Search Results (88023 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-19924 1 Issuehunt 1 Boostnote 2024-11-21 5.4 Medium
In Boostnote 0.12.1, exporting to PDF contains opportunities for XSS attacks.
CVE-2020-19915 1 Wuzhicms 1 Wuzhicms 2024-11-21 6.1 Medium
Cross Site Scripting (XSS vulnerability exists in WUZHI CMS 4.1.0 via the mailbox username in index.php.
CVE-2020-19914 1 Xiuno 1 Xiunobbs 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) in xiunobbs 4.0.4 allows remote attackers to execute arbitrary web script or HTML via the attachment upload function.
CVE-2020-19907 1 Mitre 1 Caldera 2024-11-21 8.8 High
A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.
CVE-2020-19891 1 Dbhcms Project 1 Dbhcms 2024-11-21 7.2 High
DBHcms v1.2.0 has an Arbitrary file write vulnerability in dbhcms\mod\mod.editor.php $_POST['updatefile'] is filename and $_POST['tinymce_content'] is file content, there is no filter function for security. A remote authenticated admin user can exploit this vulnerability to get a webshell.
CVE-2020-19887 1 Dbhcms Project 1 Dbhcms 2024-11-21 4.8 Medium
DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
CVE-2020-19885 1 Dbhcms Project 1 Dbhcms 2024-11-21 4.8 Medium
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
CVE-2020-19884 1 Dbhcms Project 1 Dbhcms 2024-11-21 4.8 Medium
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcms\mod\mod.domain.edit.php line 119.
CVE-2020-19883 1 Dbhcms Project 1 Dbhcms 2024-11-21 4.8 Medium
DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcms\mod\mod.users.view.php line 57 for user_login, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
CVE-2020-19882 1 Dbhcms Project 1 Dbhcms 2024-11-21 4.8 Medium
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in dbhcms\mod\mod.menus.edit.php line 83 and in dbhcms\mod\mod.menus.view.php line 111, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
CVE-2020-19881 1 Dbhcms Project 1 Dbhcms 2024-11-21 4.8 Medium
DBHcms v1.2.0 has a reflected xss vulnerability as there is no security filter in dbhcms\mod\mod.selector.php line 108 for $_GET['return_name'] parameter, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
CVE-2020-19880 1 Dbhcms Project 1 Dbhcms 2024-11-21 6.1 Medium
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function form 'Name' in dbhcms\types.php, A remote unauthenticated attacker can exploit this vulnerability to hijack other users.
CVE-2020-19879 1 Dbhcms Project 1 Dbhcms 2024-11-21 6.1 Medium
DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter of $_GET['dbhcms_pid'] variable in dbhcms\page.php line 107,
CVE-2020-19855 1 Phpwcms 1 Phpwcms 2024-11-21 6.1 Medium
phpwcms v1.9 contains a cross-site scripting (XSS) vulnerability in /image_zoom.php.
CVE-2020-19766 1 Tokenerc20 Project 1 Tokenerc20 2024-11-21 7.5 High
The time check operation of PepeAuctionSale 1.0 can be rendered ineffective by assigning a large number to the _duration variable, compromising access control to the application.
CVE-2020-19762 1 Carrier 1 Webctrl System 2024-11-21 6.1 Medium
Automated Logic Corporation (ALC) WebCTRL System 6.5 and prior allows remote attackers to execute any JavaScript code via a XSS payload for the first parameter in a GET request.
CVE-2020-19721 1 Axiosys 1 Bento4 2024-11-21 6.5 Medium
A heap buffer overflow vulnerability in Ap4TrunAtom.cpp of Bento 1.5.1-628 may lead to an out-of-bounds write while running mp42aac, leading to system crashes and a denial of service (DOS).
CVE-2020-19709 1 Feehi 1 Feehicms 2024-11-21 6.1 Medium
Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.
CVE-2020-19704 1 Spring-boot-admin Project 1 Spring-boot-admin 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability via ResourceController.java in spring-boot-admin as of 20190710 allows attackers to execute arbitrary web scripts or HTML.
CVE-2020-19703 1 Dzzoffice 1 Dzzoffice 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.