CVE Database

CVE-2013-3323CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.

CVE-2013-6295CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module

CVE-2014-3879CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a policy that does not exist, which causes the loaded policy chain to no be discarded and allows context-dependent attackers to bypass authentication via a login (1) without a password or (2) with an incorrect password.

CVE-2019-10791CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and options functions can be controlled by users without any sanitization.

CVE-2020-8441CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

JYaml through 1.3 allows remote code execution during deserialization of a malicious payload through the load() function. NOTE: this is a discontinued product.

CVE-2020-7796KEVCRITICALin_the_wild
CVSS 9.8
EPSS 93.55%
Priority 99

Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

CVE-2019-20477CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.

CVE-2019-20478CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an untrusted argument. In other words, this issue affects developers who are unaware of the need to use methods such as safe_load in these use cases.

CVE-2014-3622CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.

CVE-2016-1000004CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-345

Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_dom. This issue affects HHVM versions prior to 3.9.5, all versions between 3.10.0 and 3.12.3 (inclusive), and all versions between 3.13.0 and 3.14.1 (inclusive).

CVE-2016-1000005CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

mcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to type confusion if other types of data were passed in. This issue affects HHVM versions prior to 3.9.5, all versions between 3.10.0 and 3.12.3 (inclusive), and all versions between 3.13.0 and 3.14.1 (inclusive).

CVE-2014-2228CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-776

The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages.

CVE-2014-2727CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.

CVE-2019-4640CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-346

IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code which could result in an attacker executing malicious code. IBM X-Force ID: 170046.

CVE-2020-6061CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this vulnerability.

CVE-2014-9614CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/.

CVE-2020-3943CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to execute arbitrary code in vRealize Operations.

CVE-2020-6970CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially crafted script could execute code on the OpenEnterprise Server.

CVE-2013-2018CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2014-4678CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.

CVE-2014-3484CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Multiple stack-based buffer overflows in the __dn_expand function in network/dn_expand.c in musl libc 1.1x before 1.1.2 and 0.9.13 through 1.0.3 allow remote attackers to (1) have unspecified impact via an invalid name length in a DNS response or (2) cause a denial of service (crash) via an invalid name length in a DNS response, related to an infinite loop with no output.

CVE-2014-4657CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.

CVE-2020-3765CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe After Effects versions 16.1.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2020-9015CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow attackers to bypass intended TACACS+ shell restrictions via a | character. NOTE: the vendor reports that this is a configuration issue relating to an overly permissive regular expression in the TACACS+ server permitted commands

CVE-2016-4606CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized actions. This may aid in other attacks.

CVE-2020-6841CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

D-Link DCH-M225 1.05b01 and earlier devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the spotifyConnect.php userName parameter.

CVE-2012-0828CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 line from server containing characters outside of the Basic Multilingual Plane (BMP).

CVE-2020-9039CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-276

Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint exposed by the projector process is an endpoint that administrators can use for various tasks such as updating configuration and collecting performance profiles. The endpoint was unauthenticated and has been updated to only allow authenticated users to access these administrative APIs.

CVE-2020-9352CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parameter. NOTE: the documentation states "These tools are, by default, available to anyone ... so they should only be deployed into a trusted environment. Alternately, the tools can easily be restricted to administrators or end users by protecting the tools path with normal authentication and authorization mechanisms on the web server."

CVE-2020-9355CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled.

CVE-2019-18182CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable a non-default XferCommand and retrieve an attacker-controlled crafted database and package.

CVE-2019-18183CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable the non-default delta feature and retrieve an attacker-controlled crafted database and delta file.

CVE-2019-20481CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.

CVE-2020-4210CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175020.

CVE-2020-4211CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175022.

CVE-2020-4212CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175023.

CVE-2020-4213CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175024.

CVE-2020-4222CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175091.

CVE-2020-9366CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Specially crafted output, or a special program, could corrupt memory and crash Screen or possibly have unspecified other impact.

CVE-2019-10796CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

rpi through 0.0.3 allows execution of arbritary commands. The variable pinNumbver in function GPIO within src/lib/gpio.js is used as part of the arguement of exec function without any sanitization.

CVE-2018-14705CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these applications. This not only poses a severe risk to the availability of these applications, but also poses severe risks to the confidentiality and integrity of data stored within the applications and the device itself.

CVE-2019-12511CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

In NETGEAR Nighthawk X10-R9000 prior to 1.0.4.26, an attacker may execute arbitrary system commands as root by sending a specially-crafted MAC address to the "NETGEAR Genie" SOAP endpoint at AdvancedQoS:GetCurrentBandwidthByMAC. Although this requires QoS being enabled, advanced QoS being enabled, and a valid authentication JWT, additional vulnerabilities (CVE-2019-12510) allow an attacker to interact with the entire SOAP API without authentication. Additionally, DNS rebinding techniques may be used to exploit this vulnerability remotely. Exploiting this vulnerability is somewhat involved. The following limitations apply to the payload and must be overcome for successful exploitation: - No more than 17 characters may be used. - At least one colon must be included to prevent mangling. - A single-quote and meta-character must be used to break out of the existing command. - Parent command remnants after the injection point must be dealt with. - The payload must be in all-caps. Despite these limitations, it is still possible to gain access to an interactive root shell via this vulnerability. Since the web server assigns certain HTTP headers to environment variables with all-caps names, it is possible to insert a payload into one such header and reference the subsequent environment variable in the injection point.

CVE-2019-17275CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

OnCommand Cloud Manager versions prior to 3.8.0 are susceptible to arbitrary code execution by remote attackers.

CVE-2016-11020CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Kunena before 5.0.4 does not restrict avatar file extensions to gif, jpeg, jpg, and png. This can lead to XSS and remote code execution.

CVE-2020-9398CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

ISPConfig before 3.1.15p3, when the undocumented reverse_proxy_panel_allowed=sites option is manually enabled, allows SQL Injection.

CVE-2020-9406CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.

CVE-2019-19994CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows blind Command Injection. An attacker without authentication is able to execute arbitrary operating system command by injecting the vulnerable parameter in the PHP Web page /common/vam_monitor_sap.php.

CVE-2020-3923CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET, contain misconfigured authentication mechanism. Attackers can crack the default password and gain access to the system.

CVE-2020-3924CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.

CVE-2019-10801CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" function without any sanitization.

← PreviousPage 341 / 7034Next →