Search Results (77145 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-36131 1 Aomedia 1 Aomedia 2024-11-21 8.8 High
AOM v2.0.1 was discovered to contain a stack buffer overflow via the component stats/rate_hist.c.
CVE-2020-36129 1 Aomedia 1 Aomedia 2024-11-21 8.8 High
AOM v2.0.1 was discovered to contain a stack buffer overflow via the component src/aom_image.c.
CVE-2020-36128 1 Paxtechnology 1 Paxstore 2024-11-21 8.2 High
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability. Each payment terminal has a session token (called X-Terminal-Token) to access the marketplace. This allows the store to identify the terminal and make available the applications distributed by its reseller. By intercepting HTTPS traffic from the application store, it is possible to collect the request responsible for assigning the X-Terminal-Token to the terminal, which makes it possible to craft an X-Terminal-Token pretending to be another device. An attacker can use this behavior to authenticate its own payment terminal in the application store through token impersonation.
CVE-2020-36126 1 Paxtechnology 1 Paxstore 2024-11-21 8.1 High
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control that can lead to remote privilege escalation. PAXSTORE marketplace endpoints allow an authenticated user to read and write data not owned by them, including third-party users, application and payment terminals, where an attacker can impersonate any user which may lead to the unauthorized disclosure, modification, or destruction of information.
CVE-2020-36125 1 Paxtechnology 1 Paxstore 2024-11-21 7.1 High
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by incorrect access control where password revalidation in sensitive operations can be bypassed remotely by an authenticated attacker through requesting the endpoint directly.
CVE-2020-36120 1 Libsixel Project 1 Libsixel 2024-11-21 7.5 High
Buffer Overflow in the "sixel_encoder_encode_bytes" function of Libsixel v1.8.6 allows attackers to cause a Denial of Service (DoS).
CVE-2020-36079 1 Zenphoto 1 Zenphoto 2024-11-21 7.2 High
Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the uploader plugin, check the elFinder box, and then drag and drop files into the Files(elFinder) portion of the UI. This can, for example, place a .php file in the server's uploaded/ directory. NOTE: the vendor disputes this because exploitation can only be performed by an admin who has "lots of other possibilities to harm a site.
CVE-2020-36067 1 Gjson Project 1 Gjson 2024-11-21 7.5 High
GJSON <=v1.6.5 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a crafted GET call.
CVE-2020-36066 1 Gjson Project 1 Gjson 2024-11-21 7.5 High
GJSON <1.6.5 allows attackers to cause a denial of service (remote) via crafted JSON.
CVE-2020-36051 1 1234n 1 Minicms 2024-11-21 7.5 High
Directory traversal vulnerability in page_edit.php in MiniCMS V1.10 allows remote attackers to read arbitrary files via the state parameter.
CVE-2020-36049 1 Socket 1 Socket.io-parser 2024-11-21 7.5 High
socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used.
CVE-2020-36048 1 Socket 1 Engine.io 2024-11-21 7.5 High
Engine.IO before 4.0.0 allows attackers to cause a denial of service (resource consumption) via a POST request to the long polling transport.
CVE-2020-36037 1 Wuzhicms 1 Wuzhicms 2024-11-21 8.8 High
An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php.
CVE-2020-36009 1 Obottle Project 1 Obottle 2024-11-21 7.5 High
OBottle 2.0 in \c\g.php contains an arbitrary file download vulnerability.
CVE-2020-36008 1 Obottle Project 1 Obottle 2024-11-21 8.1 High
OBottle 2.0 in \c\t.php contains an arbitrary file write vulnerability.
CVE-2020-36003 1 Online Book Store Project 1 Online Book Store 2024-11-21 7.5 High
The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases.
CVE-2020-36002 1 Seat-reservation-system Project 1 Seat-reservation-system 2024-11-21 7.5 High
Seat-Reservation-System 1.0 has a SQL injection vulnerability in index.php in the id parameter where attackers can obtain sensitive database information.
CVE-2020-35982 1 Gpac 1 Gpac 2024-11-21 7.8 High
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function gf_hinter_track_finalize() in media_tools/isom_hinter.c.
CVE-2020-35981 1 Gpac 1 Gpac 2024-11-21 7.8 High
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function SetupWriters() in isomedia/isom_store.c.
CVE-2020-35980 1 Gpac 1 Gpac 2024-11-21 7.8 High
An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is a use-after-free in the function gf_isom_box_del() in isomedia/box_funcs.c.