Search Results (29905 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-20601 1 Thinkcmf 1 Thinkcmf 2024-11-21 9.8 Critical
An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
CVE-2020-20495 1 Bludit 1 Bludit 2024-11-21 9.1 Critical
bludit v3.13.0 contains an arbitrary file deletion vulnerability in the backup plugin via the `deleteBackup' parameter.
CVE-2020-20466 1 White Shark Systems Project 1 White Shark Systems 2024-11-21 9.8 Critical
White Shark System (WSS) 1.3.2 is vulnerable to unauthorized access via user_edit_password.php, remote attackers can modify the password of any user.
CVE-2020-20392 1 Txjia 1 Imcat 2024-11-21 9.8 Critical
SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.
CVE-2020-20300 1 Weiphp 1 Weiphp 2024-11-21 9.8 Critical
SQL injection vulnerability in the wp_where function in WeiPHP 5.0.
CVE-2020-20298 1 Zzzcms 1 Zzzphp 2024-11-21 9.8 Critical
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.
CVE-2020-20296 1 Cmswing 1 Cmswing 2024-11-21 9.8 Critical
An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance parameter, malicious parameters can execute arbitrary SQL commands.
CVE-2020-20295 1 Cmswing 1 Cmswing 2024-11-21 9.8 Critical
An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands.
CVE-2020-20294 1 Cmswing 1 Cmswing 2024-11-21 9.8 Critical
An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands.
CVE-2020-20289 1 Yccms 1 Yccms 2024-11-21 9.8 Critical
Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters, triggers a sql injection vulnerability.
CVE-2020-20287 1 Yccms 1 Yccms 2024-11-21 9.8 Critical
Unrestricted file upload vulnerability in the yccms 3.3 project. The xhUp function's improper judgment of the request parameters, triggers remote code execution.
CVE-2020-20277 1 Troglobit 1 Uftpd 2024-11-21 9.8 Critical
There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10 due to improper implementation of a chroot jail in common.c's compose_abspath function that can be abused to read or write to arbitrary files on the filesystem, leak process memory, or potentially lead to remote code execution.
CVE-2020-20276 1 Troglobit 1 Uftpd 2024-11-21 9.8 Critical
An unauthenticated stack-based buffer overflow vulnerability in common.c's handle_PORT in uftpd FTP server versions 2.10 and earlier can be abused to cause a crash and could potentially lead to remote code execution.
CVE-2020-20269 1 Caret 1 Caret 2024-11-21 9.8 Critical
A specially crafted Markdown document could cause the execution of malicious JavaScript code in Caret Editor before 4.0.0-rc22.
CVE-2020-20189 1 Newpk Project 1 Newpk 2024-11-21 9.8 Critical
SQL Injection vulnerability in NewPK 1.1 via the title parameter to admin\newpost.php.
CVE-2020-20184 1 Liftoffsoftware 1 Gateone 2024-11-21 9.8 Critical
GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.
CVE-2020-20136 1 Quantconnect 1 Lean 2024-11-21 9.8 Critical
QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.
CVE-2020-20120 1 Thinkphp 1 Thinkphp 2024-11-21 9.8 Critical
ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" methods.
CVE-2020-20092 1 Articlecms Project 1 Articlecms 2024-11-21 9.8 Critical
File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which could let a remote malicious user execute arbitrary PHP code.
CVE-2020-1964 1 Apache 1 Heron 2024-11-21 9.8 Critical
It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerabilities (CWE-502: Deserialization of Untrusted Data).