Show filters
71,417 Total Results
Displaying 531-540 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
High

CVE-2020-28653

Disclosure Date: February 03, 2021 (last updated November 28, 2024)
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.
Attacker Value
Unknown

CVE-2020-15568

Disclosure Date: January 30, 2021 (last updated November 28, 2024)
TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.
Attacker Value
Unknown

CVE-2020-16013

Disclosure Date: January 08, 2021 (last updated November 28, 2024)
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Attacker Value
Unknown

CVE-2021-3018

Disclosure Date: January 05, 2021 (last updated November 28, 2024)
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the id parameter on the /cms/print.php page.
Attacker Value
Unknown

CVE-2020-35847

Disclosure Date: December 30, 2020 (last updated November 28, 2024)
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
Attacker Value
Unknown

CVE-2020-25494

Disclosure Date: December 18, 2020 (last updated November 28, 2024)
Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels parameter to cgi-bin/printbook.
Attacker Value
Unknown

CVE-2020-29574

Disclosure Date: December 11, 2020 (last updated November 28, 2024)
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
Attacker Value
Very High

CVE-2020-17530

Disclosure Date: December 11, 2020 (last updated November 28, 2024)
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
Attacker Value
Unknown

CVE-2020-26951

Disclosure Date: December 09, 2020 (last updated November 28, 2024)
A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
Attacker Value
Unknown

CVE-2020-27950

Disclosure Date: December 08, 2020 (last updated November 28, 2024)
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to disclose kernel memory.