CVE Database

CVE-2020-3318CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to access a sensitive part of an affected system with a high-privileged account. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2020-8899CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q(10.0). An unauthenticated, unauthorized attacker sending a specially crafted MMS to a vulnerable phone can trigger a heap-based buffer overflow in the Quram image codec leading to an arbitrary remote code execution (RCE) without any user interaction. The Samsung ID is SVE-2020-16747.

CVE-2019-18868CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-312

Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.bak, or /lang/en.bak.

CVE-2020-7805CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This issue is a command injection allowing attackers to execute arbitrary OS commands.

CVE-2020-4427KEVCRITICALin_the_wild
CVSS 9.8
EPSS 90.34%
Priority 70

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.

CVE-2020-4429KEVCRITICALin_the_wild
CVSS 9.8
EPSS 90.70%
Priority 0

IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrative account. A remote attacker could exploit this vulnerability to login and execute arbitrary code on the system with root privileges. IBM X-Force ID: 180534.

CVE-2020-10176CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands.

CVE-2020-10794CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to unauthenticated path traversal that allows an attacker to download the application database. This can be combined with CVE-2020-10795 for remote root access.

CVE-2020-11052CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

In Sorcery before 0.15.0, there is a brute force vulnerability when using password authentication via Sorcery. The brute force protection submodule will prevent a brute force attack for the defined lockout period, but once expired, protection will not be re-enabled until a user or malicious actor logs in successfully. This does not affect users that do not use the built-in brute force protection submodule, nor users that use permanent account lockout. This has been patched in 0.15.0.

CVE-2020-12720CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.

CVE-2020-12735CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-331

reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.

CVE-2020-10638CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple heap-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.

CVE-2020-12002CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple stack-based buffer overflow vulnerabilities exist caused by a lack of proper validation of the length of user-supplied data, which may allow remote code execution.

CVE-2020-12006CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-23

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to overwrite files outside the application’s control.

CVE-2020-12022CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-129

Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An improper validation vulnerability exists that could allow an attacker to inject specially crafted input into memory where it can be executed.

CVE-2020-11532CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1188

Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user.

CVE-2020-12637CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-295

Zulip Desktop before 5.2.0 has Missing SSL Certificate Validation because all validation was inadvertently disabled during an attempt to recognize the ignoreCerts option.

CVE-2020-12766CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Gnuteca 3.8 allows action=main:search:simpleSearch SQL Injection via the exemplaryStatusId parameter.

CVE-2020-12743CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-552

An issue was discovered in Gazie 7.32. A successful installation does not remove or block (or in any other way prevent use of) its own file /setup/install/setup.php, meaning that anyone can request it without authentication. This file allows arbitrary PHP file inclusion via a hidden_req POST parameter.

CVE-2020-12746CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered on Samsung mobile devices with O(8.X), P(9.0), and Q(10.0) (Exynos chipsets) software. Attackers can bypass the Secure Bootloader protection mechanism via a heap-based buffer overflow to execute arbitrary code. The Samsung ID is SVE-2020-16712 (May 2020).

CVE-2020-12747CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos980 9630 and Exynos990 9830 chipsets) software. The Bootloader has a heap-based buffer overflow because of the mishandling of specific commands. The Samsung IDs are SVE-2020-16981, SVE-2020-16991 (May 2020).

CVE-2020-12753CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Arbitrary code execution can occur via the bootloader because of an EL1/EL3 coldboot vulnerability involving raw_resources. The LG ID is LVE-SMP-200006 (May 2020).

CVE-2018-1285CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.

CVE-2020-10022CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A malformed JSON payload that is received from an UpdateHub server may trigger memory corruption in the Zephyr OS. This could result in a denial of service in the best case, or code execution in the worst case. See NCC-NCC-016 This issue affects: zephyrproject-rtos zephyr version 2.1.0 and later versions. version 2.2.0 and later versions.

CVE-2020-8159CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.

CVE-2020-1939CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-476

The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs. One of these, ftpd, had a NULL pointer dereference bug. The NuttX RTOS itself is not affected. Users of the optional apps repository are affected only if they have enabled ftpd. Versions 6.15 to 8.2 are affected.

CVE-2020-12823CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.

CVE-2020-6242CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an attacker to logon on the Central Management Console without password in case of the BIPRWS application server was not protected with some specific certificate, leading to Missing Authentication Check.

CVE-2020-10654CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers. This condition can be potentially exploited into a Remote Code Execution vector on the authenticating endpoint.

CVE-2020-12763CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TRENDnet ProView Wireless camera TV-IP512WN 1.0R 1.0.4 is vulnerable to an unauthenticated stack-based buffer overflow in handling RTSP packets. This may result in remote code execution or denial of service. The issue is in the binary rtspd (in /sbin) when parsing a long "Authorization: Basic" RTSP header.

CVE-2019-15880CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocated the size of a kernel buffer based on a user-supplied length allowing an unprivileged process to trigger a kernel panic.

CVE-2020-7454CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

In FreeBSD 12.1-STABLE before r360971, 12.1-RELEASE before p5, 11.4-STABLE before r360971, 11.4-BETA1 before p1 and 11.3-RELEASE before p9, libalias does not properly validate packet length resulting in modules causing an out of bounds read/write condition if no checking was built into the module.

CVE-2020-9502CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-330

Some Dahua products with Build time before December 2019 have Session ID predictable vulnerabilities. During normal user access, an attacker can use the predicted Session ID to construct a data packet to attack the device.

CVE-2020-12832CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.

CVE-2020-2001CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-123

An external control of path and data vulnerability in the Palo Alto Networks PAN-OS Panorama XSLT processing logic that allows an unauthenticated user with network access to PAN-OS management interface to write attacker supplied file on the system and elevate privileges. This issue affects: All PAN-OS 7.1 Panorama and 8.0 Panorama versions; PAN-OS 8.1 versions earlier than 8.1.12 on Panorama; PAN-OS 9.0 versions earlier than 9.0.6 on Panorama.

CVE-2019-13022CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-327

Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorithm (used to set initial passwords upon first installation). It XORs the plaintext into the 'encrypted' password that is then stored within the database. These steps are able to be trivially reversed, allowing for escalation of privilege within the JetSelect application through obtaining the passwords of JetSelect administrators. JetSelect administrators have the ability to modify and delete all networking configuration across a vessel, as well as altering network configuration of all managed network devices (switches, routers).

CVE-2019-17562CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack of validation of the mac parameter in baremetal virtual router. If you insert an arbitrary shell command into the mac parameter, v-router will process the command. For example: Normal: http://{GW}:10086/baremetal/provisiondone/{mac}, Abnormal: http://{GW}:10086/baremetal/provisiondone/#';whoami;#. Mitigation of this issue is an upgrade to Apache CloudStack 4.13.1.0 or beyond.

CVE-2020-11972CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

CVE-2020-11973CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.

CVE-2020-12874CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Veritas APTARE versions prior to 10.4 included code that bypassed the normal login process when specific authentication credentials were provided to the server.

CVE-2020-0103CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-763

In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-9Android ID: A-148107188

CVE-2020-10620CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-285

Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for example, stopping the service remotely.

CVE-2020-0221CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-682

Airbrush FW's scratch memory allocator is susceptible to numeric overflow. When the overflow occurs, the next allocation could potentially return a pointer within the previous allocation's memory, which could lead to improper memory access.Product: AndroidVersions: Android kernelAndroid ID: A-135772851

CVE-2020-12834CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-276

eQ-3 Homematic Central Control Unit (CCU)2 through 2.51.6 and CCU3 through 3.51.6 allow Remote Code Execution in the JSON API Method ReGa.runScript, by unauthenticated attackers with access to the web interface, due to the default auto-login feature being enabled during first-time setup (or factory reset).

CVE-2019-18666CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without authorization via an undocumented HTTP request. Although this is the primary vulnerability, the impact depends on the firmware version. Versions 609EU through 613EUbeta were tested. Versions through 6.12b01 have weak root credentials, allowing an attacker to gain remote root access. After 6.12b01, the root credentials were changed but the telnet service can still be started without authorization.

CVE-2020-12651CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-190

SecureCRT before 8.7.2 allows remote attackers to execute arbitrary code via an Integer Overflow and a Buffer Overflow because a banner can trigger a line number to CSI functions that exceeds INT_MAX.

CVE-2020-12889CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

MISP MISP-maltego 1.4.4 incorrectly shares a MISP connection across users in a remote-transform use case.

CVE-2020-13091CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the read_pickle() function is documented as unsafe and it is the user's responsibility to use the function in a secure manner

CVE-2020-13092CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the joblib.load() function is documented as unsafe and it is the user's responsibility to use the function in a secure manner

CVE-2020-8149CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before version 0.7.1.

← PreviousPage 353 / 7034Next →