Export limit exceeded: 10020 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (10020 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-10496 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/edit-article.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit an article, given the id, via a crafted request.
CVE-2020-10495 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/edit-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit an article template, given the id, via a crafted request.
CVE-2020-10494 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/edit-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a news article, given the id, via a crafted request.
CVE-2020-10493 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/edit-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a glossary term, given the id, via a crafted request.
CVE-2020-10492 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/manage-templates.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article template via a crafted request.
CVE-2020-10491 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a department via a crafted request.
CVE-2020-10490 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a department via a crafted request.
CVE-2020-10489 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/manage-tickets.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a ticket via a crafted request.
CVE-2020-10488 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/manage-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a news article via a crafted request.
CVE-2020-10487 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a glossary term via a crafted request.
CVE-2020-10486 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/manage-comments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a comment via a crafted request.
CVE-2020-10485 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/manage-articles.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete an article via a crafted request.
CVE-2020-10484 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/add-field.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to create a custom field via a crafted request.
CVE-2020-10483 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to post a comment on any article via a crafted request.
CVE-2020-10482 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/add-template.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new article template via a crafted request.
CVE-2020-10481 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/add-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new glossary term via a crafted request.
CVE-2020-10480 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/add-category.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new category via a crafted request.
CVE-2020-10479 1 Chadhaajay 1 Phpkb 2024-11-21 4.3 Medium
CSRF in admin/add-news.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to add a new news article via a crafted request.
CVE-2020-10478 1 Chadhaajay 1 Phpkb 2024-11-21 8.8 High
CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settings, potentially gaining code execution or causing a denial of service, via a crafted request.
CVE-2020-10266 1 Universal-robots 4 Ur10, Ur3, Ur5 and 1 more 2024-11-21 8.1 High
UR+ (Universal Robots+) is a platform of hardware and software component sellers, for Universal Robots robots. When installing any of these components in the robots (e.g. in the UR10), no integrity checks are performed. Moreover, the SDK for making such components can be easily obtained from Universal Robots. An attacker could exploit this flaw by crafting a custom component with the SDK, performing Person-In-The-Middle attacks (PITM) and shipping the maliciously-crafted component on demand.