Yzmcms是Yzmcms个人开发者的一套开源的CMS(内容管理系统)。 YzmCMS v6.3中存在安全漏洞,该漏洞源于评论功能可以并发操作,允许攻击者创建异常大量的评论。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-23484 | 9.8 CRITICAL | Arbitrary File Write via Archive Extraction (Zip Slip) |
| CVE-2021-44463 | 8.1 HIGH | Emerson DeltaV Uncontrolled Search Path Element |
| CVE-2022-22992 | 7.8 HIGH | Command Injection Remote Code Execution vulnerability on Western Digital My Cloud devices. |
| CVE-2021-23558 | 7.3 HIGH | Prototype Pollution |
| CVE-2021-31567 | 6.8 MEDIUM | WordPress Download Monitor plugin <= 4.4.6 - Authenticated Arbitrary File Download vulnera |
| CVE-2022-22791 | 6.6 MEDIUM | SYNEL - eharmony Authenticated Blind & Stored XSS |
| CVE-2021-23863 | 6.1 MEDIUM | Bosch Video Security 跨站脚本漏洞 |
| CVE-2021-26264 | 6.1 MEDIUM | Emerson DeltaV Missing Authentication for Critical Function |
| CVE-2022-21719 | 6.1 MEDIUM | Reflected XSS using reload button in GLPI |
| CVE-2022-21721 | 5.9 MEDIUM | DOS Vulnerability in next.js |
| CVE-2021-23760 | 5.6 MEDIUM | Prototype Pollution |
| CVE-2022-22790 | 5.6 MEDIUM | SYNEL - eharmony Directory Traversal |
| CVE-2022-21720 | 4.9 MEDIUM | SQL injection using custom CSS administration form in GLPI |
| CVE-2022-23979 | 4.8 MEDIUM | WordPress Ultimate Reviews plugin <= 3.0.15 - Authenticated Stored Cross-Site Scripting (X |
| CVE-2022-23599 | 4.3 MEDIUM | Cross-site Scripting and Open Redirect in Products.ATContentTypes |
| CVE-2021-40339 | 3.7 LOW | OWASP Related Vulnerabilities in Hitachi Energy’s LinkOne Product |
| CVE-2021-40338 | 3.7 LOW | OWASP Related Vulnerabilities in Hitachi Energy’s LinkOne Product |
| CVE-2021-40340 | 3.7 LOW | OWASP Related Vulnerabilities in Hitachi Energy’s LinkOne Product |
| CVE-2021-44372 | Reolink Rlc-410W 输入验证错误漏洞 | |
| CVE-2021-46444 | H.H.G. Multistore SQL注入漏洞 |
Showing top 20 of 154 CVEs. View all on vendor page → →
No comments yet