CVE Database

CVE-2020-29376CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. There is an !j@l#y$z%x6x7q8c9z) password for the admin account to authenticate to the TELNET service.

CVE-2020-29377CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

An issue was discovered on V-SOL V1600D V2.03.69 OLT devices. The string K0LTdi@gnos312$ is compared to the password provided by the the remote attacker. If it matches, access is provided.

CVE-2020-29381CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. Command injection can occur in "upload tftp syslog" and "upload tftp configuration" in the CLI via a crafted filename.

CVE-2020-29127CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web browser), the portal can be accessed with root privileges when the URI cgi-bin/csp?cspid={XXXXXXXXXX}&csppage=cgi_PgOverview&csplang=en is visited from a different web browser.

CVE-2020-27660CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter.

CVE-2020-25537CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.

CVE-2020-28926CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer overflow in calls to memcpy/memmove.

CVE-2020-29390KEVCRITICALin_the_wild
CVSS 9.8
EPSS 90.59%
Priority 0

Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.

CVE-2020-26762CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A stack-based buffer-overflow exists in Edimax IP-Camera IC-3116W (v3.06) and IC-3140W (v3.07), which allows an unauthenticated, unauthorized attacker to perform remote-code-execution due to a crafted GET-Request. The overflow occurs in binary ipcam_cgi due to a missing type check in function doGetSysteminfo(). This has been fixed in version: IC-3116W v3.08.

CVE-2020-7533CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

CWE-287: Improper Authentication vulnerability exists which could cause the execution of commands on the webserver without authentication when sending specially crafted HTTP requests.

CVE-2020-7548CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-330

A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorized users to login.

CVE-2020-28940CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unauthenticated user to execute privileged commands on the device.

CVE-2020-28970CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie. (In addition, an upload endpoint could then be used by an authenticated administrator to upload executable PHP scripts.)

CVE-2020-28971CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.

CVE-2020-6880CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

A ZXELINK wireless controller has a SQL injection vulnerability. A remote attacker does not need to log in. By sending malicious SQL statements, because the device does not properly filter parameters, successful use can obtain management rights. This affects: ZXV10 W908 all versions before MIPS_A_1022IPV6R3T6P7Y20.

CVE-2020-14260CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Domino or execute attacker-controlled code on the server system.

CVE-2020-6018CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decrypt() when compiled using libsodium, leading to a Stack-Based Buffer Overflow and resulting in a memory corruption and possibly even a remote code execution.

CVE-2020-7199CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gaining privileged access, causing denial of service, and changing the configuration.

CVE-2020-28272CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Prototype pollution vulnerability in 'keyget' versions 1.0.0 through 2.2.0 allows attacker to cause a denial of service and may lead to remote code execution.

CVE-2020-28273CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Prototype pollution vulnerability in 'set-in' versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service and may lead to remote code execution.

CVE-2020-29389CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user. System using the Crux Linux Docker container deployed by affected versions of the Docker image may allow an attacker to achieve root access with a blank password.

CVE-2020-29280CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The Victor CMS v1.0 application is vulnerable to SQL injection via the 'search' parameter on the search.php page.

CVE-2020-29282CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability in BloodX 1.0 allows attackers to bypass authentication.

CVE-2020-29283CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php.

CVE-2020-29284CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

The file view-chair-list.php in Multi Restaurant Table Reservation System 1.0 does not perform input validation on the table_id parameter which allows unauthenticated SQL Injection. An attacker can send malicious input in the GET request to /dashboard/view-chair-list.php?table_id= to trigger the vulnerability.

CVE-2020-29285CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL injection vulnerability was discovered in Point of Sales in PHP/PDO 1.0, which can be exploited via the id parameter to edit_category.php.

CVE-2020-29287CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL injection vulnerability was discovered in Car Rental Management System v1.0 can be exploited via the id parameter in view_car.php or the car_id parameter in booking.php.

CVE-2020-29288CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

An SQL injection vulnerability was discovered in Gym Management System In manage_user.php file, GET parameter 'id' is vulnerable.

CVE-2020-6017CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment() when configured to support plain-text messages, leading to a Heap-Based Buffer Overflow and resulting in a memory corruption and possibly even a remote code execution.

CVE-2020-2320CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-494

Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.

CVE-2020-5800CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-669

The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and retrieve or modify information that they would not normally have access to.

CVE-2020-25462CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Heap buffer overflow in the fxCheckArrowFunction function at moddable/xs/sources/xsSyntaxical.c:3562 in Moddable SDK before OS200903.

CVE-2020-5799CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The Eat Spray Love mobile app for both iOS and Android contains a backdoor account that, when modified, allowed privileged access to restricted functionality and to other users' data.

CVE-2020-29595CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

PlugIns\IDE_ACDStd.apl in ACDSee Photo Studio Studio Professional 2021 14.0 Build 1705 has a User Mode Write AV starting at IDE_ACDStd!JPEGTransW+0x00000000000031aa.

CVE-2020-29600CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.

CVE-2020-29576CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.

CVE-2020-17531CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

A Java Serialization vulnerability was found in Apache Tapestry 4. Apache Tapestry 4 will attempt to deserialize the "sp" parameter even before invoking the page's validate method, leading to deserialization without authentication. Apache Tapestry 4 reached end of life in 2008 and no update to address this issue will be released. Apache Tapestry 5 versions are not vulnerable to this issue. Users of Apache Tapestry 4 should upgrade to the latest Apache Tapestry 5 version.

CVE-2020-25889CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Online Bus Booking System Project Using PHP/MySQL version 1.0 has SQL injection via the login page. By placing SQL injection payload on the login page attackers can bypass the authentication and can gain the admin privilege.

CVE-2020-29578CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.

CVE-2020-29564CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The official Consul Docker images 0.7.1 through 1.4.2 contain a blank password for a root user. System using the Consul Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.

CVE-2020-29575CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The official elixir Docker images before 1.8.0-alpine (Alpine specific) contain a blank password for a root user. Systems using the elixir Linux Docker container deployed by affected versions of the Docker image may allow a remote attacker to achieve root access with a blank password.

CVE-2020-29577CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.

CVE-2020-29579CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The official Express Gateway Docker images before 1.14.0 contain a blank password for a root user. Systems using the Express Gateway Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access.

CVE-2020-29580CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The official storm Docker images before 1.2.1 contain a blank password for a root user. Systems using the Storm Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.

CVE-2020-29581CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The official spiped docker images before 1.5-alpine contain a blank password for a root user. Systems using the spiped docker container deployed by affected versions of the docker image may allow an remote attacker to achieve root access with a blank password.

CVE-2020-29601CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The official notary docker images before signer-0.6.1-1 contain a blank password for a root user. System using the notary docker container deployed by affected versions of the docker image may allow an remote attacker to achieve root access with a blank password.

CVE-2020-29602CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

The official irssi docker images before 1.1-alpine (Alpine specific) contain a blank password for a root user. System using the irssi docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.

CVE-2020-28274CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Prototype pollution vulnerability in 'deepref' versions 1.1.1 through 1.2.1 allows attacker to cause a denial of service and may lead to remote code execution.

CVE-2020-17529CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

Out-of-bounds Write vulnerability in TCP Stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying and invalid fragmentation offset value specified in the IP header. This is only impacts builds with both CONFIG_EXPERIMENTAL and CONFIG_NET_TCP_REASSEMBLY build flags enabled.

CVE-2020-29659CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack.

← PreviousPage 373 / 7034Next →