Export limit exceeded: 363318 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 363318 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (363318 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-18889 | 1 Puppycms | 1 Puppycms | 2024-11-21 | 6.5 Medium |
| Cross Site Request Forgery (CSRF) vulnerability in puppyCMS v5.1 that can change the admin's password via /admin/settings.php. | ||||
| CVE-2020-18888 | 1 Puppycms | 1 Puppycms | 2024-11-21 | 7.5 High |
| Arbitrary File Deletion vulnerability in puppyCMS v5.1 allows remote malicious attackers to delete the file/folder via /admin/functions.php. | ||||
| CVE-2020-18886 | 1 Phpmywind | 1 Phpmywind | 2024-11-21 | 7.2 High |
| Unrestricted File Upload in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the component 'admin/upload_file_do.php'. | ||||
| CVE-2020-18885 | 1 Phpmywind | 1 Phpmywind | 2024-11-21 | 7.2 High |
| Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'. | ||||
| CVE-2020-18879 | 1 Bludit | 1 Bludit | 2024-11-21 | 9.8 Critical |
| Unrestricted File Upload in Bludit v3.8.1 allows remote attackers to execute arbitrary code by uploading malicious files via the component 'bl-kereln/ajax/upload-logo.php'. | ||||
| CVE-2020-18878 | 1 Skycaiji | 1 Skycaiji | 2024-11-21 | 5.3 Medium |
| Directory Traversal in Skycaiji v1.3 allows remote attackers to obtain sensitive information via the component 'index.php?m=admin&c=Tool&a=log&file=D%3A%5CphpStudy%5CWWW%5Cindex.php'. | ||||
| CVE-2020-18877 | 1 Wuzhicms | 1 Wuzhicms | 2024-11-21 | 7.5 High |
| SQL Injection in Wuzhi CMS v4.1.0 allows remote attackers to obtain sensitive information via the 'flag' parameter in the component '/coreframe/app/order/admin/index.php'. | ||||
| CVE-2020-18875 | 1 Dotcms | 1 Dotcms | 2024-11-21 | 8.8 High |
| Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files. | ||||
| CVE-2020-18839 | 1 Freedesktop | 1 Poppler | 2024-11-21 | 6.5 Medium |
| Buffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service. | ||||
| CVE-2020-18831 | 1 Exiv2 | 1 Exiv2 | 2024-11-21 | 7.8 High |
| Buffer Overflow vulnerability in tEXtToDataBuf function in pngimage.cpp in Exiv2 0.27.1 allows remote attackers to cause a denial of service and other unspecified impacts via use of crafted file. | ||||
| CVE-2020-18781 | 1 Audiofile | 1 Audiofile | 2024-11-21 | 5.5 Medium |
| Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file, this bug can be triggered by the executable sfconvert. | ||||
| CVE-2020-18780 | 1 Nasm | 1 Netwide Assembler | 2024-11-21 | 5.5 Medium |
| A Use After Free vulnerability in function new_Token in asm/preproc.c in nasm 2.14.02 allows attackers to cause a denial of service via crafted nasm command. | ||||
| CVE-2020-18778 | 1 Libav | 1 Libav | 2024-11-21 | 6.5 Medium |
| In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_p_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file. | ||||
| CVE-2020-18776 | 1 Libav | 1 Libav | 2024-11-21 | 6.5 Medium |
| In Libav 12.3, there is a segmentation fault in vc1_decode_b_mb_intfr in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file. | ||||
| CVE-2020-18775 | 1 Libav | 1 Libav | 2024-11-21 | 6.5 Medium |
| In Libav 12.3, there is a heap-based buffer over-read in vc1_decode_b_mb_intfi in vc1_block.c that allows an attacker to cause denial-of-service via a crafted file. | ||||
| CVE-2020-18774 | 1 Exiv2 | 1 Exiv2 | 2024-11-21 | 6.5 Medium |
| A float point exception in the printLong function in tags_int.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file. | ||||
| CVE-2020-18773 | 1 Exiv2 | 1 Exiv2 | 2024-11-21 | 6.5 Medium |
| An invalid memory access in the decode function in iptc.cpp of Exiv2 0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted tif file. | ||||
| CVE-2020-18771 | 2 Debian, Exiv2 | 2 Debian Linux, Exiv2 | 2024-11-21 | 8.1 High |
| Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak. | ||||
| CVE-2020-18768 | 1 Libtiff | 1 Libtiff | 2024-11-21 | 5.5 Medium |
| There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in libtiff 4.0.10, which allows an attacker to cause a denial-of-service through a crafted tiff file. | ||||
| CVE-2020-18766 | 1 Antsword Project | 1 Antsword | 2024-11-21 | 9.6 Critical |
| A cross-site scripting (XSS) vulnerability AntSword v2.0.7 can remotely execute system commands. | ||||