Search Results (29910 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-24133 1 Radare 1 Radare2-extras 2024-11-21 9.8 Critical
A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.
CVE-2020-24115 1 Online Book Store Project 1 Online Book Store 2024-11-21 9.8 Critical
In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.
CVE-2020-24113 1 Yealink 2 W60b, W60b Firmware 2024-11-21 9.1 Critical
Directory Traversal vulnerability in Contacts File Upload Interface in Yealink W60B version 77.83.0.85, allows attackers to gain sensitive information and cause a denial of service (DoS).
CVE-2020-24074 1 Silk-v3-decoder Project 1 Silk-v3-decoder 2024-11-21 9.8 Critical
The decode program in silk-v3-decoder Version:20160922 Build By kn007 does not strictly check data, resulting in a buffer overflow.
CVE-2020-24055 1 Verint 4 4320, 4320 Firmware, 5620ptz and 1 more 2024-11-21 9.8 Critical
Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service implemented in the binary executable '/usr/sbin/DM' that listens on port TCP 6666. The service is vulnerable to a stack buffer overflow. It is worth noting that this service does not require any authentication.
CVE-2020-24054 1 Moog 4 Exvf5c-2, Exvf5c-2 Firmware, Exvp7c2-3 and 1 more 2024-11-21 9.8 Critical
The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that can spawn a given process repeatedly at a certain time interval as 'root'. One of the limitations of this feature is that it only takes a path to a binary without arguments; however, this can be circumvented using special shell variables, such as '${IFS}'. As a result, an attacker can execute arbitrary commands as 'root' on the units.
CVE-2020-24052 1 Moog 4 Exvf5c-2, Exvf5c-2 Firmware, Exvp7c2-3 and 1 more 2024-11-21 9.1 Critical
Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbitrary files via a crafted Document Type Definition (DTD) in an XML request.
CVE-2020-24051 1 Moog 4 Exvf5c-2, Exvf5c-2 Firmware, Exvp7c2-3 and 1 more 2024-11-21 9.8 Critical
The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol, which requires authentication for some of its operations. It was found that the authentication check for those ONVIF operations can be bypassed. An attacker can abuse this issue to execute privileged operations without authentication, for instance, to create a new Administrator user.
CVE-2020-24032 1 Xorux 2 Lpar2rrd, Stor2rrd 2024-11-21 9.8 Critical
tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone.
CVE-2020-24027 1 Live555 1 Liblivemedia 2024-11-21 9.8 Critical
In Live Networks, Inc., liblivemedia version 20200625, there is a potential buffer overflow bug in the server handling of a RTSP "PLAY" command, when the command specifies seeking by absolute time.
CVE-2020-24007 1 Umanni 1 Human Resources 2024-11-21 9.8 Critical
Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.
CVE-2020-24000 1 Eyoucms 1 Eyoucms 2024-11-21 9.8 Critical
SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php.
CVE-2020-23980 1 Designmasterevents 1 Conference Management 2024-11-21 9.8 Critical
DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.
CVE-2020-23979 1 13enforme 1 13enforme Cms 2024-11-21 9.8 Critical
13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter.
CVE-2020-23978 1 Soluzioneglobale 1 Ecommerce Cms 2024-11-21 9.8 Critical
SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"
CVE-2020-23976 1 Webexcels 1 Ecommerce Cms 2024-11-21 9.8 Critical
Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.
CVE-2020-23973 1 Kandnconcepts Club Cms Project 1 Kandnconcepts Club Cms 2024-11-21 9.8 Critical
KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.
CVE-2020-23936 1 Phpgurukul 1 Vehicle Parking Management System 2024-11-21 9.8 Critical
PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".
CVE-2020-23907 1 Avast 1 Retdec 2024-11-21 9.8 Critical
An issue was discovered in retdec v3.3. In function canSplitFunctionOn() of ir_modifications.cpp, there is a possible out of bounds read due to a heap buffer overflow. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution.
CVE-2020-23878 1 Flowpaper 1 Pdf2json 2024-11-21 9.8 Critical
pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch.