Search Results (322986 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-19108 1 Projectworlds 1 Online Book Store Project In Php 2024-11-21 9.8 Critical
SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remote malicious user execute arbitrary code.
CVE-2020-19107 1 Projectworlds 1 Online Book Store Project In Php 2024-11-21 9.8 Critical
SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote malicious user execute arbitrary code.
CVE-2020-19049 1 Mybb 1 Mybb 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Description" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-management&action=add'.
CVE-2020-19048 1 Mybb 1 Mybb 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) in MyBB v1.8.20 allows remote attackers to inject arbitrary web script or HTML via the "Title" field found in the "Add New Forum" page by doing an authenticated POST HTTP request to '/Upload/admin/index.php?module=forum-management&action=add'.
CVE-2020-19047 1 Iwebshop 1 Iwebshop 2024-11-21 8.8 High
Cross Site Request Forgey (CSRF) in iWebShop v5.3 allows remote atatckers to execute arbitrary code via malicious POST request to the component '/index.php?controller=system&action=admin_edit_act'.
CVE-2020-19046 1 S-cms 1 S-cms 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) in S-CMS v1.0 allows remote attackers to execute arbitrary code via the component '/admin/tpl.php?page='.
CVE-2020-19042 1 Zzcms 1 Zzcms 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability exists in zzcms 2019 XSS via a modify action in user/adv.php.
CVE-2020-19038 1 Halo 1 Halo 2024-11-21 9.1 Critical
File Deletion vulnerability in Halo 0.4.3 via delBackup.
CVE-2020-19037 1 Halo 1 Halo 2024-11-21 5.3 Medium
Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted articles via cookies.
CVE-2020-19007 1 Halo 1 Halo 2024-11-21 5.4 Medium
Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser.
CVE-2020-19005 1 Zrlog 1 Zrlog 2024-11-21 5.7 Medium
zrlog v2.1.0 has a vulnerability with the permission check. If admin account is logged in, other unauthorized users can download the database backup file directly.
CVE-2020-19003 1 Liftoffsoftware 1 Gate One 2024-11-21 5.3 Medium
An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.
CVE-2020-19002 1 Jupo 1 Mezzanine 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary code via the 'Description' field of the component 'admin/blog/blogpost/add/'. This issue is different than CVE-2018-16632.
CVE-2020-19001 1 Simiki Project 1 Simiki 2024-11-21 9.8 Critical
Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob/master/simiki/config.py'.
CVE-2020-19000 1 Simiki Project 1 Simiki 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary code via line 54 of the component 'simiki/blob/master/simiki/generators.py'.
CVE-2020-18999 1 Blog Mini Project 1 Blog Mini 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/submit-articles'.
CVE-2020-18998 1 Blog Mini Project 1 Blog Mini 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) in Blog_mini v1.0 allows remote attackers to execute arbitrary code via the component '/admin/custom/blog-plugin/add'.
CVE-2020-18985 1 Synacor 1 Zimbra Collaboration Suite 2024-11-21 6.1 Medium
An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing.
CVE-2020-18984 1 Synacor 1 Zimbra Collaboration Suite 2024-11-21 6.1 Medium
A reflected cross-site scripting (XSS) vulnerability in the zimbraAdmin/public/secureRequest.jsp component of Zimbra Collaboration 8.8.12 allows unauthenticated attackers to execute arbitrary web scripts or HTML via a host header injection.
CVE-2020-18982 1 Halo 1 Halo 2024-11-21 5.4 Medium
Cross Sie Scripting (XSS) vulnerability in Halo 0.4.3 via CommentAuthorUrl.