs to insert content into the editor.
Published Aug 10, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Lack of authentication in the network relays used in MEGVII Koala 2.9.1-c3s allows attackers to grant physical access to anyone by sending packet data to UDP port 5000.
Published Aug 14, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filename that lacks an extension.
Published Aug 11, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
CMS Made Simple 2.2.14 allows Authenticated Arbitrary File Upload because the File Manager does not block .ptar files, a related issue to CVE-2017-16798.
Published Aug 14, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
flatCore before 1.5.7 allows XSS by an admin via the acp/acp.php?tn=pages&sub=edit&editpage=1 page_linkname, page_title, page_content, or page_extracontent parameter, or the acp/acp.php?tn=system&sub=sys_pref prefs_pagename, prefs_pagetitle, or prefs_pagesubtitle parameter.
Published Aug 9, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Dashboards and progressiveProfileForms in ForgeRock Identity Manager before 7.0.0 are vulnerable to stored XSS. The vulnerability affects versions 6.5.0.4, 6.0.0.6.
Published Aug 31, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHP-Fusion 9.03 allows XSS via the error_log file.
Published Aug 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate users to administrators, delete users, and download user faces from the database.
Published Aug 14, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
flatCore before 1.5.7 allows upload and execution of a .php file by an admin.
Published Aug 9, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.
Published Aug 19, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHP-Fusion 9.03 allows XSS on the preview page.
Published Aug 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder.
Published Aug 12, 2020 · Updated Aug 4, 2024
Medium · CVSS 6
This vulnerability allows local attackers to disclose sensitive informations on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the VGA virtual device. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated array. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute code in the context of the hypervisor. Was ZDI-CAN-11363.
Published Aug 25, 2020 · Updated Aug 4, 2024