CVE Database

CVE-2019-20582CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) devices (Exynos9810 chipsets) software. There is a use after free in the ion driver. The Samsung ID is SVE-2019-14837 (August 2019).

CVE-2019-20583CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. There is type confusion in the EXT_FR Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14847 (August 2019).

CVE-2019-20584CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. There is type confusion in the HDCP Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14850 (August 2019).

CVE-2019-20585CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. There is type confusion in the SEC_FR Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14851 (August 2019).

CVE-2019-20586CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

An issue was discovered on Samsung mobile devices with O(8.1) and P(9.0) (with TEEGRIS) software. There is type confusion in the FINGERPRINT Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14864 (August 2019).

CVE-2020-6989CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, a buffer overflow in the web server allows remote attackers to cause a denial-of-service condition or execute arbitrary code.

CVE-2019-20576CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered on Samsung mobile devices with P(9.0) software. The MemorySaver Content Provider allows SQL injection. The Samsung ID is SVE-2019-14365 (August 2019).

CVE-2019-20590CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-191

An issue was discovered on Samsung mobile devices with O(8.x) (Qualcomm chipsets) software. There is an integer underflow in the Secure Storage Trustlet. The Samsung ID is SVE-2019-13952 (July 2019).

CVE-2019-20605CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. A heap overflow occurs for baseband in the Shannon modem. The Samsung ID is SVE-2019-14071 (May 2019).

CVE-2019-20607CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (MSM8996, MSM8998, Exynos7420, Exynos7870, Exynos8890, and Exynos8895 chipsets) software. A heap overflow in the keymaster Trustlet allows attackers to write to TEE memory, and achieve arbitrary code execution. The Samsung ID is SVE-2019-14126 (May 2019).

CVE-2019-20611CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), Go(8.1), P(9.0), and Go(9.0) (Exynos chipsets) software. A baseband stack overflow leads to arbitrary code execution. The Samsung ID is SVE-2019-13963 (April 2019).

CVE-2019-20621CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. There is a baseband heap overflow. The Samsung ID is SVE-2018-13187 (February 2019).

CVE-2019-20622CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. There is a baseband stack overflow. The Samsung ID is SVE-2018-13188 (February 2019).

CVE-2020-6985CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, these devices use a hard-coded service code for access to the console.

CVE-2020-6995CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-521

In Moxa PT-7528 series firmware, Version 4.0 or lower, and PT-7828 series firmware, Version 3.9 or lower, the application utilizes weak password requirements, which may allow an attacker to gain unauthorized access.

CVE-2020-6072CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

An exploitable code execution vulnerability exists in the label-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing compressed labels in mDNS messages, the rr_decode function's return value is not checked, leading to a double free that could be exploited to execute arbitrary code. An attacker can send an mDNS message to trigger this vulnerability.

CVE-2020-6981CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, an attacker may gain access to the system without proper authentication.

CVE-2020-6991CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-521

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, weak password requirements may allow an attacker to gain access using brute force.

CVE-2020-7007CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

In Moxa EDS-G516E Series firmware, Version 5.2 or lower, the attacker may execute arbitrary codes or target the device, causing it to go out of service.

CVE-2020-8986CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-754

lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain administrative access with a large number of requests.

CVE-2020-5560CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

WL-Enq 1.11 and 1.12 allows remote attackers to execute arbitrary OS commands with the administrative privilege via unspecified vectors.

CVE-2020-5553CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

mailform version 1.04 allows remote attackers to execute arbitrary PHP code via unspecified vectors.

CVE-2020-5556CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

CVE-2020-10789CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php.

CVE-2020-1957KEVCRITICALin_the_wild
CVSS 9.8
EPSS 88.60%
Priority 0

Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

CVE-2020-3792CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have a use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2020-3793CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have a use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2020-3795CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2020-3797CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2020-3799CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have a stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2020-3801CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have a use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2020-3805CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have a use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2020-3807CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have a buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

CVE-2020-5282CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

In Nick Chan Bot before version 1.0.0-beta there is a vulnerability in the `npm` command which is part of this software package. This allows arbitrary shell execution,which can compromise the bot This is patched in version 1.0.0-beta

CVE-2020-3794CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-829

ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Successful exploitation could lead to arbitrary code execution of files located in the webroot or its subdirectory.

CVE-2020-10881CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. A crafted DNS message can trigger an overflow of a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-9660.

CVE-2020-10885CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of DNS responses. The issue results from the lack of proper validation of DNS reponses prior to further processing. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the root user. Was ZDI-CAN-9661.

CVE-2020-10886CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tmpServer service, which listens on TCP port 20002. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9662.

CVE-2020-10887CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-693

This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of IPv6 connections. The issue results from the lack of proper filtering of IPv6 SSH connections. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-9663.

CVE-2020-10888CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

This vulnerability allows remote attackers to bypass authentication on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of SSH port forwarding requests during initial setup. The issue results from the lack of proper authentication prior to establishing SSH port forwarding rules. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the WAN interface. Was ZDI-CAN-9664.

CVE-2020-3775CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a buffer errors vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2020-3783CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a heap corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2020-3784CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2020-3785CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2020-3786CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2020-3787CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2020-3788CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2020-3789CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2020-7610CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.

CVE-2020-10964CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

Serendipity before 2.3.4 on Windows allows remote attackers to execute arbitrary code because the filename of a renamed file may end with a dot. This file may then be renamed to have a .php filename.

← PreviousPage 346 / 7034Next →