Search Results (29910 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-23877 1 Science-miner 1 Pdf2xml 2024-11-21 9.8 Critical
pdf2xml v2.0 was discovered to contain a stack buffer overflow in the component getObjectStream.
CVE-2020-23874 1 Science-miner 1 Pdf2xml 2024-11-21 9.8 Critical
pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::addAttributsNode.
CVE-2020-23873 1 Science-miner 1 Pdf2xml 2024-11-21 9.8 Critical
pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::dump.
CVE-2020-23833 1 Projectworlds 1 House Rental 2024-11-21 9.8 Critical
Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on the hosting webserver via a malicious index.php POST request.
CVE-2020-23828 1 Online Course Registration Project 1 Online Course Registration 2024-11-21 9.8 Critical
A File Upload vulnerability in SourceCodester Online Course Registration v1.0 allows remote attackers to achieve Remote Code Execution (RCE) on the hosting webserver by uploading a crafted PHP web-shell that bypasses the image upload filters. An attack uses /Online%20Course%20Registration/my-profile.php with the POST parameter photo.
CVE-2020-23790 1 Uxper 1 Golo 2024-11-21 9.8 Critical
An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5.
CVE-2020-23763 1 Online Book Store Project 1 Online Book Store 2024-11-21 9.8 Critical
SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
CVE-2020-23754 1 Php-fusion 1 Phpfusion 2024-11-21 9.6 Critical
Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature.
CVE-2020-23719 1 Zibbs Project 1 Zibbs 2024-11-21 9.6 Critical
Cross site scripting (XSS) vulnerability in application/controllers/AdminController.php in xujinliang zibbs 1.0, allows attackers to execute arbitrary code via the bbsmeta parameter.
CVE-2020-23718 1 Zibbs Project 1 Zibbs 2024-11-21 9.6 Critical
Cross site scripting (XSS) vulnerability in xujinliang zibbs 1.0, allows attackers to execute arbitrary code via the route parameter to index.php.
CVE-2020-23711 1 Naviwebs 1 Navigate Cms 2024-11-21 9.8 Critical
SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php.
CVE-2020-23691 1 Yfcmf 1 Yfcmf 2024-11-21 9.8 Critical
YFCMF v2.3.1 has a Remote Command Execution (RCE) vulnerability in the index.php.
CVE-2020-23685 1 Vtimecn 1 188jianzhan 2024-11-21 9.8 Critical
SQL Injection vulnerability in 188Jianzhan v2.1.0, allows attackers to execute arbitrary code and gain escalated privileges, via the username parameter to login.php.
CVE-2020-23679 1 Linux Network Project 1 Linux Network Project 2024-11-21 9.8 Critical
Buffer overflow vulnerability in Renleilei1992 Linux_Network_Project 1.0, allows attackers to execute arbitrary code, via the password field.
CVE-2020-23653 1 Thinkadmin 1 Thinkadmin 2024-11-21 9.8 Critical
An insecure unserialize vulnerability was discovered in ThinkAdmin versions 4.x through 6.x in app/admin/controller/api/Update.php and app/wechat/controller/api/Push.php, which may lead to arbitrary remote code execution.
CVE-2020-23639 1 Moxa 2 Vport 461, Vport 461 Firmware 2024-11-21 9.8 Critical
A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a remote attacker to execute arbitrary commands in Moxa's VPort 461 Series Industrial Video Servers.
CVE-2020-23621 1 Squire-technologies 1 Svi Ms Management System 2024-11-21 9.8 Critical
The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.
CVE-2020-23620 1 Orlansoft 1 Orlansoft Erp 2024-11-21 9.8 Critical
The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.
CVE-2020-23580 1 Pbootcms 1 Pbootcms 2024-11-21 9.8 Critical
Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.
CVE-2020-23534 1 Masterlab 1 Masterlab 2024-11-21 9.8 Critical
A server-side request forgery (SSRF) vulnerability in Upgrade.php of gopeak masterlab 2.1.5, via the 'source' parameter.