Vulnerabilities (CVE)

Filtered by CWE-22
Total 7187 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-19902 1 Wcms 1 Wcms 2024-11-21 N/A 9.8 CRITICAL
Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter.
CVE-2020-19877 1 Dbhcms Project 1 Dbhcms 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
DBHcms v1.2.0 has a directory traversal vulnerability as there is no directory control function in directory /dbhcms/. A remote unauthenticated attacker can exploit this vulnerability to obtain server-sensitive information.
CVE-2020-19858 1 Plutinosoft 1 Platinum 2024-11-21 5.0 MEDIUM 7.5 HIGH
Platinum Upnp SDK through 1.2.0 has a directory traversal vulnerability. The attack could remote attack victim by sending http://ip:port/../privacy.avi URL to compromise a victim's privacy.
CVE-2020-19547 1 Popojicms 1 Popojicms 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php.
CVE-2020-19360 1 Fhem 1 Fhem 2024-11-21 5.0 MEDIUM 7.5 HIGH
Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a file, which can lead to sensitive information disclosure.
CVE-2020-19305 1 Metinfo 1 Metinfo 2024-11-21 7.5 HIGH 9.8 CRITICAL
An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowing attackers to escalate privileges.
CVE-2020-19304 1 Metinfo 1 Metinfo 2024-11-21 5.0 MEDIUM 7.5 HIGH
An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory traversal and access sensitive information.
CVE-2020-19154 1 Jflyfox 1 Jfinal Cms 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.
CVE-2020-19150 1 Jflyfox 1 Jfinal Cms 2024-11-21 5.5 MEDIUM 8.1 HIGH
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.
CVE-2020-19147 1 Jflyfox 1 Jfinal Cms 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.
CVE-2020-19146 1 Jflyfox 1 Jfinal Cms 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.
CVE-2020-18878 1 Skycaiji 1 Skycaiji 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Directory Traversal in Skycaiji v1.3 allows remote attackers to obtain sensitive information via the component 'index.php?m=admin&c=Tool&a=log&file=D%3A%5CphpStudy%5CWWW%5Cindex.php'.
CVE-2020-18665 1 Webport 1 Web Port 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Directory Traversal vulnerability in WebPort <=1.19.1 in tags of system settings.
CVE-2020-18438 1 Phpok 1 Phpok 2024-11-21 5.0 MEDIUM 7.5 HIGH
Directory traversal vulnerability in qinggan phpok 5.1, allows attackers to disclose sensitive information, via the title parameter to admin.php.
CVE-2020-18191 1 Get-simple 1 Getsimplecms 2024-11-21 6.4 MEDIUM 9.1 CRITICAL
GetSimpleCMS-3.3.15 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /GetSimpleCMS-3.3.15/admin/log.php
CVE-2020-18190 1 Bludit 1 Bludit 2024-11-21 6.4 MEDIUM 9.1 CRITICAL
Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/upload-profile-picture.
CVE-2020-18178 1 Hongcms Project 1 Hongcms 2024-11-21 7.5 HIGH 9.8 CRITICAL
Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the component "/hcms/admin/index.php/language/ajax."
CVE-2020-18127 1 Indexhibit 1 Indexhibit 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.
CVE-2020-18070 1 Idreamsoft 1 Icms 2024-11-21 6.4 MEDIUM 9.1 CRITICAL
Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP request to the "do_del()" method of the component "database.admincp.php".
CVE-2020-17564 1 Feifeicms 1 Feifeicms 2024-11-21 6.4 MEDIUM 9.1 CRITICAL
Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to the " Admin/DataAction.class.php" component.