• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2020-19887
2020-08-25
N/A
4.8 MEDIUM
DBHcms v1.2.0 has a stored XSS vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_description']' variable in dbhcmsmodmod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
CVE-2020-19886
2020-08-25
N/A
8.1 HIGH
DBHcms v1.2.0 has no CSRF protection mechanism,as demonstrated by CSRF for an /index.php?dbhcms_pid=-80&deletemenu=9 can delete any menu.
CVE-2020-19885
2020-08-25
N/A
4.8 MEDIUM
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' variable in dbhcmsmodmod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
CVE-2020-19884
2020-08-25
N/A
4.8 MEDIUM
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function in dbhcmsmodmod.domain.edit.php line 119.
CVE-2020-19883
2020-08-25
N/A
4.8 MEDIUM
DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter in dbhcmsmodmod.users.view.php line 57 for user_login, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
CVE-2020-19882
2020-08-25
N/A
4.8 MEDIUM
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for 'menu_description' variable in dbhcmsmodmod.menus.edit.php line 83 and in dbhcmsmodmod.menus.view.php line 111, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
CVE-2020-19881
2020-08-25
N/A
4.8 MEDIUM
DBHcms v1.2.0 has a reflected xss vulnerability as there is no security filter in dbhcmsmodmod.selector.php line 108 for $_GET['return_name'] parameter, A remote authenticated with admin user can exploit this vulnerability to hijack other users.
CVE-2020-19880
2020-08-25
N/A
6.1 MEDIUM
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function form 'Name' in dbhcmstypes.php, A remote unauthenticated attacker can exploit this vulnerability to hijack other users.
CVE-2020-1988
Globalprotect, Paloaltonetworks
Pan-os, Pa-7050, Pa-7080, Bridgecrew_checkov, Content_update330, Cortex_xdr_agent, Cortex_xsoar, Demisto, Expedition, Expedition_migration_tool
2020-04-09
N/A
6.7 MEDIUM
An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:) or to Program Files directory to gain system privileges. This issue affects Palo Alto Networks GlobalProtect Agent 5.0 versions before 5.0.5; 4.1 versions before 4.1.13 on Windows;
CVE-2020-19879
2020-08-25
N/A
6.1 MEDIUM
DBHcms v1.2.0 has a stored xss vulnerability as there is no security filter of $_GET['dbhcms_pid'] variable in dbhcmspage.php line 107,
« Previous 1 … 4,223 4,224 4,225 4,226 4,227 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE