Search Results (326098 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-23539 1 Realtek 2 Rtl8723de, Rtl8723de Firmware 2024-11-21 7.5 High
An issue was discovered in Realtek rtl8723de BLE Stack <= 4.1 that allows remote attackers to cause a Denial of Service via the interval field to the CONNECT_REQ message.
CVE-2020-23534 1 Masterlab 1 Masterlab 2024-11-21 9.8 Critical
A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.
CVE-2020-23533 1 Unionpayintl 1 Union Pay 2024-11-21 7.5 High
Union Pay up to 1.2.0, for web based versions contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a secret key which is NULL.
CVE-2020-23522 1 Pixelimity 1 Pixelimity 2024-11-21 6.8 Medium
Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.
CVE-2020-23520 1 Txjia 1 Imcat 2024-11-21 7.2 High
imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality.
CVE-2020-23518 1 Ultimatekode 1 Neo Billing 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in UltimateKode Neo Billing - Accounting, Invoicing And CRM Software up to version 3.5 which allows remote attackers to inject arbitrary web script or HTML.
CVE-2020-23517 1 Aryanic 1 High Cms 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers to inject arbitrary web script or HTML, via 'user' to LoginForm.
CVE-2020-23512 1 Vr Cam 2 P1, P1 Firmware 2024-11-21 9.8 Critical
VR CAM P1 Model P1 v1 has an incorrect access control vulnerability where an attacker can obtain complete access of the device from web (remote) without authentication.
CVE-2020-23490 1 Wwbn 1 Avideo 2024-11-21 7.5 High
There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can exploit this issue to read an arbitrary file on the server. Which could leak database credentials or other sensitive information such as /etc/passwd file.
CVE-2020-23489 1 Wwbn 1 Avideo 2024-11-21 8.8 High
The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in place, and therefore a user can escalate privileges to admin.
CVE-2020-23481 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 5.4 Medium
CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field.
CVE-2020-23478 1 Leoeditor 1 Leo 2024-11-21 7.5 High
Leo Editor v6.2.1 was discovered to contain a regular expression denial of service (ReDoS) vulnerability in the component plugins/importers/dart.py.
CVE-2020-23469 1 Gmate Project 1 Gmate 2024-11-21 7.5 High
gmate v0.12+bionic contains a regular expression denial of service (ReDoS) vulnerability in the gedit3 plugin.
CVE-2020-23466 1 Phpgurukul 1 Online Marriage Registration System 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability exists in the phpgurukul Online Marriage Registration System 1.0 allows attackers to run arbitrary code via the wzipcode field.
CVE-2020-23451 1 Spiceworks 1 Spiceworks 2024-11-21 8.8 High
Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.
CVE-2020-23450 1 Spiceworks 1 Spiceworks 2024-11-21 5.4 Medium
Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ without output sanitization.
CVE-2020-23449 1 Newbee-mall Project 1 Newbee-mall 2024-11-21 7.5 High
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information through the userID.
CVE-2020-23448 1 Newbee-mall Project 1 Newbee-mall 2024-11-21 9.8 Critical
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be bypassed.
CVE-2020-23447 1 Newbee-mall Project 1 Newbee-mall 2024-11-21 6.1 Medium
newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users only need to write xss payload in their address information when buying goods, which is triggered when viewing the "View Recipient Information" of this order in "Order Management Office".
CVE-2020-23446 1 Verint 1 Workforce Optimization 2024-11-21 5.3 Medium
Verint Workforce Optimization suite 15.1 (15.1.0.37634) has Unauthenticated Information Disclosure via API