Export limit exceeded: 88023 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (88023 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-19473 | 1 Flowpaper | 1 Pdf2json | 2024-11-21 | 5.5 Medium |
| An issue has been found in function DCTStream::decodeImage in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an uncaught floating point exception. | ||||
| CVE-2020-19469 | 1 Flowpaper | 1 Pdf2json | 2024-11-21 | 5.5 Medium |
| An issue has been found in function DCTStream::reset in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to an invalid write of size 8 . | ||||
| CVE-2020-19464 | 1 Flowpaper | 1 Pdf2json | 2024-11-21 | 5.5 Medium |
| An issue has been found in function XRef::fetch in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow . | ||||
| CVE-2020-19463 | 1 Flowpaper | 1 Pdf2json | 2024-11-21 | 5.5 Medium |
| An issue has been found in function vfprintf in PDF2JSON 0.70 that allows attackers to cause a Denial of Service due to a stack overflow. | ||||
| CVE-2020-19362 | 1 Vtiger | 1 Vtiger Crm | 2024-11-21 | 6.1 Medium |
| Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page. | ||||
| CVE-2020-19361 | 1 Medintux | 1 Medintux | 2024-11-21 | 6.1 Medium |
| Reflected XSS in Medintux v2.16.000 CCAM.php by manipulating the mot1 parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page. | ||||
| CVE-2020-19323 | 2 D-link, Dlink | 3 Dir-619l, Dir-619l, Dir-619l Firmware | 2024-11-21 | 7.5 High |
| An issue was discovered in /bin/mini_upnpd on D-Link DIR-619L 2.06beta devices. There is a heap buffer overflow allowing remote attackers to restart router via the M-search request ST parameter. No authentication required | ||||
| CVE-2020-19318 | 2 D-link, Dlink | 3 Dir-605l, Dir-605l, Dir-605l Firmware | 2024-11-21 | 8.8 High |
| Buffer Overflow vulnerability in D-Link DIR-605L, hardware version AX, firmware version 1.17beta and below, allows authorized attackers execute arbitrary code via sending crafted data to the webserver service program. | ||||
| CVE-2020-19316 | 2 Laravel, Microsoft | 2 Framework, Windows | 2024-11-21 | 8.8 High |
| OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17. | ||||
| CVE-2020-19295 | 1 Jeesns | 1 Jeesns | 2024-11-21 | 6.1 Medium |
| A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML. | ||||
| CVE-2020-19294 | 1 Jeesns | 1 Jeesns | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in the /article/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the article comments section. | ||||
| CVE-2020-19293 | 1 Jeesns | 1 Jeesns | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted article. | ||||
| CVE-2020-19292 | 1 Jeesns | 1 Jeesns | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in the /question/ask component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted question. | ||||
| CVE-2020-19291 | 1 Jeesns | 1 Jeesns | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in the /weibo/publishdata component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted Weibo. | ||||
| CVE-2020-19290 | 1 Jeesns | 1 Jeesns | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in the /weibo/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Weibo comment section. | ||||
| CVE-2020-19289 | 1 Jeesns | 1 Jeesns | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the new album tab. | ||||
| CVE-2020-19288 | 1 Jeesns | 1 Jeesns | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in the /localhost/u component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a private message. | ||||
| CVE-2020-19287 | 1 Jeesns | 1 Jeesns | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title. | ||||
| CVE-2020-19286 | 1 Jeesns | 1 Jeesns | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in the /question/detail component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the source field of the editor. | ||||
| CVE-2020-19285 | 1 Jeesns | 1 Jeesns | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Name text field. | ||||