CVE Database

CVE-2020-9632CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

CVE-2019-3681CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-73

A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Software Development Kit 12-SP5, SUSE Linux Enterprise Software Development Kit 12-SP4; openSUSE Leap 15.1, openSUSE Factory allowed remote attackers that can change downloaded packages to overwrite arbitrary files. This issue affects: SUSE Linux Enterprise Module for Development Tools 15 osc versions prior to 0.169.1-3.20.1. SUSE Linux Enterprise Software Development Kit 12-SP5 osc versions prior to 0.162.1-15.9.1. SUSE Linux Enterprise Software Development Kit 12-SP4 osc versions prior to 0.162.1-15.9.1. openSUSE Leap 15.1 osc versions prior to 0.169.1-lp151.2.15.1. openSUSE Factory osc versions prior to 0.169.0 .

CVE-2020-12016CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-259

Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5, Baxter ExactaMix EM 2400 Versions 1.10, 1.11, 1.13, 1.14 and ExactaMix EM1200 Versions 1.1, 1.2, 1.4 and 1.5 have hard-coded administrative account credentials for the ExactaMix operating system. Successful exploitation of this vulnerability may allow an attacker who has gained unauthorized access to system resources, including access to execute software or to view/update files, directories, or system configuration. This could allow an attacker with network access to view sensitive data including PHI.

CVE-2020-12040CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-319

Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the application layer uses an unauthenticated clear-text communication channel to send and receive system status and operational data. This could allow an attacker that has circumvented network security measures to view sensitive non-private data or to perform a man-in-the-middle attack.

CVE-2020-15322CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.

CVE-2020-12043CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-672

The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the WBM remains operational until the WBM is rebooted.

CVE-2020-12045CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-259

The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), operates a Telnet service on Port 1023 with hard-coded credentials.

CVE-2020-12047CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-259

The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-default wireless configuration enables an FTP service with hard-coded credentials.

CVE-2020-15323CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials.

CVE-2020-15320CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account.

CVE-2020-15321CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.

CVE-2020-15324CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials.

CVE-2020-14068CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An issue was discovered in MK-AUTH 19.01. The web login functionality allows an attacker to bypass authentication and gain client privileges via SQL injection in central/executar_login.php.

CVE-2020-14070CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

An issue was discovered in MK-AUTH 19.01. There is authentication bypass in the web login functionality because guessable credentials to admin/executar_login.php result in admin access.

CVE-2020-14072CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was discovered in MK-AUTH 19.01. It allows command execution as root via shell metacharacters to /auth admin scripts.

CVE-2020-15362CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

wifiscanner.js in thingsSDK WiFi Scanner 1.0.1 allows Code Injection because it can be used with options to overwrite the default executable/binary path and its arguments. An attacker can abuse this functionality to execute arbitrary code.

CVE-2018-6446CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

A vulnerability in Brocade Network Advisor Version Before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications.

CVE-2020-15069KEVCRITICALin_the_wild
CVSS 9.8
EPSS 82.58%
Priority 70

Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.

CVE-2020-15543CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.

CVE-2017-18922CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

CVE-2019-20893CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

An issue was discovered in Activision Infinity Ward Call of Duty Modern Warfare 2 through 2019-12-11. PartyHost_HandleJoinPartyRequest has a buffer overflow vulnerability and can be exploited by using a crafted joinParty packet. This can be utilized to conduct arbitrary code execution on a victim's machine.

CVE-2020-15411CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the attachment downloader.

CVE-2020-15415KEVCRITICALin_the_wild
CVSS 9.8
EPSS 93.00%
Priority 70

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.

CVE-2020-15540CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

We-com OpenData CMS 2.0 allows SQL Injection via the username field on the administrator login page.

CVE-2020-15474CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.

CVE-2020-15475CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.

CVE-2020-15489CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges.

CVE-2020-13380CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

openSIS before 7.4 allows SQL Injection.

CVE-2020-13381CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

openSIS through 7.4 allows SQL Injection.

CVE-2020-15490CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple buffer overflow vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges. (The set of affected scripts is similar to CVE-2020-12266.)

CVE-2020-13619CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.

CVE-2020-14056CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-918

Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with arbitrary third-party services.

CVE-2020-14057CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-610

Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments.

CVE-2020-15541CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.

CVE-2019-15310CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Linkplay's AWS estate, including S3 buckets containing device firmware. When combined with an OS command injection vulnerability within the XML Parsing logic of the firmware update process, an attacker would be able to gain code execution on any device that attempted to update. Note that by default all devices tested had automatic updates enabled.

CVE-2019-15311CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is Zolo Halo LAN remote code execution. The Zolo Halo Bluetooth speaker had a GoAhead web server listening on the port 80. The /httpapi.asp endpoint of the GoAhead web server was also vulnerable to multiple command execution vulnerabilities.

CVE-2020-3297CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

A vulnerability in session management for the web-based interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to defeat authentication protections and gain unauthorized access to the management interface. The attacker could obtain the privileges of the highjacked session account, which could include administrator privileges on the device. The vulnerability is due to the use of weak entropy generation for session identifier values. An attacker could exploit this vulnerability to determine a current session identifier through brute force and reuse that session identifier to take over an ongoing session. In this way, an attacker could take actions within the management interface with privileges up to the level of the administrative user.

CVE-2020-7820CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by setting the arguments to the vulnerable API. This can be leveraged for code execution by rebooting the victim’s PC

CVE-2020-7821CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Nexacro14/17 ExtCommonApiV13 Library under 2019.9.6 version contain a vulnerability that could allow remote attacker to execute arbitrary code by modifying the value of registry path. This can be leveraged for code execution by rebooting the victim’s PC

CVE-2020-15542CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.

CVE-2020-14092CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.

CVE-2020-4074CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and execute admin commands. The problem is fixed in 1.7.6.6.

CVE-2020-14172CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atlassian Jira Server and Data Center in affected versions allowed remote attackers to achieve remote code execution via insecure deserialization, if they were able to exploit a server side template injection vulnerability. The affected versions are before version 7.13.0, from version 8.0.0 before 8.5.0, and from version 8.6.0 before version 8.8.1.

CVE-2020-10282CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization) whichs leads to a variety of attacks including identity spoofing, unauthorized access, PITM attacks and more. According to literature, version 2.0 optionally allows for package signing which mitigates this flaw. Another source mentions that MAVLink 2.0 only provides a simple authentication system based on HMAC. This implies that the flying system overall should add the same symmetric key into all devices of network. If not the case, this may cause a security issue, that if one of the devices and its symmetric key are compromised, the whole authentication system is not reliable.

CVE-2020-15539CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection can occur in We-com Municipality portal CMS 2.1.x via the cerca/ keywords field.

CVE-2020-15505KEVCRITICALin_the_wild
CVSS 9.8
EPSS 94.35%
Priority 70

A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and Reporting Database (RDB) version 2.0.0.1 and earlier that allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2020-15506CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An authentication bypass vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote attackers to bypass authentication mechanisms via unspecified vectors.

CVE-2020-5595CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a buffer overflow vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.

CVE-2020-5599CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-88

TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.

CVE-2020-15367CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.

← PreviousPage 358 / 7034Next →