Search Results (78851 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-11706 1 Provideserver 1 Provide Ftp Server 2024-11-21 8.8 High
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. The Admin Interface allows CSRF for actions such as: Change any username and password, admin ones included; Create/Delete users; Enable/Disable Services; Set a rogue update proxy; and Shutdown the server.
CVE-2020-11703 1 Provideserver 1 Provide Ftp Server 2024-11-21 7.5 High
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/GetInheritedProperties allows HTTP Response Splitting via the language parameter.
CVE-2020-11701 1 Provideserver 1 Provide Ftp Server 2024-11-21 8.8 High
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. CSRF exists in the User Web Interface, as demonstrated by granting filesystem access to the public for uploading and deleting files and directories.
CVE-2020-11699 1 Titanhq 1 Spamtitan 2024-11-21 8.8 High
An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute remote code on the target server. The user has to be authenticated before interacting with this page.
CVE-2020-11694 2 Jetbrains, Microsoft 2 Pycharm, Windows 2024-11-21 7.5 High
In JetBrains PyCharm 2019.2.5 and 2019.3 on Windows, Apple Notarization Service credentials were included. This is fixed in 2019.2.6 and 2019.3.3.
CVE-2020-11693 1 Jetbrains 1 Youtrack 2024-11-21 7.5 High
JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.
CVE-2020-11691 1 Jetbrains 1 Hub 2024-11-21 7.5 High
In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible.
CVE-2020-11688 1 Jetbrains 1 Teamcity 2024-11-21 7.5 High
In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.
CVE-2020-11687 1 Jetbrains 1 Teamcity 2024-11-21 7.5 High
In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.
CVE-2020-11685 1 Jetbrains 1 Goland 2024-11-21 7.5 High
In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.
CVE-2020-11681 1 Castel 2 Nextgen Dvr, Nextgen Dvr Firmware 2024-11-21 8.1 High
Castel NextGen DVR v1.0.0 stores and displays credentials for the associated SMTP server in cleartext. Low privileged users can exploit this to create an administrator user and obtain the SMTP credentials.
CVE-2020-11679 1 Castel 2 Nextgen Dvr, Nextgen Dvr Firmware 2024-11-21 8.8 High
Castel NextGen DVR v1.0.0 is vulnerable to privilege escalation through the Adminstrator/Users/Edit/:UserId functionality. Adminstrator/Users/Edit/:UserId fails to check that the request was submitted by an Administrator. This allows a normal user to escalate their privileges by adding additional roles to their account.
CVE-2020-11677 1 Cerner 1 Medico 2024-11-21 8.8 High
Cerner medico 26.00 has a Local Buffer Overflow (issue 3 of 3).
CVE-2020-11676 1 Cerner 1 Medico 2024-11-21 8.8 High
Cerner medico 26.00 has a Local Buffer Overflow (issue 2 of 3).
CVE-2020-11675 1 Cerner 1 Medico 2024-11-21 8.8 High
Cerner medico 26.00 has a Local Buffer Overflow (issue 1 of 3).
CVE-2020-11674 1 Cerner 1 Medico 2024-11-21 8.8 High
Cerner medico 26.00 allows variable reuse, possibly causing data corruption.
CVE-2020-11671 1 Teampass 1 Teampass 2024-11-21 8.1 High
Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administrator and read/modify all passwords via authenticated api/index.php REST API calls. NOTE: the API is not available by default.
CVE-2020-11668 2 Linux, Redhat 3 Linux Kernel, Enterprise Linux, Rhel Extras Rt 2024-11-21 7.1 High
In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.
CVE-2020-11666 1 Broadcom 1 Ca Api Developer Portal 2024-11-21 8.8 High
CA API Developer Portal 4.3.1 and earlier contains an access control flaw that allows malicious users to elevate privileges.
CVE-2020-11662 1 Broadcom 1 Ca Api Developer Portal 2024-11-21 7.5 High
CA API Developer Portal 4.3.1 and earlier handles requests insecurely, which allows remote attackers to exploit a Cross-Origin Resource Sharing flaw and access sensitive information.