Search Results (71321 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-23572 1 Beescms 1 Beescms 2024-11-21 8.8 High
BEESCMS v4.0 was discovered to contain an arbitrary file upload vulnerability via the component /admin/upload.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
CVE-2020-23565 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
Irfanview v4.53 allows attackers to execute arbitrary code via a crafted JPEG 2000 file. Related to a "Data from Faulting Address controls Branch Selection starting at JPEG2000!ShowPlugInSaveOptions_W+0x0000000000032850".
CVE-2020-23564 1 Sem-cms 1 Semcms 2024-11-21 7.2 High
File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.
CVE-2020-23560 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000001bcab.
CVE-2020-23559 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000007d7f.
CVE-2020-23558 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x0000000000007f4b.
CVE-2020-23557 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ShowPlugInSaveOptions_W+0x000000000000755d.
CVE-2020-23556 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e28.
CVE-2020-23555 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e6e.
CVE-2020-23554 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e20.
CVE-2020-23553 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007d33.
CVE-2020-23552 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e62.
CVE-2020-23551 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e30.
CVE-2020-23550 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!GetPlugInInfo+0x0000000000007e82.
CVE-2020-23549 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted .cr2 file, related to a "Data from Faulting Address controls Branch Selection starting at FORMATS!GetPlugInInfo+0x00000000000047f6".
CVE-2020-23546 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted XBM file, related to a "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FORMATS!ReadMosaic+0x0000000000000981.
CVE-2020-23545 1 Irfanview 1 Irfanview 2024-11-21 7.8 High
IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ReadXPM_W+0x0000000000000531.
CVE-2020-23539 1 Realtek 2 Rtl8723de, Rtl8723de Firmware 2024-11-21 7.5 High
An issue was discovered in Realtek rtl8723de BLE Stack <= 4.1 that allows remote attackers to cause a Denial of Service via the interval field to the CONNECT_REQ message.
CVE-2020-23533 1 Unionpayintl 1 Union Pay 2024-11-21 7.5 High
Union Pay up to 1.2.0, for web based versions contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a secret key which is NULL.
CVE-2020-23520 1 Txjia 1 Imcat 2024-11-21 7.2 High
imcat 5.2 allows an authenticated file upload and consequently remote code execution via the picture functionality.