Export limit exceeded: 398987 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 398987 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (42613 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-24617 1 Mailtrain 1 Mailtrain 2024-11-21 8.8 High
Mailtrain through 1.24.1 allows SQL Injection in statsClickedSubscribersByColumn in lib/models/campaigns.js via /campaigns/clicked/ajax because variable column names are not properly escaped.
CVE-2020-24614 3 Fedoraproject, Fossil-scm, Opensuse 4 Fedora, Fossil, Backports Sle and 1 more 2024-11-21 8.8 High
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.
CVE-2020-24593 1 Mitel 1 Micloud Management Portal 2024-11-21 7.2 High
Mitel MiCloud Management Portal before 6.1 SP5 could allow a remote attacker to conduct a SQL Injection attack and access user credentials due to improper input validation.
CVE-2020-24569 1 Mbconnectline 2 Mbconnect24, Mymbconnect24 2024-11-21 4.3 Medium
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the knximport component via an advanced attack vector, allowing logged in attackers to discover arbitrary information.
CVE-2020-24568 1 Mbconnectline 2 Mbconnect24, Mymbconnect24 2024-11-21 6.5 Medium
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the lancompenent component, allowing logged-in attackers to discover arbitrary information.
CVE-2020-24503 2 Intel, Redhat 11 Ethernet Network Adapter E810-cqda1, Ethernet Network Adapter E810-cqda1 For Ocp, Ethernet Network Adapter E810-cqda1 For Ocp 3.0 and 8 more 2024-11-21 5.5 Medium
Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2020-24401 1 Magento 1 Magento 2024-11-21 6.5 Medium
Magento versions 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect authorization vulnerability. A user can still access resources provisioned under their old role after an administrator removes the role or disables the user's account.
CVE-2020-24400 1 Magento 1 Magento 2024-11-21 7.1 High
Magento versions 2.4.0 and 2.3.5 (and earlier) are affected by an SQL Injection vulnerability that could lead to sensitive information disclosure. This vulnerability could be exploited by an authenticated user with permissions to the product listing page to read data from the database.
CVE-2020-24337 1 Altran 2 Picotcp, Picotcp-ng 2024-11-21 7.5 High
An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. When an unsupported TCP option with zero length is provided in an incoming TCP packet, it is possible to cause a Denial-of-Service by achieving an infinite loop in the code that parses TCP options, aka tcp_parse_options() in pico_tcp.c.
CVE-2020-24315 1 Wordpress Poll Project 1 Wordpress Poll 2024-11-21 7.5 High
Vinoj Cardoza WordPress Poll Plugin v36 and lower executes SQL statement passed in via the pollid POST parameter due to a lack of user input escaping. This allows users who craft specific SQL statements to dump the entire targets database.
CVE-2020-24264 1 Portainer 1 Portainer 2024-11-21 9.8 Critical
Portainer 1.24.1 and earlier is affected by incorrect access control that may lead to remote arbitrary code execution. The restriction checks for bind mounts are applied only on the client-side and not the server-side, which can lead to spawning a container with bind mount. Once such a container is spawned, it can be leveraged to break out of the container leading to complete Docker host machine takeover.
CVE-2020-24221 1 Miniupnp Project 1 Ngiflib 2024-11-21 5.5 Medium
An issue was discovered in GetByte function in miniupnp ngiflib version 0.4, allows local attackers to cause a denial of service (DoS) via crafted .gif file (infinite loop).
CVE-2020-24208 1 Online Shopping Alphaware Project 1 Online Shopping Alphaware 2024-11-21 9.8 Critical
A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication process via email and password parameters.
CVE-2020-24197 1 Stock Management System Project 1 Stock Management System 2024-11-21 9.8 Critical
A SQL injection vulnerability in the login component in Stock Management System v1.0 allows remote attacker to execute arbitrary SQL commands via the username parameter.
CVE-2020-24193 1 Daily Tracker System Project 1 Daily Tracker System 2024-11-21 9.8 Critical
A SQL injection vulnerability in login in Sourcecodetester Daily Tracker System 1.0 allows unauthenticated user to execute authentication bypass with SQL injection via the email parameter.
CVE-2020-24000 1 Eyoucms 1 Eyoucms 2024-11-21 9.8 Critical
SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php.
CVE-2020-23980 1 Designmasterevents 1 Conference Management 2024-11-21 9.8 Critical
DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.
CVE-2020-23979 1 13enforme 1 13enforme Cms 2024-11-21 9.8 Critical
13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter.
CVE-2020-23978 1 Soluzioneglobale 1 Ecommerce Cms 2024-11-21 9.8 Critical
SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"
CVE-2020-23976 1 Webexcels 1 Ecommerce Cms 2024-11-21 9.8 Critical
Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.