Export limit exceeded: 88023 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (88023 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-19683 | 1 Zzzcms | 1 Zzzcms | 2024-11-21 | 5.4 Medium |
| A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an editfile action in save.php. | ||||
| CVE-2020-19667 | 2 Debian, Imagemagick | 2 Debian Linux, Imagemagick | 2024-11-21 | 7.8 High |
| Stack-based buffer overflow and unconditional jump in ReadXPMImage in coders/xpm.c in ImageMagick 7.0.10-7. | ||||
| CVE-2020-19664 | 1 Draytek | 2 Vigor2960, Vigor2960 Firmware | 2024-11-21 | 8.8 High |
| DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi. | ||||
| CVE-2020-19643 | 1 Insma | 2 Wifi Mini Spy 1080p Hd Security Ip Camera, Wifi Mini Spy 1080p Hd Security Ip Camera Firmware | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting (XSS) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B via all fields in the FTP settings page to the "goform/formSetFtpCfg" settings page. | ||||
| CVE-2020-19626 | 1 Craftcms | 1 Craft Cms | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new. | ||||
| CVE-2020-19619 | 1 Mblog Project | 1 Mblog | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the signature field to /settings/profile. | ||||
| CVE-2020-19618 | 1 Mblog Project | 1 Mblog | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post content field to /post/editing. | ||||
| CVE-2020-19617 | 1 Mblog Project | 1 Mblog | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the nickname field to /settings/profile. | ||||
| CVE-2020-19616 | 1 Mblog Project | 1 Mblog | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in mblog 3.5 via the post header field to /post/editing. | ||||
| CVE-2020-19611 | 1 Racktables Project | 1 Racktables | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting (XSS) in redirect module of Racktables version 0.21.2, allows an attacker to inject arbitrary web script or HTML via the op parameter. | ||||
| CVE-2020-19609 | 2 Artifex, Debian | 2 Mupdf, Debian Linux | 2024-11-21 | 5.5 Medium |
| Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF files allowing attackers to cause a denial of service. | ||||
| CVE-2020-19587 | 1 Idera | 1 Yellowfin Business Intelligence | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in configMap parameters in Yellowfin Business Intelligence 7.3 allows remote attackers to run arbitrary code via MIAdminStyles.i4 Admin UI. | ||||
| CVE-2020-19586 | 1 Yellowfinbi | 1 Business Intelligence | 2024-11-21 | 9.0 Critical |
| Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI. | ||||
| CVE-2020-19554 | 1 Manageengine | 1 Opmanager | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload. | ||||
| CVE-2020-19553 | 1 Wuzhicms | 1 Wuzhicms | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting (XSS) vlnerability exists in WUZHI CMS up to and including 4.1.0 in the config function in coreframe/app/attachment/libs/class/ckditor.class.php. | ||||
| CVE-2020-19527 | 1 Idreamsoft | 1 Icms | 2024-11-21 | 9.8 Critical |
| iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php. | ||||
| CVE-2020-19515 | 1 Qdpm | 1 Qdpm | 2024-11-21 | 6.1 Medium |
| qdPM V9.1 is vulnerable to Cross Site Scripting (XSS) via qdPM\install\modules\database_config.php. | ||||
| CVE-2020-19511 | 1 Typesettercms | 1 Typesetter | 2024-11-21 | 6.1 Medium |
| Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes, | ||||
| CVE-2020-19491 | 1 Sam2p Project | 1 Sam2p | 2024-11-21 | 7.8 High |
| There is an invalid memory access bug in cgif.c that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact. | ||||
| CVE-2020-19475 | 1 Flowpaper | 1 Pdf2json | 2024-11-21 | 5.5 Medium |
| An issue has been found in function CCITTFaxStream::lookChar in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid write of size 2 . | ||||