Export limit exceeded: 88023 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (88023 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-20951 1 Pluck-cms 1 Pluck 2024-11-21 9.8 Critical
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.
CVE-2020-20946 1 Qibosoft 1 Qibosoft 2024-11-21 5.4 Medium
Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add.
CVE-2020-20908 1 Akaunting 1 Akaunting 2024-11-21 5.4 Medium
Akaunting v1.3.17 was discovered to contain a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Company Name input field.
CVE-2020-20808 1 Qibosoft 1 Qibosoft 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in Qibosoft qibosoft v.7 and before allows a remote attacker to execute arbitrary code via the eindtijd and starttijd parameters of do/search.php.
CVE-2020-20799 1 Jeecms 1 Jeecms 2024-11-21 5.4 Medium
JeeCMS 1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the commentText parameter.
CVE-2020-20781 1 Ucms Project 1 Ucms 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title, key words, description or content text fields.
CVE-2020-20746 1 Tendacn 2 Ac9, Ac9 Firmware 2024-11-21 7.2 High
A stack-based buffer overflow in the httpd server on Tenda AC9 V15.03.06.60_EN allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via a crafted POST request to /goform/SetStaticRouteCfg.
CVE-2020-20740 3 Debian, Fedoraproject, Pdfresurrect Project 3 Debian Linux, Fedora, Pdfresurrect 2024-11-21 7.8 High
PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version().
CVE-2020-20701 1 S-cms 1 S-cms 2024-11-21 4.8 Medium
A stored cross site scripting (XSS) vulnerability in /app/config/of S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2020-20700 1 S-cms 1 S-cms 2024-11-21 4.8 Medium
A stored cross site scripting (XSS) vulnerability in /app/form_add/of S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Title Entry text box.
CVE-2020-20699 1 S-cms 1 S-cms 2024-11-21 4.8 Medium
A cross site scripting (XSS) vulnerability in S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Copyright text box under Basic Settings.
CVE-2020-20696 1 Gilacms 1 Gila Cms 2024-11-21 5.4 Medium
A cross-site scripting (XSS) vulnerability in /admin/content/post of GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Tags field.
CVE-2020-20695 1 Gilacms 1 Gila Cms 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in GilaCMS v1.11.4 allows attackers to execute arbitrary web scripts or HTML via a crafted SVG file.
CVE-2020-20663 1 Libiec Iccp Mod Project 1 Libiec Iccp Mod 2024-11-21 6.5 Medium
libiec_iccp_mod v1.5 contains a heap-buffer-overflow in the component mms_client_connection.c.
CVE-2020-20662 1 Libiec Iccp Mod Project 1 Libiec Iccp Mod 2024-11-21 6.5 Medium
libiec_iccp_mod v1.5 contains a heap-buffer-overflow in the component mms_client_example1.c.
CVE-2020-20645 1 Eyoucms 1 Eyoucms 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability exists in EyouCMS1.3.6 in the basic_information area.
CVE-2020-20640 1 Shopex 1 Ecshop 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in ECShop 4.0 due to security filtering issues, in the user.php file, we can use the html entity encoding to bypass the security policy of the safety.php file, triggering the xss vulnerability.
CVE-2020-20633 1 Cookielawinfo 1 Gdpr Cookie Consent 2024-11-21 5.4 Medium
ajax_policy_generator in admin/modules/cli-policy-generator/classes/class-policy-generator-ajax.php in GDPR Cookie Consent (cookie-law-info) 1.8.2 and below plugin for WordPress, allows authenticated stored XSS and privilege escalation.
CVE-2020-20628 1 Appsaloon 1 Wp-gdpr 2024-11-21 6.1 Medium
controller/controller-comments.php in WP GDPR plugin through 2.1.1 has unauthenticated stored XSS.
CVE-2020-20626 1 Lara\'s Google Analytics Project 1 Lara\'s Google Analytics 2024-11-21 5.4 Medium
lara-google-analytics.php in Lara Google Analytics plugin through 2.0.4 for WordPress allows authenticated stored XSS.