Search Results (29910 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-22873 1 Jsish 1 Jsish 2024-11-21 9.8 Critical
Buffer overflow vulnerability in function NumberToPrecisionCmd in jsish before 3.0.7, allows remote attackers to execute arbitrary code.
CVE-2020-22848 1 Chshcms 1 Cscms 2024-11-21 9.8 Critical
A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arbitrary commands.
CVE-2020-22807 1 Vtiger 1 Vtiger Crm 2024-11-21 9.8 Critical
An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.
CVE-2020-22724 1 Mercury 4 Mer1200, Mer1200 Firmware, Mer1200g and 1 more 2024-11-21 9.8 Critical
A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 and Mercury Router MER1200G v1.0.1.
CVE-2020-22617 1 Ardour 1 Ardour 2024-11-21 9.8 Critical
Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext.
CVE-2020-22612 1 Mybb 1 Mybb 2024-11-21 9.8 Critical
Installer RCE on settings file write in MyBB before 1.8.22.
CVE-2020-22336 1 Pdfcrack Project 1 Pdfcrack 2024-11-21 9.8 Critical
An issue was discovered in pdfcrack 0.17 thru 0.18, allows attackers to execute arbitrary code via a stack overflow in the MD5 function.
CVE-2020-22276 1 Weformspro 1 Weforms 2024-11-21 9.8 Critical
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
CVE-2020-22274 1 Jomsocial 1 Jomsocial 2024-11-21 9.8 Critical
JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
CVE-2020-22253 1 Xiongmaitech 16 Ahb7008t-mh-v2, Ahb7008t-mh-v2 Firmware, Ahb7804r-els and 13 more 2024-11-21 9.8 Critical
Xiongmai Technology Co devices AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS-V2, AHB7804R-LMS, and HI3518E_50H10L_S39 were all discovered to have port 9530 open which allows unauthenticated attackers to make arbitrary Telnet connections with the victim device.
CVE-2020-22249 1 Phplist 1 Phplist 2024-11-21 9.8 Critical
Remote Code Execution vulnerability in phplist 3.5.1. The application does not check any file extensions stored in the plugin zip file, Uploading a malicious plugin which contains the php files with extensions like PHP,phtml,php7 will be copied to the plugins directory which would lead to the remote code execution
CVE-2020-22226 1 Phpjabbers 1 Fundraising Script 2024-11-21 9.8 Critical
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function.
CVE-2020-22225 1 Phpjabbers 1 Fundraising Script 2024-11-21 9.8 Critical
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.
CVE-2020-22223 1 Phpjabbers 1 Fundraising Script 2024-11-21 9.8 Critical
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoad function.
CVE-2020-22212 1 74cms 1 74cms 2024-11-21 9.8 Critical
SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php.
CVE-2020-22211 1 74cms 1 74cms 2024-11-21 9.8 Critical
SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.
CVE-2020-22210 1 74cms 1 74cms 2024-11-21 9.8 Critical
SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.
CVE-2020-22209 1 74cms 1 74cms 2024-11-21 9.8 Critical
SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.
CVE-2020-22208 1 74cms 1 74cms 2024-11-21 9.8 Critical
SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.
CVE-2020-22206 1 Shopex 1 Ecshop 2024-11-21 9.8 Critical
SQL Injection in ECShop 3.0 via the aid parameter to admin/affiliate_ck.php.