CVE Database

CVE-2020-10283CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-288

The Micro Air Vehicle Link (MAVLink) protocol presents authentication mechanisms on its version 2.0 however according to its documentation, in order to maintain backwards compatibility, GCS and autopilot negotiate the version via the AUTOPILOT_VERSION message. Since this negotiation depends on the answer, an attacker may craft packages in a way that hints the autopilot to adopt version 1.0 of MAVLink for the communication. Given the lack of authentication capabilities in such version of MAVLink (refer to CVE-2020-10282), attackers may use this method to bypass authentication capabilities and interact with the autopilot directly.

CVE-2020-23936CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".

CVE-2020-16279CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplied input being passed to the command line without sanitization.

CVE-2020-7710CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host machine.

CVE-2020-24051CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol, which requires authentication for some of its operations. It was found that the authentication check for those ONVIF operations can be bypassed. An attacker can abuse this issue to execute privileged operations without authentication, for instance, to create a new Administrator user.

CVE-2020-24054CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that can spawn a given process repeatedly at a certain time interval as 'root'. One of the limitations of this feature is that it only takes a path to a binary without arguments; however, this can be circumvented using special shell variables, such as '${IFS}'. As a result, an attacker can execute arbitrary commands as 'root' on the units.

CVE-2020-24055CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service implemented in the binary executable '/usr/sbin/DM' that listens on port TCP 6666. The service is vulnerable to a stack buffer overflow. It is worth noting that this service does not require any authentication.

CVE-2019-11855CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An RPC server is enabled by default on the gateway's LAN of ALEOS before 4.12.0, 4.9.5, and 4.4.9.

CVE-2020-8234CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-613

A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be guessed, enabling the attacker to obtain high privileges and get a root shell by a Command injection.

CVE-2020-25049CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. StatusBarService has insufficient DEX access control. The Samsung ID is SVE-2020-17797 (August 2020).

CVE-2020-6637CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.

CVE-2020-7376CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-23

The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write arbitrary files to arbitrary locations on the host filesystem when the module is run on a malicious host.

CVE-2020-14510CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-193

GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unprivileged attacker to execute commands as root.

CVE-2020-14500CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-158

Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data.

CVE-2020-14508CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-193

GateManager versions prior to 9.2c, The affected product is vulnerable to an off-by-one error, which may allow an attacker to remotely execute arbitrary code or cause a denial-of-service condition.

CVE-2020-14524CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

CVE-2020-16245CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.

CVE-2020-15639CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is not required to exploit this vulnerability. The specific flaw exists within the decryptFile method of the FlashValidatorServiceImpl class. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10496.

CVE-2020-24653CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

secure-store in Expo through 2.16.1 on iOS provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN_UNLOCKED_THIS_DEVICE_ONLY is used.

CVE-2019-18847CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-295

Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.

CVE-2020-24007CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.

CVE-2020-3446CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

A vulnerability in Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Software (NFVIS)-bundled images for Cisco ENCS 5400-W Series and CSP 5000-W Series appliances could allow an unauthenticated, remote attacker to log into the NFVIS CLI of an affected device by using accounts that have a default, static password. The vulnerability exists because the affected software has user accounts with default, static passwords. An attacker with access to the NFVIS CLI of an affected device could exploit this vulnerability by logging into the CLI. A successful exploit could allow the attacker to access the NFVIS CLI with administrator privileges.

CVE-2020-25061CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered on LG mobile devices with Android OS 9 and 10 software on the VZW network. lge_property allows property overwrites. The LG ID is LVE-SMP-200016 (July 2020).

CVE-2020-15158CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

In libIEC61850 before version 1.4.3, when a message with COTP message length field with value < 4 is received an integer underflow will happen leading to heap buffer overflow. This can cause an application crash or on some platforms even the execution of remote code. If your application is used in open networks or there are untrusted nodes in the network it is highly recommend to apply the patch. This was patched with commit 033ab5b. Users of version 1.4.x should upgrade to version 1.4.3 when available. As a workaround changes of commit 033ab5b can be applied to older versions.

CVE-2019-4694CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171832.

CVE-2020-23980CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.

CVE-2020-23973CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.

CVE-2020-23976CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.

CVE-2020-23978CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"

CVE-2020-23979CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter.

CVE-2020-7715CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.

CVE-2020-5624CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in the XooNIps 3.48 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2020-24202CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote attackers to conduct code execution.

CVE-2020-24203CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-425

Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.0 allows remote unauthenticated attackers to gain remote code execution.

CVE-2020-24714CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-295

The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, the openssl binary is called without the -verify_hostname option.

CVE-2020-24715CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-295

The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, native Python code is used that lacks a comparison of the hostname to commonName and subjectAltName.

CVE-2020-7716CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

All versions of package deeps are vulnerable to Prototype Pollution via the set function.

CVE-2020-25020CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.

CVE-2020-24115CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.

CVE-2020-12645CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-307

OX App Suite 7.10.1 to 7.10.3 has improper input validation for rate limits with a crafted User-Agent header, spoofed vacation notices, and /apps/load memory consumption.

CVE-2020-24786CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer before build number 12136, ADAudit Plus before build number 6052, O365 Manager Plus before build number 4334, Cloud Security Plus before build number 4110, ADManager Plus before build number 7055, and Log360 before build number 5166. The remotely accessible Java servlet com.manageengine.ads.fw.servlet.UpdateProductDetails is prone to an authentication bypass. System integration properties can be modified and lead to full ManageEngine suite compromise.

CVE-2020-7521CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `FileUploadServlet` which may lead to uploading executable files to non-specified directories.

CVE-2020-7522CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method of `SoundUploadServlet` which may lead to uploading executable files to non-specified directories.

CVE-2020-7717CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.

CVE-2020-25052CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. H-Arx allows attackers to execute arbitrary code or cause a denial of service (memory corruption) because indexes are mishandled. The Samsung ID is SVE-2020-17426 (August 2020).

CVE-2020-25053CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. RKP allows arbitrary code execution. The Samsung ID is SVE-2020-17435 (August 2020).

CVE-2020-25055CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-863

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows attackers (who control an unprivileged SecureFolder process) to bypass admin restrictions in KnoxContainer. The Samsung ID is SVE-2020-18133 (August 2020).

CVE-2020-25057CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered on LG mobile devices with Android OS 10 software. MDMService does not properly restrict APK installations. The LG ID is LVE-SMP-200011 (July 2020).

CVE-2020-25058CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. The network_management service does not properly restrict configuration changes. The LG ID is LVE-SMP-200012 (July 2020).

CVE-2020-7718CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.

← PreviousPage 363 / 7034Next →