Search Results (29944 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-35464 1 Weave 1 Cloud Agent 2024-11-21 9.8 Critical
Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the Weave Cloud Agent container may allow a remote attacker to achieve root access with a blank password.
CVE-2020-35463 1 Instana 1 Dynamic Apm 2024-11-21 9.8 Critical
Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed using affected versions of the Instana Dynamic APM container may allow a remote attacker to achieve root access with a blank password.
CVE-2020-35462 1 Coscale Agent Project 1 Coscale Agent 2024-11-21 9.8 Critical
Version 3.16.0 of the CoScale agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the CoScale agent container may allow a remote attacker to achieve root access with a blank password.
CVE-2020-35458 1 Clusterlabs 1 Hawk 2024-11-21 9.8 Critical
An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in the login_from_cookie cookie. The user logout routine could be used by unauthenticated remote attackers to execute code as hauser.
CVE-2020-35442 1 Fangfa 1 Fdcms 2024-11-21 9.8 Critical
FDCMS (also known as Fangfa Content Management System) 4.0 allows remote attackers to get a webshell in the background via Front/lib/Action/FindexAction.class.php.
CVE-2020-35441 1 Fangfa 1 Fdcms 2024-11-21 9.8 Critical
FDCMS (aka Fangfa Content Management System) 4.0 contains a front-end SQL injection via Admin/Lib/Action/FloginAction.class.php.
CVE-2020-35430 1 Inxedu 1 Inxedu 2024-11-21 9.8 Critical
SQL Injection in com/inxedu/OS/edu/controller/letter/AdminMsgSystemController in Inxedu v2.0.6 via the ids parameter to admin/letter/delsystem.
CVE-2020-35427 1 Phpgurukul 1 Employee Record Management System 2024-11-21 9.8 Critical
SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
CVE-2020-35391 1 Tenda 2 F3, F3 Firmware 2024-11-21 9.6 Critical
Tenda N300 F3 12.01.01.48 devices allow remote attackers to obtain sensitive information (possibly including an http_passwd line) via a direct request for cgi-bin/DownloadCfg/RouterCfm.cfg, a related issue to CVE-2017-14942. NOTE: the vulnerability report may suggest that either a ? character must be placed after the RouterCfm.cfg filename, or that the HTTP request headers must be unusual, but it is not known why these are relevant to the device's HTTP response behavior.
CVE-2020-35378 1 Online Bus Ticket Reservation Project 1 Online Bus Ticket Reservation 2024-11-21 9.8 Critical
SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.
CVE-2020-35364 1 Huorong 1 Internet Security 2024-11-21 9.8 Critical
Beijing Huorong Internet Security 5.0.55.2 allows a non-admin user to escalate privileges by injecting code into a process, and then waiting for a Huorong services restart or a system reboot.
CVE-2020-35358 1 Domainmod 1 Domainmod 2024-11-21 9.8 Critical
DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or device do not expire and remain active. Such flaws frequently give attackers unauthorized access to some system data or functionality.
CVE-2020-35339 1 74cms 1 74cms 2024-11-21 9.8 Critical
In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server permissions and control the server.
CVE-2020-35338 1 Mobileviewpoint 1 Wireless Multiplex Terminal Playout Server 2024-11-21 9.8 Critical
The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default account with a password of "pokon."
CVE-2020-35337 1 Thinksaas 1 Thinksaas 2024-11-21 9.8 Critical
ThinkSAAS before 3.38 contains a SQL injection vulnerability through app/topic/action/admin/topic.php via the title parameter, which allows remote attackers to execute arbitrary SQL commands.
CVE-2020-35314 1 Wondercms 1 Wondercms 2024-11-21 9.8 Critical
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary code and obtain a webshell via the theme/plugin installer.
CVE-2020-35313 1 Wondercms 1 Wondercms 2024-11-21 9.8 Critical
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in WonderCMS 3.1.3 allows remote attackers to execute arbitrary code via a crafted URL to the theme/plugin installer.
CVE-2020-35308 1 Conquest Dicom Server Project 1 Conquest Dicom Server 2024-11-21 9.8 Critical
CONQUEST DICOM SERVER before 1.5.0 has a code execution vulnerability which can be exploited by attackers to execute malicious code.
CVE-2020-35276 1 Egavilanmedia 1 Ecm Address Book 2024-11-21 9.8 Critical
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
CVE-2020-35270 1 Student Result Management System Project 1 Student Result Management System 2024-11-21 9.1 Critical
Student Result Management System In PHP With Source Code is affected by SQL injection. An attacker can able to access of Admin Panel and manage every account of Result.