CVE Database

CVE-2020-6814CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

CVE-2020-6815CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed evidence of memory corruption or escalation of privilege and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 74.

CVE-2020-10245CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

CODESYS V3 web server before 3.5.15.40, as used in CODESYS Control runtime systems, has a buffer overflow.

CVE-2020-3936CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

UltraLog Express device management interface does not properly filter user inputted string in some specific parameters, attackers can inject arbitrary SQL command.

CVE-2020-10823CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 1 of 3).

CVE-2020-10824CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 2 of 3).

CVE-2020-10825CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 3 of 3).

CVE-2020-10826CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a remote HTTP request in DEBUG mode.

CVE-2020-10827CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.

CVE-2020-10828CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.

CVE-2020-10990CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component.

CVE-2020-10991CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java

CVE-2020-10992CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java.

CVE-2015-5684CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly disclosed in 2015) in the Lenovo Service Engine (LSE), affecting various versions of BIOS for Lenovo Notebooks, that could allow a remote user to execute arbitrary code on the system.

CVE-2020-10956CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.

CVE-2020-5723CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-312

The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an attacker to retrieve all passwords and possibly gain elevated privileges.

CVE-2019-19605CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

X-Plane before 11.41 allows Arbitrary Memory Write via crafted network packets, which could cause a denial of service or arbitrary code execution.

CVE-2019-19606CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary paths (or a leak of OS credentials to a remote system) via crafted network packets. This could be used to execute arbitrary commands on the system.

CVE-2020-10374CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot function in the Contact Support form.

CVE-2020-11105CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-763

An issue was discovered in USC iLab cereal through 1.3.0. It employs caching of std::shared_ptr values, using the raw pointer address as a unique identifier. This becomes problematic if an std::shared_ptr variable goes out of scope and is freed, and a new std::shared_ptr is allocated at the same address. Serialization fidelity thereby becomes dependent upon memory layout. In short, serialized std::shared_ptr variables cannot always be expected to serialize back into their original values. This can have any number of consequences, depending on the context within which this manifests.

CVE-2020-7611CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-444

All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed to the client.

CVE-2020-10595CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental prompting by a Kerberos library. It may overflow a buffer provided by the underlying Kerberos library by a single '\0' byte if an attacker responds to a prompt with an answer of a carefully chosen length. The effect may range from heap corruption to stack corruption depending on the structure of the underlying Kerberos library, with unknown effects but possibly including code execution. This code path is not used for normal authentication, but only when the Kerberos library does supplemental prompting, such as with PKINIT or when using the non-standard no_prompt PAM configuration option.

CVE-2020-4208CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174975.

CVE-2020-6008KEVCRITICALin_the_wild
CVSS 9.8
EPSS 7.55%
Priority 0

LifterLMS Wordpress plugin version below 3.37.15 is vulnerable to arbitrary file write leading to remote code execution

CVE-2020-5344CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

Dell EMC iDRAC7, iDRAC8 and iDRAC9 versions prior to 2.65.65.65, 2.70.70.70, 4.00.00.00 contain a stack-based buffer overflow vulnerability. An unauthenticated remote attacker may exploit this vulnerability to crash the affected process or execute arbitrary code on the system by sending specially crafted input data.

CVE-2020-7947CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1236

An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting of the user data. This can lead to (at least) CSV injection if a crafted Excel document is uploaded.

CVE-2018-11106CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versions prior to 6.5.3.5; WC7520, running firmware versions prior to 2.5.0.46; WC7600v1, running firmware versions prior to 6.5.3.5; WC7600v2, running firmware versions prior to 6.5.3.5; and WC9500, running firmware versions prior to 6.5.3.5.

CVE-2020-10867CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-668

An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended access restrictions on tasks from an untrusted process, when Self Defense is enabled.

CVE-2020-3909CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2.

CVE-2020-3910CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2.

CVE-2020-3911CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple issues in libxml2.

CVE-2020-9769CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Multiple issues were addressed by updating to version 8.1.1850. This issue is fixed in macOS Catalina 10.15.4. Multiple issues in Vim.

CVE-2020-3850CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

CVE-2020-3847CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to leak memory.

CVE-2020-3848CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

CVE-2020-3849CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

CVE-2019-9163CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbitrary code via crafted XAML objects.

CVE-2020-10948CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution via eval injection, a different issue than CVE-2002-0934. An unauthenticated, remote attacker can exploit this via a series of crafted requests.

CVE-2019-17564CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.

CVE-2020-6009CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

LearnDash Wordpress plugin version below 3.1.6 is vulnerable to Unauthenticated SQL Injection.

CVE-2020-6852CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root privileges without any password required.

CVE-2020-7617CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

ini-parser through 0.0.2 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of Object.prototype using a '__proto__' payload.

CVE-2020-7623CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument.

CVE-2020-7619CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-git-data.

CVE-2020-7620CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.

CVE-2020-7621CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function.

CVE-2020-10515CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-427

STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006.

CVE-2020-7624CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.

CVE-2020-7625CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.

CVE-2020-7626CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.

← PreviousPage 347 / 7034Next →