Search Results (118583 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-23766 1 Htmly 1 Htmly 2024-11-21 6.5 Medium
An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolute path to delete any file in the server should they gain Administrator privileges.
CVE-2020-23763 1 Online Book Store Project 1 Online Book Store 2024-11-21 9.8 Critical
SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
CVE-2020-23762 1 Larsens Calendar Project 1 Larsens Calendar 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress allows remote attackers to execute arbitrary web script via the "titel" column on the "Eintrage hinzufugen" tab.
CVE-2020-23761 1 Intelliants 1 Subrion 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in subrion CMS Version <= 4.2.1 allows remote attackers to execute arbitrary web script via the "payment gateway" column on transactions tab.
CVE-2020-23691 1 Yfcmf 1 Yfcmf 2024-11-21 9.8 Critical
YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php.
CVE-2020-23653 1 Thinkadmin 1 Thinkadmin 2024-11-21 9.8 Critical
An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wechat/controller/api/Push.php, which may lead to arbitrary remote code execution.
CVE-2020-23639 1 Moxa 2 Vport 461, Vport 461 Firmware 2024-11-21 9.8 Critical
A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a remote attacker to execute arbitrary commands in Moxa's VPort 461 Series Industrial Video Servers.
CVE-2020-23631 1 Wdja 1 Wdja Cms 2024-11-21 6.1 Medium
Cross-site request forgery (CSRF) in admin/global/manage.php in WDJA CMS 1.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via the tongji parameter.
CVE-2020-23622 1 Cling Project 1 Cling 2024-11-21 7.5 High
An issue in the UPnP protocol in 4thline cling 2.0.0 through 2.1.2 allows remote attackers to cause a denial of service via an unchecked CALLBACK parameter in the request header
CVE-2020-23621 1 Squire-technologies 1 Svi Ms Management System 2024-11-21 9.8 Critical
The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.
CVE-2020-23620 1 Orlansoft 1 Orlansoft Erp 2024-11-21 9.8 Critical
The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.
CVE-2020-23595 1 Yzmcms 1 Yzmcms 2024-11-21 8.8 High
Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information sitemodel/add.html endpoint.
CVE-2020-23580 1 Pbootcms 1 Pbootcms 2024-11-21 9.8 Critical
Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.
CVE-2020-23564 1 Sem-cms 1 Semcms 2024-11-21 7.2 High
File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.
CVE-2020-23539 1 Realtek 2 Rtl8723de, Rtl8723de Firmware 2024-11-21 7.5 High
An issue was discovered in Realtek rtl8723de BLE Stack <= 4.1 that allows remote attackers to cause a Denial of Service via the interval field to the CONNECT_REQ message.
CVE-2020-23520 1 Txjia 1 Imcat 2024-11-21 7.2 High
imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality.
CVE-2020-23518 1 Ultimatekode 1 Neo Billing 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to version 3.5 which allows remote attackers to inject arbitrary web script or HTML.
CVE-2020-23517 1 Aryanic 1 High Cms 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers to inject arbitrary web script or HTML, via 'user' to LoginForm.
CVE-2020-23512 1 Vr Cam 2 P1, P1 Firmware 2024-11-21 9.8 Critical
VR CAM P1 Model P1 v1 has an incorrect access control vulnerability where an attacker can obtain complete access of the device from web (remote) without authentication.
CVE-2020-23449 1 Newbee-mall Project 1 Newbee-mall 2024-11-21 7.5 High
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information through the userID.