Search Results (71174 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-19323 2 D-link, Dlink 3 Dir-619l, Dir-619l, Dir-619l Firmware 2024-11-21 7.5 High
An issue was discovered in /bin/mini_upnpd on D-Link DIR-619L 2.06beta devices. There is a heap buffer overflow allowing remote attackers to restart router via the M-search request ST parameter. No authentication required
CVE-2020-19318 2 D-link, Dlink 3 Dir-605l, Dir-605l, Dir-605l Firmware 2024-11-21 8.8 High
Buffer Overflow vulnerability in D-Link DIR-605L, hardware version AX, firmware version 1.17beta and below, allows authorized attackers execute arbitrary code via sending crafted data to the webserver service program.
CVE-2020-19316 2 Laravel, Microsoft 2 Framework, Windows 2024-11-21 8.8 High
OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.
CVE-2020-19304 1 Metinfo 1 Metinfo 2024-11-21 7.5 High
An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory traversal and access sensitive information.
CVE-2020-19303 1 Houdunren 1 Hdcms 2024-11-21 7.8 High
An arbitrary file upload vulnerability in /fileupload.php of hdcms 5.7 allows attackers to execute arbitrary code via a crafted file.
CVE-2020-19280 1 Jeesns 1 Jeesns 2024-11-21 8.8 High
Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program operations.
CVE-2020-19263 1 Mipcms 1 Mipcms 2024-11-21 8.8 High
A cross-site request forgery (CSRF) in MipCMS v5.0.1 allows attackers to arbitrarily escalate user privileges to administrator via index.php?s=/user/ApiAdminUser/itemEdit.
CVE-2020-19228 1 Bludit 1 Bludit 2024-11-21 7.2 High
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.
CVE-2020-19217 1 Piwigo 1 Piwigo 2024-11-21 8.8 High
SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.
CVE-2020-19216 1 Piwigo 1 Piwigo 2024-11-21 8.8 High
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.
CVE-2020-19215 1 Piwigo 1 Piwigo 2024-11-21 8.8 High
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.
CVE-2020-19199 1 Phpok 1 Phpok 2024-11-21 8.8 High
A Cross Site Request Forgery (CSRF) vulnerability exists in PHPOK 5.2.060 via admin.php?c=admin&f=save, which could let a remote malicious user execute arbitrary code.
CVE-2020-19159 1 Laiketui 1 Laiketui 2024-11-21 8.8 High
Cross Site Request Forgery (CSRF) in LaikeTui v3 allows remote attackers to execute arbitrary code via the component '/index.php?module=member&action=add'.
CVE-2020-19155 1 Jflyfox 1 Jfinal Cms 2024-11-21 8.8 High
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.
CVE-2020-19151 1 Jflyfox 1 Jfinal Cms 2024-11-21 8.8 High
Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.
CVE-2020-19150 1 Jflyfox 1 Jfinal Cms 2024-11-21 8.1 High
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.
CVE-2020-19137 1 Autumn Project 1 Autumn 2024-11-21 7.5 High
Incorrect Access Control in Autumn v1.0.4 and earlier allows remote attackers to obtain clear-text login credentials via the component "autumn-cms/user/getAllUser/?page=1&limit=10".
CVE-2020-19131 3 Debian, Redhat, Simplesystems 3 Debian Linux, Enterprise Linux, Libtiff 2024-11-21 7.5 High
Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "invertImage()" function in the component "tiffcrop".
CVE-2020-19047 1 Iwebshop 1 Iwebshop 2024-11-21 8.8 High
Cross Site Request Forgey (CSRF) in iWebShop v5.3 allows remote atatckers to execute arbitrary code via malicious POST request to the component '/index.php?controller=system&action=admin_edit_act'.
CVE-2020-18964 1 Forestblog Project 1 Forestblog 2024-11-21 8.8 High
Cross Site Request Forgery (CSRF) Vulnerability in ForestBlog latest version via the website Management background, which could let a remote malicious gain privileges.