• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2020-8547
2021-07-21
N/A
9.8 CRITICAL
phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.
CVE-2020-8545
2020-02-06
N/A
7.5 HIGH
Global.py in AIL framework 2.8 allows path traversal.
CVE-2020-8544
2020-06-17
N/A
6.5 MEDIUM
OX App Suite through 7.10.3 allows SSRF.
CVE-2020-8543
2021-07-21
N/A
7.5 HIGH
OX App Suite through 7.10.3 has Improper Input Validation.
CVE-2020-8542
2022-04-08
N/A
5.4 MEDIUM
OX App Suite through 7.10.3 allows XSS.
CVE-2020-8541
2020-06-17
N/A
6.5 MEDIUM
OX App Suite through 7.10.3 allows XXE attacks.
CVE-2020-8540
Manageengine Desktop Central, Zohocorp
Manageengine_adselfservice_plus, Application_control_plus, Desktop_central, Firewall_analyzer, Log360, Manageengine_access_manager_plus, Manageengine_ad360, Manageengine_adaudit_plus, Manageengine_admanager_plus, Manageengine_analytics_plus
2021-07-21
N/A
9.8 CRITICAL
An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
CVE-2020-8539
2020-12-08
N/A
7.8 HIGH
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an attacker to inject unauthorized commands, by executing the micomd executable deamon, to trigger unintended functionalities. In addition, this executable may be used by an attacker to inject commands to generate CAN frames that are sent into the M-CAN bus (Multimedia CAN bus) of the vehicle.
CVE-2020-8521
2020-07-09
N/A
9.8 CRITICAL
SQL injection with start and length parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql
CVE-2020-8520
2020-07-09
N/A
9.8 CRITICAL
SQL injection in order and column parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql
« Previous 1 … 3,173 3,174 3,175 3,176 3,177 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE