Search Results (13517 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-1323 1 Microsoft 2 Sharepoint Enterprise Server, Sharepoint Server 2024-11-21 6.1 Medium
An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'.
CVE-2020-1220 1 Microsoft 9 Edge, Windows 10, Windows 7 and 6 more 2024-11-21 6.1 Medium
A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'.
CVE-2020-19954 1 S-cms 1 S-cms 2024-11-21 7.5 High
An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.
CVE-2020-19890 1 Dbhcms Project 1 Dbhcms 2024-11-21 4.9 Medium
DBHcms v1.2.0 has an Arbitrary file read vulnerability in dbhcms\mod\mod.editor.php $_GET['file'] is filename,and as there is no filter function for security, you can read any file's content.
CVE-2020-19155 1 Jflyfox 1 Jfinal Cms 2024-11-21 8.8 High
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.
CVE-2020-18985 1 Synacor 1 Zimbra Collaboration Suite 2024-11-21 6.1 Medium
An issue in /domain/service/.ewell-known/caldav of Zimbra Collaboration 8.8.12 allows attackers to redirect users to any arbitrary website of their choosing.
CVE-2020-18972 1 Podofo Project 1 Podofo 2024-11-21 5.5 Medium
Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'.
CVE-2020-18898 2 Exiv2, Redhat 2 Exiv2, Enterprise Linux 2024-11-21 6.5 Medium
A stack exhaustion issue in the printIFDStructure function of Exiv2 0.27 allows remote attackers to cause a denial of service (DOS) via a crafted file.
CVE-2020-18754 1 Dcce 2 Mac1100 Plc, Mac1100 Plc Firmware 2024-11-21 7.5 High
An information disclosure vulnerability exists within Dut Computer Control Engineering Co.'s PLC MAC1100.
CVE-2020-18705 1 Quokka Project 1 Quokka 2024-11-21 9.8 Critical
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'.
CVE-2020-18703 1 Quokka Project 1 Quokka 2024-11-21 9.8 Critical
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'.
CVE-2020-18660 1 Get-simple 1 Getsimplecms 2024-11-21 6.1 Medium
GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.
CVE-2020-18647 1 5none 1 Nonecms 2024-11-21 7.5 High
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".
CVE-2020-18646 1 5none 1 Nonecms 2024-11-21 7.5 High
Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/public/index.php".
CVE-2020-18392 1 Cesanta 1 Mjs 2024-11-21 5.5 Medium
Stack overflow vulnerability in parse_array Cesanta MJS 1.20.1, allows remote attackers to cause a Denial of Service (DoS) via a crafted file.
CVE-2020-18268 1 Zblogcn 1 Z-blogphp 2024-11-21 6.1 Medium
Open Redirect in Z-BlogPHP v1.5.2 and earlier allows remote attackers to obtain sensitive information via the "redirect" parameter in the component "zb_system/cmd.php."
CVE-2020-17484 1 Uffizio 1 Gps Tracker 2024-11-21 6.1 Medium
An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL within the application that causes a redirection to an arbitrary external domain.
CVE-2020-17474 1 Zkteco 3 Facedepot 7b, Facedepot 7b Firmware, Zkbiosecurity Server 2024-11-21 9.8 Critical
A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate users to administrators, delete users, and download user faces from the database.
CVE-2020-17473 1 Zkteco 3 Facedepot 7b, Facedepot 7b Firmware, Zkbiosecurity Server 2024-11-21 5.9 Medium
Lack of mutual authentication in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to obtain a long-lasting token by impersonating the server.
CVE-2020-17466 1 Turcom 1 Trcwifizone 2024-11-21 9.8 Critical
Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redirect responses.