Search Results (326423 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-23618 1 Xtendtech 1 Voice Logger 2024-11-21 6.1 Medium
A reflected cross site scripting (XSS) vulnerability in Xtend Voice Logger 1.0 allows attackers to execute arbitrary web scripts or HTML, via the path of the error page.
CVE-2020-23617 1 Totolink 4 N100re, N100re Firmware, N200re and 1 more 2024-11-21 6.1 Medium
A cross site scripting (XSS) vulnerability in the error page of Totolink N200RE and N100RE Routers 2.0 allows attackers to execute arbitrary web scripts or HTML via SCRIPT element.
CVE-2020-23595 1 Yzmcms 1 Yzmcms 2024-11-21 8.8 High
Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information sitemodel/add.html endpoint.
CVE-2020-23580 1 Pbootcms 1 Pbootcms 2024-11-21 9.8 Critical
Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.
CVE-2020-23576 1 Laborator 1 Neon 2024-11-21 5.4 Medium
Laborator Neon dashboard v3 is affected by stored Cross Site Scripting (XSS) via the chat tab.
CVE-2020-23575 1 Kyocera 2 D-copia253mf Plus, D-copia253mf Plus Firmware 2024-11-21 7.5 High
A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnerability could allow an attacker to retrieve or view arbitrary files from the affected server.
CVE-2020-23574 1 Sysax 1 Multi Server 2024-11-21 6.5 Medium
When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uploadfile_name1.htm form to a length of 368 or more bytes. This will create a buffer overflow condition, causing the application to crash.
CVE-2020-23572 1 Beescms 1 Beescms 2024-11-21 8.8 High
BEESCMS v4.0 was discovered to contain an arbitrary file upload vulnerability via the component /admin/upload.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
CVE-2020-23567 1 Irfanview 1 Irfanview 2024-11-21 5.5 Medium
Irfanview v4.53 allows attackers to to cause a denial of service (DoS) via a crafted JPEG 2000 file. Related to "Integer Divide By Zero starting at JPEG2000!ShowPlugInSaveOptions_W+0x00000000000082ea"
CVE-2020-23566 1 Irfanview 1 Irfanview 2024-11-21 5.5 Medium
Irfanview v4.53 was discovered to contain an infinity loop via JPEG2000!ShowPlugInSaveOptions_W+0x1ecd8.
CVE-2020-23565 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
Irfanview v4.53 allows attackers to execute arbitrary code via a crafted JPEG 2000 file. Related to a "Data from Faulting Address controls Branch Selection starting at JPEG2000!ShowPlugInSaveOptions_W+0x0000000000032850".
CVE-2020-23564 1 Sem-cms 1 Semcms 2024-11-21 7.2 High
File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.
CVE-2020-23563 1 Irfanview 1 Irfanview 2024-11-21 5.5 Medium
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000002cba.
CVE-2020-23562 1 Irfanview 1 Irfanview 2024-11-21 5.5 Medium
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000000aefe.
CVE-2020-23561 1 Irfanview 1 Irfanview 2024-11-21 5.5 Medium
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000005722.
CVE-2020-23560 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000001bcab.
CVE-2020-23559 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000007d7f.
CVE-2020-23558 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000007f4b.
CVE-2020-23557 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000000755d.
CVE-2020-23556 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e28.