Search Results (327716 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-18185 1 Pluxml 1 Pluxml 2024-11-21 9.8 Critical
class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.
CVE-2020-18184 1 Pluxxml 1 Pluxxml 2024-11-21 7.2 High
In PluxXml V5.7,the theme edit function /PluXml/core/admin/parametres_edittpl.php allows remote attackers to execute arbitrary PHP code by placing this code into a template.
CVE-2020-18178 1 Hongcms Project 1 Hongcms 2024-11-21 9.8 Critical
Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the component "/hcms/admin/index.php/language/ajax."
CVE-2020-18175 1 Metinfo 1 Metinfo 2024-11-21 9.8 Critical
SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_emailadd action in basic.php.
CVE-2020-18174 1 Autohotkey 1 Autohotkey 2024-11-21 9.8 Critical
A process injection vulnerability in setup.exe of AutoHotkey 1.1.32.00 allows attackers to escalate privileges.
CVE-2020-18173 1 1password 1 1password 2024-11-21 7.8 High
A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.
CVE-2020-18172 1 Trezor 1 Bridge 2024-11-21 9.8 Critical
A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges.
CVE-2020-18171 2 Microsoft, Techsmith 2 Windows, Snagit 2024-11-21 8.8 High
TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to escalate privileges. NOTE: This implies that Snagit's use of OLE is a security vulnerability unto itself and it is not. See reference document for more details
CVE-2020-18170 1 Abloy 1 Key Manager 2024-11-21 9.8 Critical
An issue in the SeChangeNotifyPrivilege component of Abloy Key Manager Version 7.14301.0.0 allows attackers to escalate privileges via a change in permissions.
CVE-2020-18169 2 Microsoft, Techsmith 2 Windows, Snagit 2024-11-21 7.8 High
A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges. NOTE: Exploit of the Snagit installer would require the end user to ignore other safety mechanisms provided by the Host OS. See reference document for more details
CVE-2020-18167 1 Laobancms 1 Laobancms 2024-11-21 4.8 Medium
Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Homepage Introduction" field of component "admin/info.php?shuyu".
CVE-2020-18166 1 Laobancms 1 Laobancms 2024-11-21 9.8 Critical
Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ".jpg.php" extension to the component "admin/wenjian.php?wj=../templets/pc".
CVE-2020-18165 1 Laobancms 1 Laobancms 2024-11-21 4.8 Medium
Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Website SEO Keywords" field on the page "admin/info.php?shuyu".
CVE-2020-18164 1 Tp-shop 1 Tp-shop 2024-11-21 9.8 Critical
SQL Injection vulnerability exists in tp-shop 2.x-3.x via the /index.php/home/api/shop fBill parameter.
CVE-2020-18158 1 Hucart 1 Hucart 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in HuCart 5.7.4 via nickname in index.php.
CVE-2020-18157 1 Metinfo 1 Metinfo 2024-11-21 8.8 High
Cross Site Request Forgery (CSRF) vulnerability in MetInfo 6.1.3 via a doaddsave action in admin/index.php.
CVE-2020-18155 1 Intelliants 1 Subrion 2024-11-21 9.8 Critical
SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.
CVE-2020-18151 1 Thinkcmf 1 Thinkcmf 2024-11-21 6.5 Medium
Cross Site Request Forgery (CSRF) vulnerability in ThinkCMF v5.1.0, which can add an admin account.
CVE-2020-18145 1 Baidu 1 Umeditor 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in umeditor v1.2.3 via /public/common/umeditor/php/getcontent.php.
CVE-2020-18144 1 Ectouch 1 Ectouch 2024-11-21 9.8 Critical
SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php.