Export limit exceeded: 40313 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (40313 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-24400 1 Magento 1 Magento 2024-11-21 7.1 High
Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensitive information disclosure. This vulnerability could be exploited by an authenticated user with permissions to the product listing page to read data from the database.
CVE-2020-24384 1 A10networks 2 Advanced Core Operating System, Agalaxy 2024-11-21 9.8 Critical
A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution (RCE) vulnerability that could be used to compromise affected ACOS systems. ACOS versions 3.2.x (including and after 3.2.2), 4.x, and 5.1.x are affected. aGalaxy versions 3.0.x, 3.2.x, and 5.0.x are affected.
CVE-2020-24367 2 Bluestacks, Microsoft 2 Bluestacks, Windows 2024-11-21 7.8 High
Incorrect file permissions in BlueStacks 4 through 4.230 on Windows allow a local attacker to escalate privileges by modifying a file that is later executed by a higher-privileged user.
CVE-2020-24353 1 Pega 1 Pega Platform 2024-11-21 6.1 Medium
Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.
CVE-2020-24063 1 Canto 1 Canto 2024-11-21 7.2 High
The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF.
CVE-2020-23922 2 Apache, Giflib Project 2 Bookkeeper, Giflib 2024-11-21 7.1 High
An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.
CVE-2020-23564 1 Sem-cms 1 Semcms 2024-11-21 7.2 High
File Upload vulnerability in SEMCMS 3.9 allows remote attackers to run arbitrary code via SEMCMS_Upfile.php.
CVE-2020-23140 1 Microweber 1 Microweber 2024-11-21 8.1 High
Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active.
CVE-2020-23139 1 Microweber 1 Microweber 2024-11-21 5.5 Medium
Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.
CVE-2020-23138 1 Microweber 1 Microweber 2024-11-21 9.8 Critical
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.
CVE-2020-23136 1 Microweber 1 Microweber 2024-11-21 5.5 Medium
Microweber v1.1.18 is affected by no session expiry after log-out.
CVE-2020-22724 1 Mercury 4 Mer1200, Mer1200 Firmware, Mer1200g and 1 more 2024-11-21 9.8 Critical
A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 and Mercury Router MER1200G v1.0.1.
CVE-2020-22679 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
Memory leak in the sgpd_parse_entry function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.
CVE-2020-22678 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
An issue was discovered in gpac 0.8.0. The gf_media_nalu_remove_emulation_bytes function in av_parsers.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.
CVE-2020-22677 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
An issue was discovered in gpac 0.8.0. The dump_data_hex function in box_dump.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.
CVE-2020-22675 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
An issue was discovered in gpac 0.8.0. The GetGhostNum function in stbl_read.c has a heap-based buffer overflow which can lead to a denial of service (DOS) via a crafted input.
CVE-2020-22674 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
An issue was discovered in gpac 0.8.0. An invalid memory dereference exists in the function FixTrackID located in isom_intern.c, which allows attackers to cause a denial of service (DoS) via a crafted input.
CVE-2020-22673 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
Memory leak in the senc_Parse function in MP4Box in gpac 0.8.0 allows attackers to cause a denial of service (DoS) via a crafted input.
CVE-2020-22617 1 Ardour 1 Ardour 2024-11-21 9.8 Critical
Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext.
CVE-2020-22284 1 Lwip Project 1 Lwip 2024-11-21 7.5 High
A buffer overflow vulnerability in the zepif_linkoutput() function of Free Software Foundation lwIP git head version and version 2.1.2 allows attackers to access sensitive information via a crafted 6LoWPAN packet.