Search Results (326423 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-23179 1 Php-fusion 1 Php-fusion 2024-11-21 5.4 Medium
A stored cross site scripting (XSS) vulnerability in administration/settings_main.php of PHP-Fusion 9.03.50 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Site footer" field.
CVE-2020-23178 1 Php-fusion 1 Php-fusion 2024-11-21 5.4 Medium
An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session replay attack and impersonate the victim user.
CVE-2020-23172 1 Kuba Project 1 Kuba 2024-11-21 5.5 Medium
A vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with crafted Zip files due to improper validation of file paths in .zip archives.
CVE-2020-23171 1 Nim-lang 1 Nim-lang 2024-11-21 5.5 Medium
A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-slash characters included in the name of the crafted file.
CVE-2020-23162 1 Pyres 2 Termod4, Termod4 Firmware 2024-11-21 7.5 High
Sensitive information disclosure and weak encryption in Pyrescom Termod4 time management devices before 10.04k allows remote attackers to read a session-file and obtain plain-text user credentials.
CVE-2020-23161 1 Pyres 2 Termod4, Termod4 Firmware 2024-11-21 6.5 Medium
Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to traverse directories and read sensitive files via the Maintenance > Logs menu and manipulating the file-path in the URL.
CVE-2020-23160 1 Pyres 2 Termod4, Termod4 Firmware 2024-11-21 8.8 High
Remote code execution in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to arbitrary commands as root on the devices.
CVE-2020-23151 1 Rconfig 1 Rconfig 2024-11-21 9.8 Critical
rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed directly to the exec function without being escaped.
CVE-2020-23150 1 Rconfig 1 Rconfig 2024-11-21 7.5 High
A SQL injection vulnerability in config.inc.php of rConfig 3.9.5 allows attackers to access sensitive database information via a crafted GET request to install/lib/ajaxHandlers/ajaxDbInstall.php.
CVE-2020-23149 1 Rconfig 1 Rconfig 2024-11-21 7.5 High
The dbName parameter in ajaxDbInstall.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a SQL injection and access sensitive database information.
CVE-2020-23148 1 Rconfig 1 Rconfig 2024-11-21 7.5 High
The userLogin parameter in ldap/login.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a LDAP injection and obtain sensitive information via a crafted POST request.
CVE-2020-23140 1 Microweber 1 Microweber 2024-11-21 8.1 High
Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active.
CVE-2020-23139 1 Microweber 1 Microweber 2024-11-21 5.5 Medium
Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.
CVE-2020-23138 1 Microweber 1 Microweber 2024-11-21 9.8 Critical
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.
CVE-2020-23136 1 Microweber 1 Microweber 2024-11-21 5.5 Medium
Microweber v1.1.18 is affected by no session expiry after log-out.
CVE-2020-23128 1 Chamilo 1 Chamilo Lms 2024-11-21 4.9 Medium
Chamilo LMS 1.11.10 does not properly manage privileges which could allow a user with Sessions administrator privilege to create a new user then use the edit user function to change this new user to administrator privilege.
CVE-2020-23127 1 Chamilo 1 Chamilo Lms 2024-11-21 8.8 High
Chamilo LMS 1.11.10 is affected by Cross Site Request Forgery (CSRF) via the edit_user function by targeting an admin user.
CVE-2020-23126 1 Chamilo 1 Chamilo Lms 2024-11-21 6.1 Medium
Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/herself and social network friends.
CVE-2020-23109 1 Struktur 1 Libheif 2024-11-21 8.1 High
Buffer overflow vulnerability in function convert_colorspace in heif_colorconversion.cc in libheif v1.6.2, allows attackers to cause a denial of service and disclose sensitive information, via a crafted HEIF file.
CVE-2020-23083 1 Guojusoft 1 Jeecg 2024-11-21 9.8 Critical
Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?commonUpload".