Search Results (331944 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-22808 1 Fecmall Project 1 Fecmall 2024-11-21 6.1 Medium
An issue was found in yii2_fecshop 2.x. There is a reflected XSS vulnerability in the check cart page.
CVE-2020-22807 1 Vtiger 1 Vtiger Crm 2024-11-21 9.8 Critical
An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.
CVE-2020-22790 1 Safe 1 Fme Server 2024-11-21 5.4 Medium
Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web script or HTML via modifying the name of the users. The XSS is executed when an administrator access the logs.
CVE-2020-22789 1 Safe 1 Fme Server 2024-11-21 6.1 Medium
Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via the login page. The XSS is executed when an administrator accesses the logs.
CVE-2020-22785 1 Etherpad 1 Etherpad 2024-11-21 7.5 High
Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of rate limiting and missing ownership check.
CVE-2020-22784 1 Etherpad 1 Ueberdb 2024-11-21 7.5 High
In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names.
CVE-2020-22783 1 Etherpad 1 Etherpad 2024-11-21 6.5 Medium
Etherpad <1.8.3 stored passwords used by users insecurely in the database and in log files. This affects every database backend supported by Etherpad.
CVE-2020-22782 1 Etherpad 1 Etherpad 2024-11-21 7.5 High
Etherpad < 1.8.3 is affected by a denial of service in the import functionality. Upload of binary file to the import endpoint would crash the instance.
CVE-2020-22781 1 Etherpad 1 Etherpad 2024-11-21 7.5 High
In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash the instance).
CVE-2020-22765 1 Nukeviet 1 Nukeviet 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in NukeViet cms 4.4.0 via the editor in the News module.
CVE-2020-22761 1 Flatpress 1 Flatpress 2024-11-21 8.8 High
Cross Site Request Forgery (CSRF) vulnerability in FlatPress 1.1 via the DeleteFile function in flat/admin.php.
CVE-2020-22741 1 Baidu 1 Xuperchain 2024-11-21 7.5 High
An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signature in multisignature.
CVE-2020-22732 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 4.8 Medium
CMS Made Simple (CMSMS) 2.2.14 allows stored XSS via the Extensions > Fie Picker..
CVE-2020-22724 1 Mercury 4 Mer1200, Mer1200 Firmware, Mer1200g and 1 more 2024-11-21 9.8 Critical
A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 and Mercury Router MER1200G v1.0.1.
CVE-2020-22723 1 Ljcmsshop Project 1 Ljcmsshop 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in Beijing Liangjing Zhicheng Technology Co., Ltd ljcmsshop version 1.14 allows remote attackers to inject arbitrary web script or HTML via user.php by registering an account directly in the user center, and then adding the payload to the delivery address.
CVE-2020-22722 2 Microsoft, Rapidscada 2 Windows, Rapid Scada 2024-11-21 7.8 High
Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file. An attacker can obtain admin privileges by placing a malicious .exe file in the application and renaming it ScadaAgentSvc.exe, which would result in executing the binary as NT AUTHORITY\SYSTEM in a Windows operating system. For example, an attacker can plant a reverse shell from a low privileged user account and by restarting the computer, the malicious service will be started as NT AUTHORITY\SYSTEM by giving the attacker full system access to the remote PC.
CVE-2020-22721 1 Pnotes.net Project 1 Pnotes.net 2024-11-21 7.8 High
A File Upload Vulnerability in PNotes - Andrey Gruber PNotes.NET v3.8.1.2 allows a local attacker to execute arbitrary code via the Miscellaneous " External Programs by uploading the malicious .exe file to the external program.
CVE-2020-22719 1 Shimo 1 Document 2024-11-21 5.4 Medium
Shimo Document v2.0.1 contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the table content text field.
CVE-2020-22679 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.
CVE-2020-22678 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
An issue was discovered in gpac 0.8.0. The gf_media_nalu_remove_emulation_bytes function in av_parsers.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.