CVE Database

CVE-2020-4043CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

phpMussel from versions 1.0.0 and less than 1.6.0 has an unserialization vulnerability in PHP's phar wrapper. Uploading a specially crafted file to an affected version allows arbitrary code execution (discovered, tested, and confirmed by myself), so the risk factor should be regarded as very high. Newer phpMussel versions don't use PHP's phar wrapper, and are therefore unaffected. This has been fixed in version 1.6.0.

CVE-2020-13901CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-based buffer overflow.

CVE-2020-13854CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

Artica Pandora FMS 7.44 allows privilege escalation.

CVE-2020-4101CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

"HCL Digital Experience is susceptible to Server Side Request Forgery."

CVE-2020-0138CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In get_element_attr_rsp of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if bluetoothtbd were used, which it isn't in typical Android platforms, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142878416

CVE-2020-0201CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

In showSecurityFields of WifiConfigController.java there is a possible credential leak due to a confused deputy. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143601727

CVE-2020-0217CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In RW_T4tPresenceCheck of rw_t4t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141331405

CVE-2020-3928CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

GeoVision Door Access Control device family is hardcoded with a root password, which adopting an identical password in all devices.

CVE-2020-9633CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Adobe Flash Player Desktop Runtime 32.0.0.371 and earlier, Adobe Flash Player for Google Chrome 32.0.0.371 and earlier, and Adobe Flash Player for Microsoft Edge and Internet Explorer 32.0.0.330 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2020-13656CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remote code (via RPC) execution.

CVE-2020-14067CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

The install_from_hash functionality in Navigate CMS 2.9 does not consider the .phtml extension when examining files within a ZIP archive that may contain PHP code, in check_upload in lib/packages/extensions/extension.class.php and lib/packages/themes/theme.class.php.

CVE-2020-0235CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size parameter for "copy_from_user", ending up overwriting memory following "crus_sp_hdr". "crus_sp_hdr" is a static variable, of type "struct crus_sp_ioctl_header".Product: AndroidVersions: Android kernelAndroid ID: A-135129430

CVE-2020-14080CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an unauthenticated user to execute arbitrary code by POSTing to apply_sec.cgi via the action ping_test with a sufficiently long ping_ipaddr key.

CVE-2020-26105CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).

CVE-2020-0594CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2020-0595CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2020-4216CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 175066.

CVE-2020-12019CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

WebAccess Node Version 8.4.4 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

CVE-2020-4469CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. This vulnerability is due to an incomplete fix for CVE-2020-4211. IBM X-Force ID: 181724.

CVE-2020-14054CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SOKKIA GNR5 Vanguard WEB version 1.2 (build: 91f2b2c3a04d203d79862f87e2440cb7cefc3cd3) and hardware version 212 allows remote attackers to bypass admin authentication via a SQL injection attack that uses the User Name or Password field on the login page.

CVE-2018-21246CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.

CVE-2020-14033CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_streaming_rtsp_parse_sdp in plugins/janus_streaming.c has a Buffer Overflow via a crafted RTSP server.

CVE-2020-14034CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in an SDP Offer packet.

CVE-2020-11969CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication. This affects Apache TomEE 8.0.0-M1 - 8.0.1, Apache TomEE 7.1.0 - 7.1.2, Apache TomEE 7.0.0-M1 - 7.0.7, Apache TomEE 1.0.0 - 1.7.5.

CVE-2020-12001CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000 Launcher: Version 31 and later Stud, 5000 Logix Designer software: Version 32 and prior is vulnerable. The parsing mechanism that processes certain file types does not provide input sanitation. This may allow an attacker to use specially crafted files to traverse the file system and modify or expose sensitive data or execute arbitrary code.

CVE-2020-0223CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

This is an unbounded write into kernel global memory, via a user-controlled buffer size.Product: AndroidVersions: Android kernelAndroid ID: A-135130450

CVE-2020-0232CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

Function abc_pcie_issue_dma_xfer_sync creates a transfer object, adds it to the session object then continues to work with it. A concurrent thread could retrieve created transfer object from the session object and delete it using abc_pcie_dma_user_xfer_clean. If this happens, abc_pcie_start_dma_xfer and abc_pcie_wait_dma_xfer in the original thread will trigger UAF when working with the transfer object.Product: AndroidVersions: Android kernelAndroid ID: A-151453714

CVE-2020-9296CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-917

Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are supported, including Java EL expressions. If an attacker can inject arbitrary data in the error message template being passed to ConstraintValidatorContext.buildConstraintViolationWithTemplate() argument, they will be able to run arbitrary Java code.

CVE-2020-7497CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause arbitrary application execution when the computer starts.

CVE-2020-7498CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions). The fixed credentials are used to simplify file transfer. Today the use of fixed credentials is considered a vulnerability, which could cause unauthorized access to the file transfer service provided by the Modicon PLCs. This could result in various unintended results.

CVE-2020-7500CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause arbitrary code to be executed when a malicious command is entered.

CVE-2020-7508CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to gain full access by brute force.

CVE-2020-7512CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1103

A CWE-1103: Use of Platform-Dependent Third Party Components with vulnerabilities vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to exploit the component.

CVE-2020-13640CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments request. (No 7.x versions are affected.)

CVE-2020-3361CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to gain unauthorized access to a vulnerable Webex site. The vulnerability is due to improper handling of authentication tokens by a vulnerable Webex site. An attacker could exploit this vulnerability by sending crafted requests to a vulnerable Cisco Webex Meetings or Cisco Webex Meetings Server site. If successful, the attacker could gain the privileges of another user within the affected Webex site.

CVE-2020-11503CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.

CVE-2017-9109CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first RR that was found the first time. when this is fixed, the second answer scan finds the same RRs at the first. Otherwise, adns can be confused by interleaving answers for the CNAME target, with the CNAME itself. In that case the answer data structure (on the heap) can be overrun. With this fixed, it prefers to look only at the answer RRs which come after the CNAME, which is at least arguably correct.

CVE-2017-9103CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__findlabel_next. Without this, an uninitialised stack value can be used as the first label length. Depending on the circumstances, an attacker might be able to trick adns into crashing the calling program, leaking aspects of the contents of some of its memory, causing it to allocate lots of memory, or perhaps overrunning a buffer. This is only possible with applications which make non-raw queries for SOA or RP records.

CVE-2017-9104CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-400

An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered.

CVE-2020-7679CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

In all versions of package casperjs, the mergeObjects utility function is susceptible to Prototype Pollution.

CVE-2019-20853CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-668

An issue was discovered in Mattermost Packages before 5.16.3. A Droplet could allow Internet access to a service that has a remote code execution problem.

CVE-2019-20856CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-427

An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.

CVE-2018-21251CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

An issue was discovered in Mattermost Server before 5.2 and 5.1.1. Authorization could be bypassed if the channel name were not the same in the params and the body.

CVE-2020-8165CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.

CVE-2017-18885CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows attackers to gain privileges by accessing unintended API endpoints on a user's behalf.

CVE-2017-18888CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows SQL injection during the fetching of multiple posts.

CVE-2017-18900CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

An issue was discovered in Mattermost Server before 4.1.0, 4.0.4, and 3.10.3. It allows CSV injection via a compliance report.

CVE-2016-11064CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.

CVE-2020-3628CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Improper access due to socket opened by the logging application without specifying localhost address in Snapdragon Consumer IOT, Snapdragon Mobile in APQ8053, Rennell, SDX20

CVE-2020-14931CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) 1.3a might allow remote WHOIS servers to execute arbitrary code via a long line in a response that is mishandled by nic_format_buff.

← PreviousPage 356 / 7034Next →