Export limit exceeded: 91247 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (91247 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-23045 | 1 Macs Cms Project | 1 Macs Cms | 2024-11-21 | 7.2 High |
| Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a SQL injection vulnerability via the 'roleId' parameter of the `editRole` and `deletUser` modules. | ||||
| CVE-2020-23043 | 1 Air Sender Project | 1 Air Sender | 2024-11-21 | 8.8 High |
| Tran Tu Air Sender v1.0.2 was discovered to contain an arbitrary file upload vulnerability in the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted file. | ||||
| CVE-2020-23040 | 1 Sky File Project | 1 Sky File | 2024-11-21 | 7.5 High |
| Sky File v2.1.0 contains a directory traversal vulnerability in the FTP server which allows attackers to access sensitive data and files via 'null' path commands. | ||||
| CVE-2020-23038 | 1 Kumilabs | 1 Swift File Transfer | 2024-11-21 | 7.5 High |
| Swift File Transfer Mobile v1.1.2 and below was discovered to contain an information disclosure vulnerability in the path parameter. This vulnerability is exploited via an error caused by including non-existent path environment variables. | ||||
| CVE-2020-23026 | 1 Dhrystone Project | 1 Dhrystone | 2024-11-21 | 7.5 High |
| A NULL pointer dereference in the main() function dhry_1.c of dhrystone 2.1 causes a denial of service (DoS). | ||||
| CVE-2020-22907 | 1 Jsish | 1 Jsish | 2024-11-21 | 7.5 High |
| Stack overflow vulnerability in function jsi_evalcode_sub in jsish before 3.0.18, allows remote attackers to cause a Denial of Service via a crafted value to the execute parameter. | ||||
| CVE-2020-22886 | 1 Artifex | 1 Mujs | 2024-11-21 | 7.5 High |
| Buffer overflow vulnerability in function jsG_markobject in jsgc.c in mujs before 1.0.8, allows remote attackers to cause a denial of service. | ||||
| CVE-2020-22885 | 1 Artifex | 1 Mujs | 2024-11-21 | 7.5 High |
| Buffer overflow vulnerability in mujs before 1.0.8 due to recursion in the GC scanning phase, allows remote attackers to cause a denial of service. | ||||
| CVE-2020-22882 | 1 Moddable | 1 Moddable | 2024-11-21 | 7.5 High |
| Issue was discovered in the fxParserTree function in moddable, allows attackers to cause denial of service via a crafted payload. Fixed in commit 723816ab9b52f807180c99fc69c7d08cf6c6bd61. | ||||
| CVE-2020-22876 | 1 Quickjs Project | 1 Quickjs | 2024-11-21 | 7.5 High |
| Buffer Overflow vulnerability in quickjs.c in QuickJS, allows remote attackers to cause denial of service. This issue is resolved in the 2020-07-05 release. | ||||
| CVE-2020-22845 | 1 Mikrotik | 1 Routeros | 2024-11-21 | 7.5 High |
| A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted FTP requests. | ||||
| CVE-2020-22844 | 1 Mikrotik | 1 Routeros | 2024-11-21 | 7.5 High |
| A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted SMB requests. | ||||
| CVE-2020-22809 | 1 Windscribe | 1 Windscribe | 2024-11-21 | 7.8 High |
| In Windscribe v1.83 Build 20, 'WindscribeService' has an Unquoted Service Path that facilitates privilege escalation. | ||||
| CVE-2020-22785 | 1 Etherpad | 1 Etherpad | 2024-11-21 | 7.5 High |
| Etherpad < 1.8.3 is affected by a missing lock check which could cause a denial of service. Aggressively targeting random pad import endpoints with empty data would flatten all pads due to lack of rate limiting and missing ownership check. | ||||
| CVE-2020-22784 | 1 Etherpad | 1 Ueberdb | 2024-11-21 | 7.5 High |
| In Etherpad UeberDB < 0.4.4, due to MySQL omitting trailing spaces on char / varchar columns during comparisons, retrieving database records using UeberDB's MySQL connector could allow bypassing access controls enforced on key names. | ||||
| CVE-2020-22782 | 1 Etherpad | 1 Etherpad | 2024-11-21 | 7.5 High |
| Etherpad < 1.8.3 is affected by a denial of service in the import functionality. Upload of binary file to the import endpoint would crash the instance. | ||||
| CVE-2020-22781 | 1 Etherpad | 1 Etherpad | 2024-11-21 | 7.5 High |
| In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash the instance). | ||||
| CVE-2020-22761 | 1 Flatpress | 1 Flatpress | 2024-11-21 | 8.8 High |
| Cross Site Request Forgery (CSRF) vulnerability in FlatPress 1.1 via the DeleteFile function in flat/admin.php. | ||||
| CVE-2020-22741 | 1 Baidu | 1 Xuperchain | 2024-11-21 | 7.5 High |
| An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signature in multisignature. | ||||
| CVE-2020-22722 | 2 Microsoft, Rapidscada | 2 Windows, Rapid Scada | 2024-11-21 | 7.8 High |
| Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file. An attacker can obtain admin privileges by placing a malicious .exe file in the application and renaming it ScadaAgentSvc.exe, which would result in executing the binary as NT AUTHORITY\SYSTEM in a Windows operating system. For example, an attacker can plant a reverse shell from a low privileged user account and by restarting the computer, the malicious service will be started as NT AUTHORITY\SYSTEM by giving the attacker full system access to the remote PC. | ||||