Export limit exceeded: 27656 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 40435 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (40435 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-23945 | 1 Victor Cms Project | 1 Victor Cms | 2024-11-21 | 7.5 High |
| A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter can be used by sqlmap to obtain data information in the database. | ||||
| CVE-2020-23936 | 1 Phpgurukul | 1 Vehicle Parking Management System | 2024-11-21 | 9.8 Critical |
| PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)". | ||||
| CVE-2020-23833 | 1 Projectworlds | 1 House Rental | 2024-11-21 | 9.8 Critical |
| Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on the hosting webserver via a malicious index.php POST request. | ||||
| CVE-2020-23793 | 1 Spice-space | 1 Spice-server | 2024-11-21 | 8.6 High |
| An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known if there will be other other effects. | ||||
| CVE-2020-23763 | 1 Online Book Store Project | 1 Online Book Store | 2024-11-21 | 9.8 Critical |
| SQL injection in admin.php in Online Book Store 1.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication. | ||||
| CVE-2020-23740 | 1 Drivergenius | 1 Drivergenius | 2024-11-21 | 7.8 High |
| In DriverGenius 9.61.5480.28 there is a local privilege escalation vulnerability in the driver wizard, attackers can use constructed programs to increase user privileges. | ||||
| CVE-2020-23735 | 1 Saibo | 1 Cyber Game Accelerator | 2024-11-21 | 7.8 High |
| In Saibo Cyber Game Accelerator 3.7.9 there is a local privilege escalation vulnerability. Attackers can use the constructed program to increase user privileges | ||||
| CVE-2020-23711 | 1 Naviwebs | 1 Navigate Cms | 2024-11-21 | 9.8 Critical |
| SQL Injection vulnerability in NavigateCMS 2.9 via the URL encoded GET input category in navigate.php. | ||||
| CVE-2020-23685 | 1 Vtimecn | 1 188jianzhan | 2024-11-21 | 9.8 Critical |
| SQL Injection vulnerability in 188Jianzhan v2.1.0, allows attackers to execute arbitrary code and gain escalated privileges, via the username parameter to login.php. | ||||
| CVE-2020-23630 | 1 Zzcms | 1 Zzcms | 2024-11-21 | 8.8 High |
| A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection). | ||||
| CVE-2020-23566 | 1 Irfanview | 1 Irfanview | 2024-11-21 | 5.5 Medium |
| Irfanview v4.53 was discovered to contain an infinity loop via JPEG2000!ShowPlugInSaveOptions_W+0x1ecd8. | ||||
| CVE-2020-23489 | 1 Wwbn | 1 Avideo | 2024-11-21 | 8.8 High |
| The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in place, and therefore a user can escalate privileges to admin. | ||||
| CVE-2020-23282 | 1 Mv | 1 Mconnect | 2024-11-21 | 7.5 High |
| SQL injection in Logon Page in MV's mConnect application, v02.001.00, allows an attacker to use a non existing user with a generic password to connect to the application and get access to unauthorized information. | ||||
| CVE-2020-23262 | 1 Mingsoft | 1 Mcms | 2024-11-21 | 9.8 Critical |
| An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do. | ||||
| CVE-2020-23150 | 1 Rconfig | 1 Rconfig | 2024-11-21 | 7.5 High |
| A SQL injection vulnerability in config.inc.php of rConfig 3.9.5 allows attackers to access sensitive database information via a crafted GET request to install/lib/ajaxHandlers/ajaxDbInstall.php. | ||||
| CVE-2020-23149 | 1 Rconfig | 1 Rconfig | 2024-11-21 | 7.5 High |
| The dbName parameter in ajaxDbInstall.php of rConfig 3.9.5 is unsanitized, allowing attackers to perform a SQL injection and access sensitive database information. | ||||
| CVE-2020-23045 | 1 Macs Cms Project | 1 Macs Cms | 2024-11-21 | 7.2 High |
| Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a SQL injection vulnerability via the 'roleId' parameter of the `editRole` and `deletUser` modules. | ||||
| CVE-2020-22882 | 1 Moddable | 1 Moddable | 2024-11-21 | 7.5 High |
| Issue was discovered in the fxParserTree function in moddable, allows attackers to cause denial of service via a crafted payload. Fixed in commit 723816ab9b52f807180c99fc69c7d08cf6c6bd61. | ||||
| CVE-2020-22807 | 1 Vtiger | 1 Vtiger Crm | 2024-11-21 | 9.8 Critical |
| An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature. | ||||
| CVE-2020-22781 | 1 Etherpad | 1 Etherpad | 2024-11-21 | 7.5 High |
| In Etherpad < 1.8.3, a specially crafted URI would raise an unhandled exception in the cache mechanism and cause a denial of service (crash the instance). | ||||