CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the web root of the application to gain access to the server via the web shell.
Serenissima Informatica Fast Checkin 1.0 is vulnerable to Directory Traversal.
A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker. This affects all Solar-Log devices that use firmware version v4.2.7 up to v5.1.1 (included).
PopojiCMS v2.0.1 backend plugin function has a file upload vulnerability.
In gin-vue-admin < 2.5.5, the download module has a Path Traversal vulnerability.
The CC Child Pages WordPress plugin before 1.43 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
The GeoDirectory WordPress plugin before 2.2.22 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs.
ZenTao 16.4 to 18.0.beta1 is vulnerable to SQL injection. After logging in with any user, you can complete SQL injection by constructing a special request and sending it to function importNotice.
Seltmann GmbH Content Management System 6 is vulnerable to SQL Injection via /index.php.
