Search Results (339377 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-36034 1 School Faculty Scheduling System Project 1 School Faculty Scheduling System 2024-11-21 9.8 Critical
SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.
CVE-2020-36033 1 Water Billing System Project 1 Water Billing System 2024-11-21 9.8 Critical
SQL injection vulnerability in SourceCodester Water Billing System 1.0 via the id parameter to edituser.php.
CVE-2020-36012 1 Bdtask 1 Multi-store 2024-11-21 4.8 Medium
Stored XSS vulnerability in BDTASK Multi-Store Inventory Management System 1.0 allows a local admin to inject arbitrary code via the Customer Name Field.
CVE-2020-36011 1 Qdocs 1 Smart Hospital 2024-11-21 4.8 Medium
A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbitrary code via the Name, Guardian Name, Email, Address, Remarks, or Any Known Allergies field.
CVE-2020-36009 1 Obottle Project 1 Obottle 2024-11-21 7.5 High
OBottle 2.0 in \c\g.php contains an arbitrary file download vulnerability.
CVE-2020-36008 1 Obottle Project 1 Obottle 2024-11-21 8.1 High
OBottle 2.0 in \c\t.php contains an arbitrary file write vulnerability.
CVE-2020-36007 1 Appcms 1 Appcms 2024-11-21 6.1 Medium
AppCMS 2.0.101 in /admin/template/tpl_app.php has a cross site scripting attack vulnerability which allows the attacker to obtain sensitive information of other users.
CVE-2020-36006 1 Appcms 1 Appcms 2024-11-21 6.5 Medium
AppCMS 2.0.101 in /admin/info.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary files on the site.
CVE-2020-36005 1 Appcms 1 Appcms 2024-11-21 6.5 Medium
AppCMS 2.0.101 in /admin/app.php has an arbitrary file deletion vulnerability which allows attackers to delete arbitrary files on the site.
CVE-2020-36004 1 Appcms 1 Appcms 2024-11-21 6.5 Medium
AppCMS 2.0.101 in /admin/download_frame.php has a SQL injection vulnerability which allows attackers to obtain sensitive database information.
CVE-2020-36003 1 Online Book Store Project 1 Online Book Store 2024-11-21 7.5 High
The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases.
CVE-2020-36002 1 Seat-reservation-system Project 1 Seat-reservation-system 2024-11-21 7.5 High
Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive database information.
CVE-2020-35992 1 Fiserv 1 Prologue 2024-11-21 6.5 Medium
Fiserv Prologue through 2020-12-16 does not properly protect the database password. If an attacker were to gain access to the configuration file (specifically, the LogPassword attribute within appconfig.ini), they would be able to decrypt the password stored within the configuration file. This would yield cleartext credentials for the database (to gain access to financial records of customers stored within the database), and in some cases would allow remote login to the database.
CVE-2020-35990 1 Foxit 1 Pdf Reader 2024-11-21 5.5 Medium
Buffer Overflow vulnerability in cFilenameInit parameter in browseForDoc function in Foxit Software Foxit PDF Reader version 10.1.0.37527, allows local attackers to cause a denial of service (DoS) via crafted .pdf file.
CVE-2020-35987 1 Rukovoditel 1 Rukovoditel 2024-11-21 5.4 Medium
A stored cross site scripting (XSS) vulnerability in the 'Entities List' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.
CVE-2020-35986 1 Rukovoditel 1 Rukovoditel 2024-11-21 5.4 Medium
A stored cross site scripting (XSS) vulnerability in the 'Users Access Groups' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.
CVE-2020-35985 1 Rukovoditel 1 Rukovoditel 2024-11-21 5.4 Medium
A stored cross site scripting (XSS) vulnerability in the 'Global Lists" feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Name' parameter.
CVE-2020-35984 1 Rukovoditel 1 Rukovoditel 2024-11-21 5.4 Medium
A stored cross site scripting (XSS) vulnerability in the 'Users Alerts' feature of Rukovoditel 2.7.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' parameter.
CVE-2020-35982 1 Gpac 1 Gpac 2024-11-21 7.8 High
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function gf_hinter_track_finalize() in media_tools/isom_hinter.c.
CVE-2020-35981 1 Gpac 1 Gpac 2024-11-21 7.8 High
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function SetupWriters() in isomedia/isom_store.c.