Search Results (322814 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-13445 1 Liferay 1 Liferay Portal 2024-11-21 8.8 High
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensitive objects, which allows remote authenticated users to execute arbitrary code via crafted FreeMarker and Velocity templates.
CVE-2020-13444 1 Liferay 1 Liferay Portal 2024-11-21 6.5 Medium
Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which allows remote authenticated users to obtain the password to REST Data Providers.
CVE-2020-13443 1 Expressionengine 1 Expressionengine 2024-11-21 8.8 High
ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Save As Draft actions. A user with low privileges (member) is able to upload this. It is possible to bypass the MIME type check and file-extension check while uploading new files. Short aliases are not used for an attachment; instead, direct access is allowed to the uploaded files. It is possible to upload PHP only if one has member access, or registration/forum is enabled and one can create a member with the default group id of 5. To exploit this, one must to be able to send and compose messages (at least).
CVE-2020-13442 1 Dext5 1 Dext5 2024-11-21 9.8 Critical
A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.
CVE-2020-13440 1 Rockcarry 1 Ffjpeg 2024-11-21 6.5 Medium
ffjpeg through 2020-02-24 has an invalid write in bmp_load in bmp.c.
CVE-2020-13439 1 Rockcarry 1 Ffjpeg 2024-11-21 6.5 Medium
ffjpeg through 2020-02-24 has a heap-based buffer over-read in jfif_decode in jfif.c.
CVE-2020-13438 1 Rockcarry 1 Ffjpeg 2024-11-21 6.5 Medium
ffjpeg through 2020-02-24 has an invalid read in jfif_encode in jfif.c.
CVE-2020-13435 3 Fedoraproject, Redhat, Sqlite 3 Fedora, Enterprise Linux, Sqlite 2024-11-21 5.5 Medium
SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c.
CVE-2020-13434 8 Apple, Canonical, Debian and 5 more 16 Icloud, Ipados, Iphone Os and 13 more 2024-11-21 5.5 Medium
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
CVE-2020-13433 1 Adminpanel Project 1 Adminpanel 2024-11-21 9.8 Critical
Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.
CVE-2020-13432 1 Rejetto 1 Http File Server 2024-11-21 7.5 High
rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests with a long URI or long HTTP headers.
CVE-2020-13431 1 Geti2p 1 I2p 2024-11-21 7.8 High
I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% subdirectory.
CVE-2020-13430 2 Grafana, Redhat 3 Grafana, Enterprise Linux, Service Mesh 2024-11-21 6.1 Medium
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
CVE-2020-13429 1 Grafana 1 Piechart-panel 2024-11-21 5.4 Medium
legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option.
CVE-2020-13428 2 Debian, Videolan 2 Debian Linux, Vlc Media Player 2024-11-21 7.8 High
A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file.
CVE-2020-13427 1 Victorcms Project 1 Victorcms 2024-11-21 6.1 Medium
Victor CMS 1.0 has Persistent XSS in admin/users.php?source=add_user via the user_name, user_firstname, or user_lastname parameter.
CVE-2020-13426 1 Bdtask 1 Multi-scheduler 2024-11-21 6.5 Medium
The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the possibility of deleting records (users) when an ID is known.
CVE-2020-13425 1 Thetrackr 2 Trackr, Trackr Firmware 2024-11-21 7.1 High
TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a denial of service when battery capacity is exhausted.
CVE-2020-13424 1 Xcloner 1 Xcloner 2024-11-21 6.5 Medium
The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure.
CVE-2020-13423 1 Form Builder For Magento 2 Project 1 Form Builder For Magento 2 2024-11-21 4.8 Medium
Form Builder 2.1.0 for Magento has multiple XSS issues that can be exploited against Magento 2 admin accounts via the Current_url or email field, or the User-Agent HTTP header.