Export limit exceeded: 76953 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (76953 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-24033 1 Fs 2 S3900 24t4s, S3900 24t4s Firmware 2024-11-21 8.8 High
An issue was discovered in fs.com S3900 24T4S 1.7.0 and earlier. The form does not have an authentication or token authentication mechanism that allows remote attackers to forge requests on behalf of a site administrator to change all settings including deleting users, creating new users with escalated privileges.
CVE-2020-24020 1 Ffmpeg 1 Ffmpeg 2024-11-21 8.8 High
Buffer Overflow vulnerability in FFMpeg 4.2.3 in dnn_execute_layer_pad in libavfilter/dnn/dnn_backend_native_layer_pad.c due to a call to memcpy without length checks, which could let a remote malicious user execute arbitrary code.
CVE-2020-23996 1 Ilias 1 Ilias 2024-11-21 8.8 High
A local file inclusion vulnerability in ILIAS before 5.3.19, 5.4.10 and 6.0 allows remote authenticated attackers to execute arbitrary code via the import of personal data.
CVE-2020-23972 1 Gmapfp 1 Gmapfp 2024-11-21 7.5 High
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating to the application and can also upload files which due to issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.
CVE-2020-23971 1 Gmapfp 1 Gmapfp 2024-11-21 7.5 High
gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to the application and also can upload files due the issues of unrestricted file uploads which can be bypassed by changing the content-type and name file too double extensions.
CVE-2020-23968 1 Ilex 1 International Sign\&go 2024-11-21 7.8 High
Ilex International Sign&go Workstation Security Suite 7.1 allows elevation of privileges via a symlink attack on ProgramData\Ilex\S&G\Logs\000-sngWSService1.log.
CVE-2020-23967 1 Drweb 1 Security Space 2024-11-21 7.8 High
Dr.Web Security Space versions 11 and 12 allow elevation of privilege for local users without administrative privileges to NT AUTHORITY\SYSTEM due to insufficient control during autoupdate.
CVE-2020-23960 1 Fork-cms 1 Fork Cms 2024-11-21 8.8 High
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Fork before 5.8.3 allows remote attackers to perform unauthorized actions as administrator to (1) approve the mass of the user's comments, (2) restoring a deleted user, (3) installing or running modules, (4) resetting the analytics, (5) pinging the mailmotor api, (6) uploading things to the media library, (7) exporting locale.
CVE-2020-23945 1 Victor Cms Project 1 Victor Cms 2024-11-21 7.5 High
A SQL injection vulnerability exists in Victor CMS V1.0 in the cat_id parameter of the category.php file. This parameter can be used by sqlmap to obtain data information in the database.
CVE-2020-23934 1 Ritecms 1 Ritecms 2024-11-21 8.8 High
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager" section.
CVE-2020-23931 1 Gpac 1 Gpac 2024-11-21 7.1 High
An issue was discovered in gpac before 1.0.1. The abst_box_read function in box_code_adobe.c has a heap-based buffer over-read.
CVE-2020-23928 1 Gpac 1 Gpac 2024-11-21 7.1 High
An issue was discovered in gpac before 1.0.1. The abst_box_read function in box_code_adobe.c has a heap-based buffer over-read.
CVE-2020-23922 2 Apache, Giflib Project 2 Bookkeeper, Giflib 2024-11-21 7.1 High
An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.
CVE-2020-23921 1 Fast Ber Project 1 Fast Ber 2024-11-21 7.1 High
An issue was discovered in fast_ber through v0.4. yy::yylex() in asn_compiler.hpp has a heap-based buffer over-read.
CVE-2020-23909 1 Advancemame 1 Advancemame 2024-11-21 7.1 High
Heap-based buffer over-read in function png_convert_4 in file pngex.cc in AdvanceMAME through 2.1.
CVE-2020-23879 1 Flowpaper 1 Pdf2json 2024-11-21 7.5 High
pdf2json v0.71 was discovered to contain a NULL pointer dereference in the component ObjectStream::getObject.
CVE-2020-23876 1 Science-miner 1 Pdf2xml 2024-11-21 7.5 High
pdf2xml v2.0 was discovered to contain a memory leak in the function TextPage::testLinkedText.
CVE-2020-23872 1 Science-miner 1 Pdf2xml 2024-11-21 7.5 High
A NULL pointer dereference in the function TextPage::restoreState of pdf2xml v2.0 allows attackers to cause a denial of service (DoS).
CVE-2020-23864 1 Iobit 1 Malware Fighter 2024-11-21 7.8 High
An issue exits in IOBit Malware Fighter version 8.0.2.547. Local escalation of privileges is possible by dropping a malicious DLL file into the WindowsApps folder.
CVE-2020-23837 1 Multi User Project 1 Multi User 2024-11-21 8.8 High
A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attackers to add admin (or other) users after an authenticated admin visits a third-party site or clicks on a URL.