Export limit exceeded: 76953 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (76953 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-23836 1 Oswapp 1 Warehouse Inventory System 2024-11-21 8.8 High
A Cross-Site Request Forgery (CSRF) vulnerability in edit_user.php in OSWAPP Warehouse Inventory System (aka OSWA-INV) through 2020-08-10 allows remote attackers to change the admin's password after an authenticated admin visits a third-party site.
CVE-2020-23834 1 Realtimelogic 1 Barracudadrive 2024-11-21 8.8 High
Insecure Service File Permissions in the bd service in Real Time Logic BarracudaDrive v6.5 allow local attackers to escalate privileges to admin by replacing the %SYSTEMDRIVE%\bd\bd.exe file. When the computer next starts, the new bd.exe will be run as LocalSystem.
CVE-2020-23830 1 Stock Management System Project 1 Stock Management System 2024-11-21 7.1 High
A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 allows remote attackers to deny future logins by changing an authenticated victim's username when they visit a third-party site.
CVE-2020-23829 1 Librehealth 1 Librehealth Ehr 2024-11-21 8.8 High
interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.
CVE-2020-23826 1 Assaabloy 2 Yale Wipc-303w, Yale Wipc-303w Firmware 2024-11-21 8.8 High
The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. NOTE: This may be a duplicate of CVE-2020-10176
CVE-2020-23824 1 Argosoft 1 Mail Server 2024-11-21 8.8 High
ArGo Soft Mail Server 1.8.8.9 is affected by Cross Site Request Forgery (CSRF) for perform remote arbitrary code execution. The component is the Administration dashboard. When using admin/user credentials, if the admin/user admin opens a website with the malicious page that will run the CSRF.
CVE-2020-23811 1 Xuxueli 1 Xxl-job 2024-11-21 7.5 High
xxl-job 2.2.0 allows Information Disclosure of username, model, and password via job/admin/controller/UserController.java.
CVE-2020-23804 2 Debian, Freedesktop 2 Debian Linux, Poppler 2024-11-21 7.5 High
Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.
CVE-2020-23793 1 Spice-space 1 Spice-server 2024-11-21 8.6 High
An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known if there will be other other effects.
CVE-2020-23776 1 Winmail Project 1 Winmail 2024-11-21 7.5 High
A SSRF vulnerability exists in Winmail 6.5 in app.php in the key parameter when HTTPS is on. An attacker can use this vulnerability to cause the server to send a request to a specific URL. An attacker can modify the request header 'HOST' value to cause the server to send the request.
CVE-2020-23768 1 Phpyun 1 Phpyun 2024-11-21 7.5 High
An information disclosure vulnerability was discovered in alipay_function.php in the log file of Alibaba payment interface on PHPPYUN prior to version 5.0.1. If exploited, this vulnerability will allow attackers to obtain users' personally identifiable information including e-mail address and telephone numbers.
CVE-2020-23765 1 Bludit 1 Bludit 2024-11-21 7.2 High
A file upload vulnerability was discovered in the file path /bl-plugins/backup/plugin.php on Bludit version 3.12.0. If an attacker is able to gain Administrator rights they will be able to use unsafe plugins to upload a backup file and control the server.
CVE-2020-23740 1 Drivergenius 1 Drivergenius 2024-11-21 7.8 High
In DriverGenius 9.61.5480.28 there is a local privilege escalation vulnerability in the driver wizard, attackers can use constructed programs to increase user privileges.
CVE-2020-23735 1 Saibo 1 Cyber Game Accelerator 2024-11-21 7.8 High
In Saibo Cyber Game Accelerator 3.7.9 there is a local privilege escalation vulnerability. Attackers can use the constructed program to increase user privileges
CVE-2020-23722 1 Thedaylightstudio 1 Fuel Cms 2024-11-21 8.8 High
An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privilege via the "id" and "fuel_id" parameters.
CVE-2020-23715 1 Webport Cms Project 1 Webport Cms 2024-11-21 8.6 High
Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download.
CVE-2020-23686 1 Ayacms Project 1 Ayacms 2024-11-21 8.8 High
Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified impacts.
CVE-2020-23680 1 Text2pdf Project 1 Text2pdf 2024-11-21 7.8 High
An issue was discovered in function StartPage in text2pdf.c in pdfcorner text2pdf 1.1, allows attackers to cause denial of service or possibly other undisclosed impacts.
CVE-2020-23630 1 Zzcms 1 Zzcms 2024-11-21 8.8 High
A blind SQL injection vulnerability exists in zzcms ver201910 based on time (cookie injection).
CVE-2020-23622 1 Cling Project 1 Cling 2024-11-21 7.5 High
An issue in the UPnP protocol in 4thline cling 2.0.0 through 2.1.2 allows remote attackers to cause a denial of service via an unchecked CALLBACK parameter in the request header