Search Results (331236 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-21642 1 Zohocorp 1 Manageengine Analytics Plus 2024-11-21 9.8 Critical
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.
CVE-2020-21641 1 Zohocorp 1 Manageengine Analytics Plus 2024-11-21 7.5 High
Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file.
CVE-2020-21639 1 Ruijie 2 Rg-uac 6000-e50, Rg-uac 6000-e50 Firmware 2024-11-21 6.1 Medium
Ruijie RG-UAC 6000-E50 commit 9071227 was discovered to contain a cross-site scripting (XSS) vulnerability via the rule_name parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2020-21627 1 Ruijie 2 Rg-uac, Rg-uac Firmware 2024-11-21 7.5 High
Ruijie RG-UAC commit 9071227 was discovered to contain a vulnerability in the component /current_action.php?action=reboot, which allows attackers to cause a denial of service (DoS) via unspecified vectors.
CVE-2020-21606 1 Struktur 1 Libde265 2024-11-21 6.5 Medium
libde265 v1.0.4 contains a heap buffer overflow fault in the put_epel_16_fallback function, which can be exploited via a crafted a file.
CVE-2020-21605 1 Struktur 1 Libde265 2024-11-21 6.5 Medium
libde265 v1.0.4 contains a segmentation fault in the apply_sao_internal function, which can be exploited via a crafted a file.
CVE-2020-21604 1 Struktur 1 Libde265 2024-11-21 6.5 Medium
libde265 v1.0.4 contains a heap buffer overflow fault in the _mm_loadl_epi64 function, which can be exploited via a crafted a file.
CVE-2020-21603 1 Struktur 1 Libde265 2024-11-21 6.5 Medium
libde265 v1.0.4 contains a heap buffer overflow in the put_qpel_0_0_fallback_16 function, which can be exploited via a crafted a file.
CVE-2020-21602 1 Struktur 1 Libde265 2024-11-21 6.5 Medium
libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_bipred_16_fallback function, which can be exploited via a crafted a file.
CVE-2020-21601 1 Struktur 1 Libde265 2024-11-21 6.5 Medium
libde265 v1.0.4 contains a stack buffer overflow in the put_qpel_fallback function, which can be exploited via a crafted a file.
CVE-2020-21600 1 Struktur 1 Libde265 2024-11-21 6.5 Medium
libde265 v1.0.4 contains a heap buffer overflow in the put_weighted_pred_avg_16_fallback function, which can be exploited via a crafted a file.
CVE-2020-21599 2 Debian, Struktur 2 Debian Linux, Libde265 2024-11-21 6.5 Medium
libde265 v1.0.4 contains a heap buffer overflow in the de265_image::available_zscan function, which can be exploited via a crafted a file.
CVE-2020-21598 2 Debian, Struktur 2 Debian Linux, Libde265 2024-11-21 8.8 High
libde265 v1.0.4 contains a heap buffer overflow in the ff_hevc_put_unweighted_pred_8_sse function, which can be exploited via a crafted a file.
CVE-2020-21597 2 Debian, Struktur 2 Debian Linux, Libde265 2024-11-21 6.5 Medium
libde265 v1.0.4 contains a heap buffer overflow in the mc_chroma function, which can be exploited via a crafted a file.
CVE-2020-21596 2 Debian, Struktur 2 Debian Linux, Libde265 2024-11-21 6.5 Medium
libde265 v1.0.4 contains a global buffer overflow in the decode_CABAC_bit function, which can be exploited via a crafted a file.
CVE-2020-21595 1 Struktur 1 Libde265 2024-11-21 6.5 Medium
libde265 v1.0.4 contains a heap buffer overflow in the mc_luma function, which can be exploited via a crafted a file.
CVE-2020-21594 1 Struktur 1 Libde265 2024-11-21 6.5 Medium
libde265 v1.0.4 contains a heap buffer overflow in the put_epel_hv_fallback function, which can be exploited via a crafted a file.
CVE-2020-21590 1 Wuzhicms 1 Wuzhicms 2024-11-21 4.3 Medium
Directory traversal in coreframe/app/template/admin/index.php in WUZHI CMS 4.1.0 allows attackers to list files in arbitrary directories via the dir parameter.
CVE-2020-21588 1 Coreftp 1 Core Ftp 2024-11-21 5.5 Medium
Buffer overflow in Core FTP LE v2.2 allows local attackers to cause a denial or service (crash) via a long string in the Setup->Users->Username editbox.
CVE-2020-21585 1 Emlog 1 Emlog 2024-11-21 9.8 Critical
Vulnerability in emlog v6.0.0 allows user to upload webshells via zip plugin module.