Export limit exceeded: 40429 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (40429 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-24400 | 1 Magento | 1 Magento | 2024-11-21 | 7.1 High |
| Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensitive information disclosure. This vulnerability could be exploited by an authenticated user with permissions to the product listing page to read data from the database. | ||||
| CVE-2020-24337 | 1 Altran | 2 Picotcp, Picotcp-ng | 2024-11-21 | 7.5 High |
| An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. When an unsupported TCP option with zero length is provided in an incoming TCP packet, it is possible to cause a Denial-of-Service by achieving an infinite loop in the code that parses TCP options, aka tcp_parse_options() in pico_tcp.c. | ||||
| CVE-2020-24315 | 1 Wordpress Poll Project | 1 Wordpress Poll | 2024-11-21 | 7.5 High |
| Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to a lack of user input escaping. This allows users who craft specific SQL statements to dump the entire targets database. | ||||
| CVE-2020-24264 | 1 Portainer | 1 Portainer | 2024-11-21 | 9.8 Critical |
| Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bind mounts are applied only on the client-side and not the server-side, which can lead to spawning a container with bind mount. Once such a container is spawned, it can be leveraged to break out of the container leading to complete Docker host machine takeover. | ||||
| CVE-2020-24221 | 1 Miniupnp Project | 1 Ngiflib | 2024-11-21 | 5.5 Medium |
| An issue was discovered in GetByte function in miniupnp ngiflib version 0.4, allows local attackers to cause a denial of service (DoS) via crafted .gif file (infinite loop). | ||||
| CVE-2020-24208 | 1 Online Shopping Alphaware Project | 1 Online Shopping Alphaware | 2024-11-21 | 9.8 Critical |
| A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication process via email and password parameters. | ||||
| CVE-2020-24197 | 1 Stock Management System Project | 1 Stock Management System | 2024-11-21 | 9.8 Critical |
| A SQL injection vulnerability in the login component in Stock Management System v1.0 allows remote attacker to execute arbitrary SQL commands via the username parameter. | ||||
| CVE-2020-24193 | 1 Daily Tracker System Project | 1 Daily Tracker System | 2024-11-21 | 9.8 Critical |
| A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter. | ||||
| CVE-2020-24000 | 1 Eyoucms | 1 Eyoucms | 2024-11-21 | 9.8 Critical |
| SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php. | ||||
| CVE-2020-23980 | 1 Designmasterevents | 1 Conference Management | 2024-11-21 | 9.8 Critical |
| DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page. | ||||
| CVE-2020-23979 | 1 13enforme | 1 13enforme Cms | 2024-11-21 | 9.8 Critical |
| 13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter. | ||||
| CVE-2020-23978 | 1 Soluzioneglobale | 1 Ecommerce Cms | 2024-11-21 | 9.8 Critical |
| SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php" | ||||
| CVE-2020-23976 | 1 Webexcels | 1 Ecommerce Cms | 2024-11-21 | 9.8 Critical |
| Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter. | ||||
| CVE-2020-23973 | 1 Kandnconcepts Club Cms Project | 1 Kandnconcepts Club Cms | 2024-11-21 | 9.8 Critical |
| KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter. | ||||
| CVE-2020-23945 | 1 Victor Cms Project | 1 Victor Cms | 2024-11-21 | 7.5 High |
| A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter can be used by sqlmap to obtain data information in the database. | ||||
| CVE-2020-23936 | 1 Phpgurukul | 1 Vehicle Parking Management System | 2024-11-21 | 9.8 Critical |
| PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)". | ||||
| CVE-2020-23833 | 1 Projectworlds | 1 House Rental | 2024-11-21 | 9.8 Critical |
| Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on the hosting webserver via a malicious index.php POST request. | ||||
| CVE-2020-23793 | 1 Spice-space | 1 Spice-server | 2024-11-21 | 8.6 High |
| An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known if there will be other other effects. | ||||
| CVE-2020-23763 | 1 Online Book Store Project | 1 Online Book Store | 2024-11-21 | 9.8 Critical |
| SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication. | ||||
| CVE-2020-23740 | 1 Drivergenius | 1 Drivergenius | 2024-11-21 | 7.8 High |
| In DriverGenius 9.61.5480.28 there is a local privilege escalation vulnerability in the driver wizard, attackers can use constructed programs to increase user privileges. | ||||