Search Results (345877 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-5625 1 Riken 1 Xoonips 2024-11-21 6.1 Medium
Cross-site scripting vulnerability in XooNIps 3.48 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.
CVE-2020-5624 1 Riken 1 Xoonips 2024-11-21 9.8 Critical
SQL injection vulnerability in the XooNIps 3.48 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2020-5623 1 Nitori 1 Nitori 2024-11-21 6.1 Medium
NITORI App for Android versions 6.0.4 and earlier and NITORI App for iOS versions 6.0.2 and earlier allow remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.
CVE-2020-5622 1 Shadan-kun 1 Server Security Type 2024-11-21 7.5 High
Shadankun Server Security Type (excluding normal blocking method types) Ver.1.5.3 and earlier allows remote attackers to cause a denial of service which may result in not being able to add newly detected attack source IP addresses as blocking targets for about 10 minutes via a specially crafted request.
CVE-2020-5621 1 Netgear 4 Gs716t, Gs716tv2 Firmware, Gs724t and 1 more 2024-11-21 4.3 Medium
Cross-site request forgery (CSRF) vulnerability in NETGEAR switching hubs (GS716Tv2 Firmware version 5.4.2.30 and earlier, and GS724Tv3 Firmware version 5.4.2.30 and earlier) allow remote attackers to hijack the authentication of administrators and alter the settings of the device via unspecified vectors.
CVE-2020-5620 1 Exceedone 1 Exment 2024-11-21 5.4 Medium
Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary script or HTML via a specially crafted file.
CVE-2020-5619 1 Exceedone 1 Exment 2024-11-21 5.4 Medium
Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary script or HTML via unspecified vectors.
CVE-2020-5617 1 Skygroup 1 Skysea Client View 2024-11-21 7.8 High
Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unauthorized privileges and modify/obtain sensitive information or perform unintended operations via unspecified vectors.
CVE-2020-5616 8 Calendar01 Project, Calendar02 Project, Calendarform01 Project and 5 more 8 Calendar01, Calendar02, Calendarform01 and 5 more 2024-11-21 9.8 Critical
[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] free edition ver1.0.0, [Gallery01] free edition ver1.0.3 and earlier, [CalendarForm01] free edition ver1.0.3 and earlier, and [Link01] free edition ver1.0.0 allows remote attackers to bypass authentication and log in to the product with administrative privileges via unspecified vectors.
CVE-2020-5615 2 Calendar01 Project, Calendar02 Project 2 Calendar01, Calendar02 2024-11-21 8.8 High
Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1.0.0 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2020-5614 1 Kujirahand 1 Konawiki 2024-11-21 5.3 Medium
Directory traversal vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2020-5613 1 Kujirahand 1 Konawiki 2024-11-21 6.1 Medium
Cross-site scripting vulnerability in KonaWiki 3.1.0 and earlier allows remote attackers to execute an arbitrary script via a specially crafted URL.
CVE-2020-5612 1 Kujirahand 1 Konawiki 2024-11-21 6.1 Medium
Cross-site scripting vulnerability in KonaWiki 2.2.0 and earlier allows remote attackers to execute an arbitrary script via a specially crafted URL.
CVE-2020-5611 1 Wpsocialrocket 1 Social Sharing 2024-11-21 8.8 High
Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2020-5610 1 Toyota 1 Global Techstream 2024-11-21 7.8 High
Global TechStream (GTS) for TOYOTA dealers version 15.10.032 and earlier allows an attacker to cause a denial-of-service (DoS) condition and execute arbitrary code via unspecified vectors.
CVE-2020-5609 1 Yokogawa 8 B\/m9000cs, B\/m9000cs Firmware, B\/m9000vp and 5 more 2024-11-21 9.8 Critical
Directory traversal vulnerability in CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01 allows a remote unauthenticated attacker to create or overwrite arbitrary files and run arbitrary commands via unspecified vectors.
CVE-2020-5608 1 Yokogawa 8 B\/m9000cs, B\/m9000cs Firmware, B\/m9000vp and 5 more 2024-11-21 9.8 Critical
CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01 allows a remote unauthenticated attacker to bypass authentication and send altered communication packets via unspecified vectors.
CVE-2020-5607 1 Ss-proj 1 Shirasagi 2024-11-21 6.1 Medium
Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVE-2020-5606 1 Buffalo 2 Airstation Whr-g54s, Airstation Whr-g54s Firmware 2024-11-21 6.1 Medium
Cross-site scripting vulnerability in WHR-G54S firmware 1.43 and earlier allows remote attackers to inject arbitrary script via a specially crafted page.
CVE-2020-5605 1 Buffalo 2 Airstation Whr-g54s, Airstation Whr-g54s Firmware 2024-11-21 4.3 Medium
Directory traversal vulnerability in WHR-G54S firmware 1.43 and earlier allows an attacker to access sensitive information such as setting values via unspecified vectors.