Search Results (29910 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-23512 1 Vr Cam 2 P1, P1 Firmware 2024-11-21 9.8 Critical
VR CAM P1 Model P1 v1 has an incorrect access control vulnerability where an attacker can obtain complete access of the device from web (remote) without authentication.
CVE-2020-23448 1 Newbee-mall Project 1 Newbee-mall 2024-11-21 9.8 Critical
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be bypassed.
CVE-2020-23426 1 Zzcms 1 Zzcms 2024-11-21 9.8 Critical
zzcms 201910 contains an access control vulnerability through escalation of privileges in /user/adv.php, which allows an attacker to modify data for further attacks such as CSRF.
CVE-2020-23361 1 Phplist 1 Phplist 2024-11-21 9.8 Critical
phpList 3.5.3 allows type juggling for login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
CVE-2020-23360 1 Oscommerce 1 Oscommerce 2024-11-21 9.8 Critical
oscommerce v2.3.4.1 has a functional problem in user registration and password rechecking, where a non-identical password can bypass the checks in /catalog/admin/administrators.php and /catalog/password_reset.php
CVE-2020-23359 1 Webidsupport 1 Webid 2024-11-21 9.8 Critical
WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the identicalness of two passwords. Two non-identical passwords can still bypass the check.
CVE-2020-23323 1 Jerryscript 1 Jerryscript 2024-11-21 9.8 Critical
There is a heap-buffer-overflow at re-parser.c in re_parse_char_escape in JerryScript 2.2.0.
CVE-2020-23321 1 Jerryscript 1 Jerryscript 2024-11-21 9.8 Critical
There is a heap-buffer-overflow at lit-strings.c:431 in lit_read_code_unit_from_utf8 in JerryScript 2.2.0.
CVE-2020-23306 1 Jerryscript 1 Jerryscript 2024-11-21 9.8 Critical
There is a stack-overflow at ecma-regexp-object.c:535 in ecma_regexp_match in JerryScript 2.2.0.
CVE-2020-23303 1 Jerryscript 1 Jerryscript 2024-11-21 9.8 Critical
There is a heap-buffer-overflow at jmem-poolman.c:165 in jmem_pools_collect_empty in JerryScript 2.2.0.
CVE-2020-23302 1 Jerryscript 1 Jerryscript 2024-11-21 9.8 Critical
There is a heap-use-after-free at ecma-helpers-string.c:772 in ecma_ref_ecma_string in JerryScript 2.2.0
CVE-2020-23262 1 Mingsoft 1 Mcms 2024-11-21 9.8 Critical
An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.
CVE-2020-23151 1 Rconfig 1 Rconfig 2024-11-21 9.8 Critical
rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed directly to the exec function without being escaped.
CVE-2020-23138 1 Microweber 1 Microweber 2024-11-21 9.8 Critical
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.
CVE-2020-23083 1 Guojusoft 1 Jeecg 2024-11-21 9.8 Critical
Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?commonUpload".
CVE-2020-23037 1 Portable 1 Playable 2024-11-21 9.8 Critical
Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.
CVE-2020-22937 1 Phome 1 Empirecms 2024-11-21 9.8 Critical
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
CVE-2020-22884 1 Espruino 1 Espruino 2024-11-21 9.8 Critical
Buffer overflow vulnerability in function jsvGetStringChars in Espruino before RELEASE_2V09, allows remote attackers to execute arbitrary code.
CVE-2020-22875 1 Jsish 1 Jsish 2024-11-21 9.8 Critical
Integer overflow vulnerability in function Jsi_ObjSetLength in jsish before 3.0.6, allows remote attackers to execute arbitrary code.
CVE-2020-22874 1 Jsish 1 Jsish 2024-11-21 9.8 Critical
Integer overflow vulnerability in function Jsi_ObjArraySizer in jsish before 3.0.8, allows remote attackers to execute arbitrary code.