Search Results (42607 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-20474 1 White Shark Systems Project 1 White Shark Systems 2024-11-21 7.5 High
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the default_task_edituser.php files failing to filter the csa_to_user parameter. Remote attackers can exploit the vulnerability to obtain database sensitive information.
CVE-2020-20473 1 White Shark Systems Project 1 White Shark Systems 2024-11-21 7.5 High
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the control_task.php, control_project.php, default_user.php files failing to filter the sort parameter. Remote attackers can exploit the vulnerability to obtain database sensitive information.
CVE-2020-20471 1 White Shark Systems Project 1 White Shark Systems 2024-11-21 8.8 High
White Shark System (WSS) 1.3.2 has an unauthorized access vulnerability in default_user_edit.php, remote attackers can exploit this vulnerability to escalate to admin privileges.
CVE-2020-20469 1 White Shark Systems Project 1 White Shark Systems 2024-11-21 7.5 High
White Shark System (WSS) 1.3.2 has a SQL injection vulnerability. The vulnerability stems from the log_edit.php files failing to filter the csa_to_user parameter, remote attackers can exploit the vulnerability to obtain database sensitive information.
CVE-2020-20466 1 White Shark Systems Project 1 White Shark Systems 2024-11-21 9.8 Critical
White Shark System (WSS) 1.3.2 is vulnerable to unauthorized access via user_edit_password.php, remote attackers can modify the password of any user.
CVE-2020-20444 1 Openclinic Project 1 Openclinic 2024-11-21 7.2 High
Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .
CVE-2020-20392 1 Txjia 1 Imcat 2024-11-21 9.8 Critical
SQL Injection vulnerability in imcat v5.2 via the fm[auser] parameters in coms/add_coms.php.
CVE-2020-20340 1 S-cms 1 S-cms 2024-11-21 7.5 High
A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive database information.
CVE-2020-20300 1 Weiphp 1 Weiphp 2024-11-21 9.8 Critical
SQL injection vulnerability in the wp_where function in WeiPHP 5.0.
CVE-2020-20296 1 Cmswing 1 Cmswing 2024-11-21 9.8 Critical
An issue was found in CMSWing project version 1.3.8, Because the rechargeAction function does not check the balance parameter, malicious parameters can execute arbitrary SQL commands.
CVE-2020-20295 1 Cmswing 1 Cmswing 2024-11-21 9.8 Critical
An issue was found in CMSWing project version 1.3.8. Because the updateAction function does not check the detail parameter, malicious parameters can execute arbitrary SQL commands.
CVE-2020-20294 1 Cmswing 1 Cmswing 2024-11-21 9.8 Critical
An issue was found in CMSWing project version 1.3.8. Because the log function does not check the log parameter, malicious parameters can execute arbitrary commands.
CVE-2020-20289 1 Yccms 1 Yccms 2024-11-21 9.8 Critical
Sql injection vulnerability in the yccms 3.3 project. The no_top function's improper judgment of the request parameters, triggers a sql injection vulnerability.
CVE-2020-20189 1 Newpk Project 1 Newpk 2024-11-21 9.8 Critical
SQL Injection vulnerability in NewPK 1.1 via the title parameter to admin\newpost.php.
CVE-2020-20120 1 Thinkphp 1 Thinkphp 2024-11-21 9.8 Critical
ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" methods.
CVE-2020-1998 1 Paloaltonetworks 1 Pan-os 2024-11-21 5.4 Medium
An improper authorization vulnerability in PAN-OS that mistakenly uses the permissions of local linux users instead of the intended SAML permissions of the account when the username is shared for the purposes of SSO authentication. This can result in authentication bypass and unintended resource access for the user. This issue affects: PAN-OS 7.1 versions earlier than 7.1.26; PAN-OS 8.1 versions earlier than 8.1.13; PAN-OS 9.0 versions earlier than 9.0.6; PAN-OS 9.1 versions earlier than 9.1.1; All versions of PAN-OS 8.0.
CVE-2020-1996 1 Paloaltonetworks 1 Pan-os 2024-11-21 5.3 Medium
A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages into the management server ms.log file. This vulnerability can be leveraged to obfuscate an ongoing attack or fabricate log entries in the ms.log file This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.9.
CVE-2020-1963 1 Apache 1 Ignite 2024-11-21 9.1 Critical
Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem.
CVE-2020-1951 4 Apache, Canonical, Debian and 1 more 6 Tika, Ubuntu Linux, Debian Linux and 3 more 2024-11-21 5.5 Medium
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
CVE-2020-1937 1 Apache 1 Kylin 2024-11-21 8.8 High
Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.