Export limit exceeded: 381905 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381905 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-24007 | 1 Umanni | 1 Human Resources | 2024-11-21 | 9.8 Critical |
| Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page. | ||||
| CVE-2020-24003 | 1 Microsoft | 1 Skype | 2024-11-21 | 3.3 Low |
| Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Skype Client's microphone and camera access. | ||||
| CVE-2020-24000 | 1 Eyoucms | 1 Eyoucms | 2024-11-21 | 9.8 Critical |
| SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php. | ||||
| CVE-2020-23996 | 1 Ilias | 1 Ilias | 2024-11-21 | 8.8 High |
| A local file inclusion vulnerability in ILIAS before 5.3.19, 5.4.10 and 6.0 allows remote authenticated attackers to execute arbitrary code via the import of personal data. | ||||
| CVE-2020-23995 | 1 Ilias | 1 Ilias | 2024-11-21 | 6.5 Medium |
| An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload. | ||||
| CVE-2020-23992 | 1 Nagios | 1 Nagios Xi | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request. | ||||
| CVE-2020-23989 | 1 Nedi | 1 Nedi | 2024-11-21 | 5.4 Medium |
| NeDi 1.9C allows pwsec.php oid XSS. | ||||
| CVE-2020-23986 | 1 Github Readme Stats Project | 1 Github Readme Stats | 2024-11-21 | 6.1 Medium |
| Github Read Me Stats commit 3c7220e4f7144f6cb068fd433c774f6db47ccb95 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the function renderError. | ||||
| CVE-2020-23984 | 1 Online Hotel Booking System Pro Project | 1 Online Hotel Booking System Pro | 2024-11-21 | 5.4 Medium |
| Online Hotel Booking System Pro PHP Version 1.3 has Persistent Cross-site Scripting in Customer registration-form all-tags. | ||||
| CVE-2020-23983 | 1 Ichat Project | 1 Ichat | 2024-11-21 | 5.4 Medium |
| Michael-design iChat Realtime PHP Live Support System 1.6 has persistent Cross-site Scripting via chat,text-filed tags. | ||||
| CVE-2020-23982 | 1 Designmasterevents | 1 Conference Management Cms | 2024-11-21 | 6.1 Medium |
| DesignMasterEvents Conference management 1.0.0 has cross site scripting via the 'certificate.php' | ||||
| CVE-2020-23981 | 1 13enforme | 1 13enforme Cms | 2024-11-21 | 6.1 Medium |
| 13enforme CMS 1.0 has Cross Site Scripting via the "content.php" id parameter. | ||||
| CVE-2020-23980 | 1 Designmasterevents | 1 Conference Management | 2024-11-21 | 9.8 Critical |
| DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page. | ||||
| CVE-2020-23979 | 1 13enforme | 1 13enforme Cms | 2024-11-21 | 9.8 Critical |
| 13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter. | ||||
| CVE-2020-23978 | 1 Soluzioneglobale | 1 Ecommerce Cms | 2024-11-21 | 9.8 Critical |
| SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php" | ||||
| CVE-2020-23977 | 1 Kandnconcepts Club Cms Project | 1 Kandnconcepts Club Cms | 2024-11-21 | 6.1 Medium |
| KandNconcepts Club CMS 1.1 and 1.2 has cross site scripting via the 'team.php,player.php,club.php' id parameter. | ||||
| CVE-2020-23976 | 1 Webexcels | 1 Ecommerce Cms | 2024-11-21 | 9.8 Critical |
| Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter. | ||||
| CVE-2020-23975 | 1 Webexcels | 1 Ecommerce Cms | 2024-11-21 | 6.1 Medium |
| Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has cross site scripting via the 'search.php' id parameter. | ||||
| CVE-2020-23974 | 1 Create-project Manager Project | 1 Create-project Manager | 2024-11-21 | 5.4 Medium |
| Create-Project Manager 1.07 has Multi Persistent Cross-site Scripting and HTML injection in via Online chat, Social feed,Message(title-tag), Add new client (all-tags). | ||||
| CVE-2020-23973 | 1 Kandnconcepts Club Cms Project | 1 Kandnconcepts Club Cms | 2024-11-21 | 9.8 Critical |
| KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter. | ||||