Export limit exceeded: 371966 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (371966 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-10994 | 4 Canonical, Fedoraproject, Python and 1 more | 4 Ubuntu Linux, Fedora, Pillow and 1 more | 2024-11-21 | 5.5 Medium |
| In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file. | ||||
| CVE-2020-10993 | 1 Osmand | 1 Osmand | 2024-11-21 | 9.1 Critical |
| Osmand through 2.0.0 allow XXE because of binary/BinaryMapIndexReader.java. | ||||
| CVE-2020-10992 | 1 Azkaban Project | 1 Azkaban | 2024-11-21 | 9.8 Critical |
| Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java. | ||||
| CVE-2020-10991 | 1 Mulesoft | 1 Aplkit | 2024-11-21 | 9.8 Critical |
| Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java | ||||
| CVE-2020-10990 | 1 Accenture | 1 Mercury | 2024-11-21 | 9.8 Critical |
| An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component. | ||||
| CVE-2020-10989 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-11-21 | 6.1 Medium |
| An XSS issue in the /goform/WifiBasicSet endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute malicious payloads via the WifiName POST parameter. | ||||
| CVE-2020-10988 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-11-21 | 9.8 Critical |
| A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated remote attackers to start a telnetd service on the device. | ||||
| CVE-2020-10986 | 1 Tenda | 2 Ac15, Ac15 Firmware | 2024-11-21 | 6.5 Medium |
| A CSRF issue in the /goform/SysToolReboot endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to reboot the device and cause denial of service via a payload hosted by an attacker-controlled web page. | ||||
| CVE-2020-10985 | 1 Gambio | 1 Gambio Gx | 2024-11-21 | 4.8 Medium |
| Gambio GX before 4.0.1.0 allows XSS in admin/coupon_admin.php. | ||||
| CVE-2020-10984 | 1 Gambio | 1 Gambio Gx | 2024-11-21 | 8.8 High |
| Gambio GX before 4.0.1.0 allows admin/admin.php CSRF. | ||||
| CVE-2020-10983 | 1 Gambio | 1 Gambio Gx | 2024-11-21 | 4.9 Medium |
| Gambio GX before 4.0.1.0 allows SQL Injection in admin/mobile.php. | ||||
| CVE-2020-10982 | 1 Gambio | 1 Gambio Gx | 2024-11-21 | 4.9 Medium |
| Gambio GX before 4.0.1.0 allows SQL Injection in admin/gv_mail.php. | ||||
| CVE-2020-10981 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 4.3 Medium |
| GitLab EE/CE 9.0 to 12.9 allows a maintainer to modify other maintainers' pipeline trigger descriptions within the same project. | ||||
| CVE-2020-10980 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 9.8 Critical |
| GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration. | ||||
| CVE-2020-10979 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 4.3 Medium |
| GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines metrics to unauthorized users. | ||||
| CVE-2020-10978 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 5.3 Medium |
| GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API. | ||||
| CVE-2020-10977 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 5.5 Medium |
| GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects. | ||||
| CVE-2020-10976 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.5 High |
| GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget. | ||||
| CVE-2020-10975 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 4.3 Medium |
| GitLab EE/CE 10.8 to 12.9 is leaking metadata and comments on vulnerabilities to unauthorized users on the vulnerability feedback page. | ||||
| CVE-2020-10974 | 1 Wavlink | 26 Jetstream Ac3000, Jetstream Ac3000 Firmware, Jetstream Erac3000 and 23 more | 2024-11-21 | 7.5 High |
| An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, Wavlink WN530H4, Wavlink WN57X93, Wavlink WN572HG3, Wavlink WN575A4, Wavlink WN578A2, Wavlink WN579G3, Wavlink WN579X3, and Jetstream AC3000/ERAC3000 | ||||