CVE-2020-20363: Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.
Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.
Published Jul 8, 2021 · Updated Jul 9, 2026
Browse CVE records published in 2020 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 50 of 19384 matching CVEs · Page 4 of 388.
Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.
Published Jul 8, 2021 · Updated Jul 9, 2026
WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box.
Published Sep 1, 2021 · Updated Jul 9, 2026
Buffer Overflow vulnerability in Avast AntiVirus before v.19.7 allows a local attacker to cause a denial of service via a crafted request to the aswSnx.sys driver.
Published Jul 11, 2023 · Updated Jul 9, 2026
An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon.
Published Jul 12, 2023 · Updated Jul 9, 2026
A Cross Site Request Forgery (CSRF) vulnerability was discovered in PHPMyWind 5.6 which allows attackers to create a new administrator account without authentication.
Published Oct 14, 2021 · Updated Jul 9, 2026
A SQL injection vulnerability has been discovered in zz cms version 2019 which allows attackers to retrieve sensitive data via the component subzs.php.
Published Oct 14, 2021 · Updated Jul 9, 2026
Cross Site Scripting (XSS) in redirect module of Racktables version 0.21.2, allows an attacker to inject arbitrary web script or HTML via the op parameter.
Published Dec 7, 2021 · Updated Jul 9, 2026
An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.
Published May 11, 2022 · Updated Jul 9, 2026
Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.
Published Mar 4, 2022 · Updated Jul 9, 2026
Multilple Cross Site Scripting (XSS) vulnerability exists in Intelliants Subrion CMS v4.2.1 in the Configuration panel.
Published Mar 4, 2022 · Updated Jul 9, 2026
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.1 via the q parameter in the Kickstart template.
Published Mar 4, 2022 · Updated Jul 9, 2026
Lexmark MX6500 LW75.JD.P296 and previous devices have Incorrect Access Control via the access control settings.
Published Feb 19, 2025 · Updated Jul 8, 2026
OS Command Injection vulnerability in OKER G955V1 v1.03.02.20161128, allows physical attackers to interrupt the boot sequence and execute arbitrary commands with root privileges.
Published Jan 18, 2023 · Updated Jul 5, 2026
In Saibo Cyber Game Accelerator 3.7.9 there is a local privilege escalation vulnerability. Attackers can use the constructed program to increase user privileges
Published Dec 3, 2020 · Updated Jul 4, 2026
Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,
Published Jun 21, 2021 · Updated Jul 4, 2026
Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and install malicious plugins for system access.
Published Jun 25, 2026 · Updated Jun 27, 2026
Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published Jun 23, 2026 · Updated Jun 24, 2026
Acrobat Reader versions 2020.009.20074, 2020.001.30002, 2017.011.30171, 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published Jun 23, 2026 · Updated Jun 23, 2026
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Published Jun 23, 2026 · Updated Jun 23, 2026
Rob--W cors-anywhere instances configured as an open proxy allow unauthenticated external users to induce the server to make HTTP requests to arbitrary targets (SSRF). Because the proxy forwards requests and headers, an attacker can reach internal-only endpoints and link-local metadata services, retrieve instance role credentials or other sensitive metadata, and interact with internal APIs and services that are not intended to be internet-facing. The vulnerability is exploitable by sending crafted requests to the proxy with the target resource encoded in the URL; many cors-anywhere deployments forward arbitrary methods and headers (including PUT), which can permit exploitation of IMDSv2 workflows as well as access to internal management APIs. Successful exploitation can result in theft of cloud credentials, unauthorized access to internal services, remote code execution or privilege escalation (depending on reachable backends), data exfiltration, and full compromise of cloud resources. Mitigation includes: restricting the proxy to trusted origins or authentication, whitelisting allowed target hosts, preventing access to link-local and internal IP ranges, removing support for unsafe HTTP methods/headers, enabling cloud provider mitigations, and deploying network-level protections.
Published Sep 25, 2025 · Updated Jun 23, 2026
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.
Published Aug 5, 2022 · Updated Jun 23, 2026
RealTimes Desktop Service 18.1.4 contains an unquoted service path vulnerability in the rpdsvc.exe binary that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories to execute arbitrary code with LocalSystem privileges during service startup or system reboot.
Published Jun 19, 2026 · Updated Jun 23, 2026
Realtek Audio Service 1.0.0.55 contains an unquoted service path vulnerability in RtkAudioService64.exe that allows local attackers to escalate privileges by injecting malicious code. Attackers can place executable files in the unquoted service path directory to execute arbitrary code with LocalSystem privileges during service startup or system reboot.
Published Jun 19, 2026 · Updated Jun 22, 2026
TFTP Broadband 4.3.0.1465 contains an unquoted service path vulnerability in the tftpt.exe service binary that allows local attackers to execute arbitrary code with system privileges. Attackers can place a malicious executable in the Program Files directory path that will be executed during service startup or system reboot with LocalSystem privileges.
Published Jun 19, 2026 · Updated Jun 22, 2026
TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to escalate privileges. NOTE: This implies that Snagit's use of OLE is a security vulnerability unto itself and it is not. See reference document for more details.
Published Jul 26, 2021 · Updated Jun 10, 2026
A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges. NOTE: Exploit of the Snagit installer would require the end user to ignore other safety mechanisms provided by the Host OS. See reference document for more details.
Published Jul 26, 2021 · Updated Jun 10, 2026
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Published Dec 9, 2020 · Updated Jun 10, 2026
Azure SDK for Java Security Feature Bypass Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Edge for Android Spoofing Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows SMB Information Disclosure Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Chakra Scripting Engine Memory Corruption Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Excel Security Feature Bypass Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Excel Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Excel Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Excel Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Excel Information Disclosure Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Excel Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft PowerPoint Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Excel Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft Excel Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft SharePoint Remote Code Execution Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft SharePoint Information Disclosure Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Microsoft SharePoint Server Spoofing Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Kerberos Security Feature Bypass Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Azure SDK for C Security Feature Bypass Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows Backup Engine Elevation of Privilege Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows Backup Engine Elevation of Privilege Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026
Windows Backup Engine Elevation of Privilege Vulnerability
Published Dec 9, 2020 · Updated Jun 9, 2026