Search Results (29905 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-19112 1 Projectworlds 1 Online Book Store Project In Php 2024-11-21 9.8 Critical
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a remote malicious user execute arbitrary code.
CVE-2020-19111 1 Projectworlds 1 Online Book Store Project In Php 2024-11-21 9.8 Critical
Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicious user bypass authentication and obtain sensitive information.
CVE-2020-19110 1 Projectworlds 1 Online Book Store Project In Php 2024-11-21 9.8 Critical
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let a remote malicious user execute arbitrary code.
CVE-2020-19109 1 Projectworlds 1 Online Book Store Project In Php 2024-11-21 9.8 Critical
SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_edit.php, which could let a remote malicious user execute arbitrary code.
CVE-2020-19108 1 Projectworlds 1 Online Book Store Project In Php 2024-11-21 9.8 Critical
SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remote malicious user execute arbitrary code.
CVE-2020-19107 1 Projectworlds 1 Online Book Store Project In Php 2024-11-21 9.8 Critical
SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote malicious user execute arbitrary code.
CVE-2020-19038 1 Halo 1 Halo 2024-11-21 9.1 Critical
File Deletion vulnerability in Halo 0.4.3 via delBackup.
CVE-2020-19001 1 Simiki Project 1 Simiki 2024-11-21 9.8 Critical
Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob/master/simiki/config.py'.
CVE-2020-18980 1 Halo 1 Halo 2024-11-21 9.8 Critical
Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters.
CVE-2020-18912 1 Earcms 1 Ear 2024-11-21 9.8 Critical
An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php.
CVE-2020-18890 1 Puppycms 1 Puppycms 2024-11-21 9.8 Critical
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.
CVE-2020-18879 1 Bludit 1 Bludit 2024-11-21 9.8 Critical
Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'.
CVE-2020-18766 1 Antsword Project 1 Antsword 2024-11-21 9.6 Critical
A cross-site scripting (XSS) vulnerability AntSword v2.0.7 can remotely execute system commands.
CVE-2020-18758 1 Dcce 2 Mac1100 Plc, Mac1100 Plc Firmware 2024-11-21 9.8 Critical
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code.
CVE-2020-18753 1 Dcce 2 Mac1100 Plc, Mac1100 Plc Firmware 2024-11-21 9.8 Critical
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to gain access to the system and escalate privileges via a crafted packet.
CVE-2020-18717 1 Zzzcms 1 Zzzphp 2024-11-21 9.8 Critical
SQL Injection in ZZZCMS zzzphp 1.7.1 allows remote attackers to execute arbitrary code due to a lack of parameter filtering in inc/zzz_template.php.
CVE-2020-18716 1 Rockoa 1 Rockoa 2024-11-21 9.8 Critical
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.php.
CVE-2020-18714 1 Rockoa 1 Rockoa 2024-11-21 9.8 Critical
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.php's getdata function.
CVE-2020-18713 1 Rockoa 1 Rockoa 2024-11-21 9.8 Critical
SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in customerAction.php
CVE-2020-18705 1 Quokka Project 1 Quokka 2024-11-21 9.8 Critical
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'.