CVE Database

CVE-2020-8088CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.

CVE-2013-2612CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary shell commands with root privileges due to an error in the Web UI.

CVE-2019-7131CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

Adobe Acrobat and Reader versions 2019.010.20064 and earlier, 2019.010.20064 and earlier, 2017.011.30110 and earlier version, and 2015.006.30461 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-8257CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2019-15585CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edition (EE) in the GitLab SAML integration had a validation issue that permitted an attacker to takeover another user's account.

CVE-2019-5464CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.

CVE-2014-3445CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash.

CVE-2013-1437CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.

CVE-2013-2060CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart.

CVE-2014-2914CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by set_prompt.

CVE-2014-2896CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an out-of-bounds read.

CVE-2014-2897CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows remote attackers to have unspecified impact via a crafted HMAC, which triggers an out-of-bounds read.

CVE-2014-2898CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers an out-of-bounds read when an error occurs, related to not checking the return code and MAC verification failure.

CVE-2020-5214CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

In NetHack before 3.6.5, detecting an unknown configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files. Users should upgrade to NetHack 3.6.5.

CVE-2020-8086CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username of a local admin.

CVE-2020-5212CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

In NetHack before 3.6.5, an extremely long value for the MENUCOLOR configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files. Users should upgrade to NetHack 3.6.5.

CVE-2020-5213CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

In NetHack before 3.6.5, too long of a value for the SYMBOL configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files. Users should upgrade to NetHack 3.6.5.

CVE-2015-8011CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.

CVE-2020-4207CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking when handling a failed HTTP request with specific content in the headers. By sending a specially crafted HTTP request, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause a denial of service. IBM X-Force ID: 174972.

CVE-2020-5211CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

In NetHack before 3.6.5, an invalid extended command in value for the AUTOCOMPLETE configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared systems that allow users to upload their own configuration files. Users should upgrade to NetHack 3.6.5.

CVE-2013-3071CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.

CVE-2019-20216CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because REMOTE_PORT is mishandled. The value of the urn: service/device is checked with the strstr function, which allows an attacker to concatenate arbitrary commands separated by shell metacharacters.

CVE-2019-20217CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because SERVER_ID is mishandled. The value of the urn: service/device is checked with the strstr function, which allows an attacker to concatenate arbitrary commands separated by shell metacharacters.

CVE-2026-2161CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was found in itsourcecode Directory Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/forget-password.php. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

CVE-2020-3718CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2020-3716CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2020-8432CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what-where condition, allowing an attacker to execute arbitrary code. NOTE: this vulnerablity was introduced when attempting to fix a memory leak identified by static analysis.

CVE-2013-3316CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".

CVE-2013-3317CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.

CVE-2019-10783CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function to parse user input.

CVE-2020-8443CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-193

In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-based buffer overflow during the cleaning of crafted syslog msgs (received from authenticated remote agents and delivered to the analysisd processing queue by ossec-remoted).

CVE-2020-8444CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of ossec-alert formatted msgs (received from authenticated remote agents and delivered to the analysisd processing queue by ossec-remoted).

CVE-2020-8445CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many cases, those characters are later logged. Because newlines (\n) are permitted in messages processed by ossec-analysisd, it may be possible to inject nested events into the ossec log. Use of terminal control characters may allow obfuscating events or executing commands when viewed through vulnerable terminal emulators. This may be an unauthenticated remote attack for certain types and origins of logged data.

CVE-2020-8447CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of syscheck formatted msgs (received from authenticated remote agents and delivered to the analysisd processing queue by ossec-remoted).

CVE-2014-3719CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Multiple SQL injection vulnerabilities in cgi-bin/review_m.cgi in Ex Libris ALEPH 500 (Integrated library management system) 18.1 and 20 allow remote attackers to execute arbitrary SQL commands via the (1) find, (2) lib, or (3) sid parameter.

CVE-2013-2198CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows attackers to bypass intended restrictions via a crafted username.

CVE-2020-7956CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-295

HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.

CVE-2020-8440CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a resume.

CVE-2016-2031CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive information, perform unauthorized actions and execute arbitrary code.

CVE-2014-2025CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unknown vectors.

CVE-2020-8508CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

nsak64.sys in Norman Malware Cleaner 2.08.08 allows users to call arbitrary kernel functions because the passing of function pointers between user and kernel mode is mishandled.

CVE-2020-7471CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with a user-specified column delimiter). By passing a suitably crafted delimiter to a contrib.postgres.aggregates.StringAgg instance, it was possible to break escaping and inject malicious SQL.

CVE-2020-8510CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password.

CVE-2020-8591CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.

CVE-2020-8592CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password feature).

CVE-2020-8597CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.

CVE-2020-5235CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

There is a potentially exploitable out of memory condition In Nanopb before 0.4.1, 0.3.9.5, and 0.2.9.4. When nanopb is compiled with PB_ENABLE_MALLOC, the message to be decoded contains a repeated string, bytes or message field and realloc() runs out of memory when expanding the array nanopb can end up calling `free()` on a pointer value that comes from uninitialized memory. Depending on platform this can result in a crash or further memory corruption, which may be exploitable in some cases. This problem is fixed in nanopb-0.4.1, nanopb-0.3.9.5, nanopb-0.2.9.4.

CVE-2012-5618CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-640

Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.

CVE-2019-4675CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171511.

CVE-2015-3613CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page

← PreviousPage 338 / 7034Next →