Export limit exceeded: 335962 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 335962 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 34138 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (34138 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-19625 1 Gridx Project 1 Gridx 2024-11-21 9.8 Critical
Remote Code Execution Vulnerability in tests/support/stores/test_grid_filter.php in oria gridx 1.3, allows remote attackers to execute arbitrary code, via crafted value to the $query parameter.
CVE-2020-19498 1 Struktur 1 Libheif 2024-11-21 8.8 High
Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impacts.
CVE-2020-19492 1 Sam2p Project 1 Sam2p 2024-11-21 7.8 High
There is a floating point exception in ReadImage that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
CVE-2020-18980 1 Halo 1 Halo 2024-11-21 9.8 Critical
Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters.
CVE-2020-18439 1 Phpok 1 Phpok 2024-11-21 9.1 Critical
An issue was discoverered in in function edit_save_f in framework/admin/tpl_control.php in qinggan phpok 5.1, allows attackers to write arbitrary files or get a shell.
CVE-2020-18184 1 Pluxxml 1 Pluxxml 2024-11-21 7.2 High
In PluxXml V5.7,the theme edit function /PluXml/core/admin/parametres_edittpl.php allows remote attackers to execute arbitrary PHP code by placing this code into a template.
CVE-2020-18174 1 Autohotkey 1 Autohotkey 2024-11-21 9.8 Critical
A process injection vulnerability in setup.exe of AutoHotkey 1.1.32.00 allows attackers to escalate privileges.
CVE-2020-18078 1 Sem-cms 1 Semcms 2024-11-21 9.8 Critical
A vulnerability in /include/web_check.php of SEMCMS v3.8 allows attackers to reset the Administrator account's password.
CVE-2020-17952 1 Twothink Project 1 Twothink 2024-11-21 9.8 Critical
A remote code execution (RCE) vulnerability in /library/think/App.php of Twothink v2.0 allows attackers to execute arbitrary PHP code.
CVE-2020-17753 2 Rc Project, Rcpro Project 2 Rc, Rcpro 2024-11-21 6.5 Medium
An issue was discovered in function addMeByRC in the smart contract implementation for RC, an Ethereum token, allows attackers to transfer an arbitrary amount of tokens to an arbitrary address.
CVE-2020-17520 1 Apache 1 Pulsar Manager 2024-11-21 6.5 Medium
In the Pulsar manager 0.1.0 version, malicious users will be able to bypass pulsar-manager's admin, permission verification mechanism by constructing special URLs, thereby accessing any HTTP API.
CVE-2020-17508 1 Apache 1 Traffic Server 2024-11-21 7.5 High
The ATS ESI plugin has a memory disclosure vulnerability. If you are running the plugin please upgrade. Apache Traffic Server versions 7.0.0 to 7.1.11 and 8.0.0 to 8.1.0 are affected.
CVE-2020-17497 1 Intel 1 Inet Wireless Daemon 2024-11-21 8.1 High
eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAPOL Msg4/4.
CVE-2020-17487 2 Fedoraproject, Radare 2 Fedora, Radare2 2024-11-21 7.5 High
radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_parse_algorithmidentifier in libr/util/x509.c. This is due to a malformed object identifier in IMAGE_DIRECTORY_ENTRY_SECURITY.
CVE-2020-17485 1 Uffizio 1 Gps Tracker 2024-11-21 9.8 Critical
A Remote Code Execution vulnerability exist in Uffizio's GPS Tracker all versions. The web server can be compromised by uploading and executing a web/reverse shell. An attacker could then run commands, browse system files, and browse local resources
CVE-2020-17483 1 Uffizio 1 Gps Tracker 2024-11-21 7.5 High
An improper access control vulnerability exists in Uffizio's GPS Tracker all versions that lead to sensitive information disclosure of all the connected devices. By visiting the vulnerable host at port 9000, we see it responds with a JSON body that has all the details about the devices which have been deployed.
CVE-2020-17355 1 Arista 1 Eos 2024-11-21 7.5 High
Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause a denial of service (restart of agents) by crafting a malformed DHCP packet which leads to an incorrect route being installed.
CVE-2020-17353 4 Debian, Fedoraproject, Lilypond and 1 more 5 Debian Linux, Fedora, Lilypond and 2 more 2024-11-21 9.8 Critical
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
CVE-2020-17162 1 Microsoft 15 Windows 10, Windows 10 1507, Windows 10 1607 and 12 more 2024-11-21 8.8 High
Microsoft Windows Security Feature Bypass Vulnerability
CVE-2020-17110 1 Microsoft 1 Hevc Video Extensions 2024-11-21 7.8 High
HEVC Video Extensions Remote Code Execution Vulnerability