ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-21881
+1 in the same advisory: …36763
Cross Site Request Forgery (CSRF) vulnerability in admin.php in DuxCMS 2.1 allows remote attackers to modtify application data via article/admin/content/add.

Cross Site Request Forgery (CSRF) vulnerability in admin.php in DuxCMS 2.1 allows remote attackers to modtify application data via article/admin/content/add.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • duxcms project duxcms
CVE-2020-21861
+1 in the same advisory: …21862
File upload vulnerability in DuxCMS 2.1 allows attackers to execute arbitrary php code via duxcms/AdminUpload/upload.

File upload vulnerability in DuxCMS 2.1 allows attackers to execute arbitrary php code via duxcms/AdminUpload/upload.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • duxcms project duxcms
CVE-2020-36610
+1 in the same advisory: …36609
A vulnerability was found in annyshow DuxCMS 2.1.

A vulnerability was found in annyshow DuxCMS 2.1. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-215116.

NVD description · AI analysis pending
8.0
group max
<1% PoC
  • duxcms project duxcms
CVE-2021-3242
DuxCMS v3.1.3 was discovered to contain a SQL injection vulnerability via the component s/tools/SendTpl/index?keyword=.

DuxCMS v3.1.3 was discovered to contain a SQL injection vulnerability via the component s/tools/SendTpl/index?keyword=.

NVD description · AI analysis pending
9.81% PoC
  • duxcms project duxcms