CVE Database

CVE-2020-8125CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using klona.

CVE-2019-10787CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be controlled by user without any sanitization.

CVE-2019-10788CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible to inject arbitrary commands as part of the metadata options which is given to the "exec" function.

CVE-2020-8114CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-276

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

CVE-2020-6174CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-347

TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.

CVE-2020-6969CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-522

It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access the C-More Touch Panels EA9 series: firmware versions prior to 6.53 and manipulate system configurations.

CVE-2020-6754CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g., .jsp files) into /webapps/ROOT/assets/tmp_upload, which can lead to remote command execution (with the permissions of the user running the dotCMS application).

CVE-2019-20447CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint.

CVE-2010-4815CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution.

CVE-2015-5626CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to cause a denial of service (network-communications outage) via a crafted packet.

CVE-2015-5627CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to cause a denial of service (process outage) via a crafted packet.

CVE-2015-5628CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and earlier, Exaquantum R2.85.00 and earlier, Exaquantum/Batch R2.50.30 and earlier, Exapilot R3.96.10 and earlier, Exaplog R3.40.00 and earlier, Exasmoc R4.03.20 and earlier, Exarqe R4.03.20 and earlier, Field Wireless Device OPC Server R2.01.02 and earlier, PRM R3.12.00 and earlier, STARDOM VDS R7.30.01 and earlier, STARDOM OPC Server for Windows R3.40 and earlier, FAST/TOOLS R10.01 and earlier, B/M9000CS R5.05.01 and earlier, B/M9000 VP R7.03.04 and earlier, and FieldMate R1.01 or R1.02 allows remote attackers to execute arbitrary code via a crafted packet.

CVE-2011-1517CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash.

CVE-2015-2909CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote attackers to obtain access by leveraging situations in which this warning was not heeded. NOTE: the vendor states "The user is presented with clear warnings on the GUI that they should set usernames and passwords."

CVE-2013-4521CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165.

CVE-2019-10789CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.

CVE-2020-8636CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .

CVE-2020-8771CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts.

CVE-2020-8772CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.

CVE-2012-6306CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A vulnerability exists in HCView (aka Hardcoreview) 1.4 due to a write access violation with a GIF file.

CVE-2020-6760CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Schmid ZI 620 V400 VPN 090 routers allow an attacker to execute OS commands as root via shell metacharacters to an entry on the SSH subcommand menu, as demonstrated by ping.

CVE-2020-8645CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in Simplejobscript.com SJS through 1.66. There is an unauthenticated SQL injection via the job applications search function. The vulnerable parameter is job_id. The function is getJobApplicationsByJobId(). The file is _lib/class.JobApplication.php.

CVE-2019-10590CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-129

Out of bound access while parsing dts atom, which is non-standard as it does not have valid number of tracks in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCS405, QCS605, QM215, Rennell, SA6155P, Saipan, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

CVE-2013-4334CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities

CVE-2019-17268CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected.

CVE-2013-4335CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-776

opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilities

CVE-2014-9530CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A vulnerability exists in nw.js before 0.11.3 when calling nw methods from normal frames, which has an unspecified impact.

CVE-2019-15605CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-444

HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed

CVE-2019-15606CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

CVE-2013-3091CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."

CVE-2020-8796CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

Biscom Secure File Transfer (SFT) before 5.1.1071 and 6.0.1xxx before 6.0.1005 allows Remote Code Execution on the server.

CVE-2020-6770CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000 and DIVAR IP 7000 if a vulnerable BVMS version is installed.

CVE-2015-5741CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-444

The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fields.

CVE-2019-20062CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).

CVE-2012-6611CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and can be successfully used without setting this password.

CVE-2019-20451CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The HTTP API in Prismview System 9 11.10.17.00 and Prismview Player 11 13.09.1100 allows remote code execution by uploading RebootSystem.lnk and requesting /REBOOTSYSTEM or /RESTARTVNC. (Authentication is required but an XML file containing credentials can be downloaded.)

CVE-2020-8840CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.

CVE-2013-4267CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Power FS module (plugins/action.powerfs/class.PowerFSController.php), a (2) file name to the getTrustSizeOnFileSystem function in the File System (Standard) module (plugins/access.fs/class.fsAccessWrapper.php), or the (3) revision parameter to the Subversion Repository module (plugins/meta.svn/class.SvnManager.php).

CVE-2019-14514CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was discovered in Microvirt MEmu all versions prior to 7.0.2. A guest Android operating system inside the MEmu emulator contains a /system/bin/systemd binary that is run with root privileges on startup (this is unrelated to Red Hat's systemd init program, and is a closed-source proprietary tool that seems to be developed by Microvirt). This program opens TCP port 21509, presumably to receive installation-related commands from the host OS. Because everything after the installer:uninstall command is concatenated directly into a system() call, it is possible to execute arbitrary commands by supplying shell metacharacters.

CVE-2020-3934CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, contains a vulnerability of Pre-auth SQL Injection, allowing attackers to inject a specific SQL command.

CVE-2014-2052CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

CVE-2013-2057CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability

CVE-2013-1607CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability

CVE-2014-9753CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login parameter.

CVE-2014-0234CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1188

The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.

CVE-2014-9390CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.

CVE-2013-7378CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

scripts/email.coffee in the Hubot Scripts module before 2.4.4 for Node.js allows remote attackers to execute arbitrary commands.

CVE-2013-7381CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

libnotify before 1.0.4 for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in a call to libnotify.notify.

CVE-2015-5617CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in pub/m_pending_news/delete_pending_news.jsp in Enorth Webpublisher CMS allows remote attackers to execute arbitrary SQL commands via the cbNewsId parameter.

CVE-2013-3725CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.

← PreviousPage 339 / 7034Next →