CVE Database

CVE-2020-7627CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function.

CVE-2020-7628CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.

CVE-2020-7629CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.

CVE-2020-7630CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.

CVE-2020-10599CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited resulting in a buffer overflow, which may lead to a denial-of-service condition and execution of arbitrary code.

CVE-2020-6994CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-12

A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.

CVE-2020-8637CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.

CVE-2020-8638CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter.

CVE-2020-8147CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-471

Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using utils-extend.

CVE-2020-11518CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.

CVE-2020-11542CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

3xLOGIC Infinias eIDC32 2.213 devices with Web 1.107 allow Authentication Bypass via CMD.HTM?CMD= because authentication depends on the client side's interpretation of the <KEY>MYKEY</KEY> substring.

CVE-2020-11548CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1236

The Search Meter plugin through 2.13.2 for WordPress allows user input introduced in the search bar to be any formula. The attacker could achieve remote code execution via CSV injection if a wp-admin/index.php?page=search-meter Export is performed.

CVE-2020-11558CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. audio_sample_entry_Read in isomedia/box_code_base.c does not properly decide when to make gf_isom_box_del calls. This leads to various use-after-free outcomes involving mdia_Read, gf_isom_delete_movie, and gf_isom_parse_movie_boxes.

CVE-2020-7636CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command function.

CVE-2020-7631CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.

CVE-2020-7632CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.

CVE-2020-7633CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.

CVE-2020-7634CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

heroku-addonpool through 0.1.15 is vulnerable to Command Injection.

CVE-2020-7635CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.

CVE-2020-7622CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

This affects the package io.jooby:jooby-netty before 1.6.9, from 2.0.0 and before 2.2.1. The DefaultHttpHeaders is set to false which means it does not validates that the header isn't being abused for HTTP Response Splitting.

CVE-2020-11545CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Project Worlds Official Car Rental System 1 is vulnerable to multiple SQL injection issues, as demonstrated by the email and parameters (account.php), uname and pass parameters (login.php), and id parameter (book_car.php) This allows an attacker to dump the MySQL database and to bypass the login authentication prompt.

CVE-2020-11597CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request and inject SQL statements in the user context of the db owner.

CVE-2020-11598CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and executing an ASHX file.

CVE-2020-11586CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XML DTD data.

CVE-2016-11025CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered on Samsung mobile devices with software through 2016-09-13 (Exynos AP chipsets). There is a memcpy heap-based buffer overflow in the OTP service. The Samsung ID is SVE-2016-7114 (December 2016).

CVE-2016-11028CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered on Samsung mobile devices with software through 2016-09-13 (Exynos AP chipsets). There is a stack-based buffer overflow in the OTP TrustZone trustlet. The Samsung IDs are SVE-2016-7173 and SVE-2016-7174 (December 2016).

CVE-2016-11033CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered on Samsung mobile devices with M(6.0) software. There is a heap-based buffer overflow in tlc_server. The Samsung IDs are SVE-2016-7220 and SVE-2016-7225 (November 2016).

CVE-2016-11036CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

An issue was discovered on Samsung mobile devices with M(6.0) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-6008 (August 2016).

CVE-2016-11038CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

An issue was discovered on Samsung mobile devices with software through 2016-04-05 (incorporating the Samsung Professional Audio SDK). The Jack audio service doesn't implement access control for shared memory, leading to arbitrary code execution or privilege escalation. The Samsung ID is SVE-2016-5953 (July 2016).

CVE-2017-18693CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. There is a buffer overflow in the fps sysfs entry. The Samsung ID is SVE-2016-7510 (January 2017).

CVE-2017-18696CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos7420, Exynos8890, or MSM8996 chipsets) software. RKP allows memory corruption. The Samsung ID is SVE-2016-7897 (January 2017).

CVE-2020-7614CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated together without any validation and are used by the 'exec' function directly.

CVE-2017-18652CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. SVoice allows arbitrary code execution by changing dynamic libraries. The Samsung ID is SVE-2017-9299 (September 2017).

CVE-2017-18655CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a stack-based buffer overflow with resultant memory corruption in a trustlet. The Samsung IDs are SVE-2017-8889, SVE-2017-8891, and SVE-2017-8892 (August 2017).

CVE-2017-18660CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a buffer overflow in tlc_server. The Samsung ID is SVE-2017-8888 (July 2017).

CVE-2017-18661CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.x) software. There is a buffer overflow in process_cipher_tdea. The Samsung ID is SVE-2017-8973 (July 2017).

CVE-2017-18681CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

An issue was discovered on Samsung Galaxy S5 mobile devices with software through 2016-12-20 (Qualcomm AP chipsets). There are multiple buffer overflows in the bootloader. The Samsung ID is SVE-2016-7930 (March 2017).

CVE-2017-18683CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. SVoice allows Hare Hunting during application installation. The Samsung ID is SVE-2016-6942 (February 2017).

CVE-2017-18684CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. SVoice allows provider seizure via an application that uses a custom provider. The Samsung ID is SVE-2016-6942 (February 2017).

CVE-2017-18690CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) (Exynos54xx, Exynos7420, Exynos8890, or Exynos8895 chipsets) software. There is a buffer overflow in the sensor hub. The Samsung ID is SVE-2016-7484 (January 2017).

CVE-2017-18691CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos8890 chipsets) software. There are multiple Buffer Overflows in TSP sysfs cmd_store. The Samsung ID is SVE-2016-7500 (January 2017).

CVE-2019-4393CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

HCL AppScan Standard is vulnerable to excessive authorization attempts

CVE-2020-11514CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

The Rank Math plugin through 1.0.40.2 for WordPress allows unauthenticated remote attackers to update arbitrary WordPress metadata, including the ability to escalate or revoke administrative privileges for existing users via the unsecured rankmath/v1/updateMeta REST API endpoint.

CVE-2020-6974CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Honeywell Notifier Web Server (NWS) Version 3.50 is vulnerable to a path traversal attack, which allows an attacker to bypass access to restricted directories. Honeywell has released a firmware update to address the problem.

CVE-2020-11543CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

OpsRamp Gateway before 7.0.0 has a backdoor account vadmin with the password 9vt@f3Vt that allows root SSH access to the server. This issue has been resolved in OpsRamp Gateway firmware version 7.0.0 where an administrator and a system user accounts are the only available user accounts for the gateway appliance.

CVE-2020-11630CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of serialized objects sent between nodes (connected via the Peers protocol) allows insecure objects to be deserialized.

CVE-2017-18644CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered on Samsung mobile devices with L(5.1), M(6.x), and N(7.x) software. There is a muic_set_reg_sel heap-based buffer overflow during the reading of MUIC register values. The Samsung ID is SVE-2017-10011 (December 2017).

CVE-2017-18645CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) (Qualcomm chipsets) software. There is a panel_lpm sysfs stack-based buffer overflow. The Samsung ID is SVE-2017-9414 (December 2017).

CVE-2018-21089CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

An issue was discovered on Samsung mobile devices with N(7.x) (MT6755/MT6757 Mediatek models) software. Bootloader has an integer overflow that leads to arbitrary code execution via the download offset control. The Samsung ID is SVE-2017-10732 (January 2018).

CVE-2018-21090CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

An issue was discovered on Samsung mobile devices with software through 2017-11-03 (S.LSI modem chipsets). The Exynos modem chipset has a baseband buffer overflow. The Samsung ID is SVE-2017-10745 (January 2018).

← PreviousPage 348 / 7034Next →