CVE Database

CVE-2019-7198CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero. QuTS hero h4.5.1.1472 build 20201031 and later QTS 4.5.1.1456 build 20201015 and later QTS 4.4.3.1354 build 20200702 and later

CVE-2020-29667CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-613

In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system because of Insufficient Session Expiration.

CVE-2020-19142CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.

CVE-2020-19527CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php.

CVE-2020-26201CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-521

Askey AP5100W_Dual_SIG_1.01.097 and all prior versions use a weak password at the Operating System (rlx-linux) level. This allows an attacker to gain unauthorized access as an admin or root user to the device Operating System via Telnet or SSH.

CVE-2020-29311CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside the config file and being triggered by another part of the software.

CVE-2020-28215CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-862

A CWE-862: Missing Authorization vulnerability exists in Easergy T300 (firmware 2.7 and older), that could cause a wide range of problems, including information exposures, denial of service, and arbitrary code execution when access control checks are not applied consistently.

CVE-2020-7540CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions), that could cause unauthenticated command execution in the controller when sending special HTTP requests.

CVE-2020-24633CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

There are multiple buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending especially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211) of access-points or controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.

CVE-2020-24634CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management protocol) UDP port (8211) of access-pointsor controllers in Aruba 9000 Gateway; Aruba 7000 Series Mobility Controllers; Aruba 7200 Series Mobility Controllers version(s): 2.1.0.1, 2.2.0.0 and below; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below ; 6.4.4.23, 6.5.4.17, 8.2.2.9, 8.3.0.13, 8.5.0.10, 8.6.0.5, 8.7.0.0 and below.

CVE-2020-13556CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2020-7788CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2020-29591CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-521

Versions of the Official registry Docker images through 2.7.0 contain a blank password for the root user. Systems deployed using affected versions of the registry container may allow a remote attacker to achieve root access with a blank password.

CVE-2020-15357CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

Network Analysis functionality in Askey AP5100W_Dual_SIG_1.01.097 and all prior versions allows remote attackers to execute arbitrary commands via a shell metacharacter in the ping, traceroute, or route options.

CVE-2020-28439CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package 'corenlp-js-interface.' Vulnerability can be exploited with the following PoC:

CVE-2020-28440CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function.

CVE-2020-19165CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

PHPSHE 1.7 has SQL injection via the admin.php?mod=user&userlevel_id=1 userlevel_id[] parameter.

CVE-2020-27730CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.

CVE-2020-17438CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that reassembles fragmented packets fails to properly validate the total length of an incoming packet specified in its IP header, as well as the fragmentation offset value specified in the IP header. By crafting a packet with specific values of the IP header length and the fragmentation offset, attackers can write into the .bss section of the program (past the statically allocated buffer that is used for storing the fragmented data) and cause a denial of service in uip_reass() in uip.c, or possibly execute arbitrary code on some target architectures.

CVE-2020-24336CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answers in ip64-dns64.c doesn't verify whether the address in the answer's length is sane. Therefore, when copying an address of an arbitrary length, a buffer overflow can occur. This bug can be exploited whenever NAT64 is enabled.

CVE-2020-24338CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered in picoTCP through 1.7.0. The DNS domain name record decompression functionality in pico_dns_decompress_name() in pico_dns_common.c does not validate the compression pointer offset values with respect to the actual data present in a DNS response packet, causing out-of-bounds writes that lead to Denial-of-Service and Remote Code Execution.

CVE-2020-25107CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. There is no check on whether a domain name has '\0' termination. This may lead to successful Denial-of-Service, and possibly Remote Code Execution.

CVE-2020-25108CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The DNS response data length is not checked (it can be set to an arbitrary value from a packet). This may lead to successful Denial-of-Service, and possibly Remote Code Execution.

CVE-2020-25109CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The number of DNS queries/responses (set in a DNS header) is not checked against the data present. This may lead to successful Denial-of-Service, and possibly Remote Code Execution.

CVE-2020-25110CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-125

An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The length byte of a domain name in a DNS query/response is not checked, and is used for internal memory operations. This may lead to successful Denial-of-Service, and possibly Remote Code Execution.

CVE-2020-25111CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered in the IPv6 stack in Contiki through 3.0. There is an insufficient check for the IPv6 header length. This leads to Denial-of-Service and potential Remote Code Execution via a crafted ICMPv6 echo packet.

CVE-2020-25112CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered in the IPv6 stack in Contiki through 3.0. There are inconsistent checks for IPv6 header extension lengths. This leads to Denial-of-Service and potential Remote Code Execution via a crafted ICMPv6 echo packet.

CVE-2020-29563CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device.

CVE-2020-5639CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Directory traversal vulnerability in FileZen versions from V3.0.0 to V4.2.2 allows remote attackers to upload an arbitrary file in a specific directory via unspecified vectors. As a result, an arbitrary OS command may be executed.

CVE-2020-29227KEVCRITICALin_the_wild
CVSS 9.8
EPSS 93.41%
Priority 0

An issue was discovered in Car Rental Management System 1.0. An unauthenticated user can perform a file inclusion attack against the /index.php file with a partial filename in the "page" parameter, to cause local file inclusion resulting in code execution.

CVE-2020-14244CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the server or inject code into the system which would execute with the privileges of the server.

CVE-2020-14268CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the client or inject code into the system which would execute with the privileges of the client.

CVE-2020-35378CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection in the login page in Online Bus Ticket Reservation 1.0 allows attackers to execute arbitrary SQL commands and bypass authentication via the username and password fields.

CVE-2020-35338CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

The Web Administrative Interface in Mobile Viewpoint Wireless Multiplex Terminal (WMT) Playout Server 20.2.8 and earlier has a default account with a password of "pokon."

CVE-2020-20136CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.

CVE-2020-20184CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.

CVE-2020-25187CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

Medtronic MyCareLink Smart 25000 is  vulnerable when an authenticated attacker runs a debug command, which can be sent to the patient reader and cause a heap overflow event within the MCL Smart Patient Reader software stack. The heap overflow could allow an attacker to remotely execute code on the MCL Smart Patient Reader, potentially leading to control of the device

CVE-2020-8257CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-269

Improper privilege management on services run by Citrix Gateway Plug-in for Windows, versions before and including 13.0-61.48 and 12.1-58.15, lead to privilege escalation attacks

CVE-2020-20189CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

SQL Injection vulnerability in NewPK 1.1 via the title parameter to admin\newpost.php.

CVE-2020-25228CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). A service available on port 10005/tcp of the affected devices could allow complete access to all services without authorization. An attacker could gain full control over an affected device, if he has access to this service. The system manual recommends to protect access to this port.

CVE-2020-0456CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170378843

CVE-2020-0455CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170372514

CVE-2020-0457CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170367562

CVE-2020-28442CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-Other

All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.

CVE-2020-4747CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper authentication methods. IBM X-Force ID: 188516.

CVE-2020-27068CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Product: AndroidVersions: Android kernelAndroid ID: A-127973231References: Upstream kernel

CVE-2020-35464CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the Weave Cloud Agent container may allow a remote attacker to achieve root access with a blank password.

CVE-2020-35462CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

Version 3.16.0 of the CoScale agent Docker image contains a blank password for the root user. Systems deployed using affected versions of the CoScale agent container may allow a remote attacker to achieve root access with a blank password.

CVE-2020-35463CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

Version 1.0.0 of the Instana Dynamic APM Docker image contains a blank password for the root user. Systems deployed using affected versions of the Instana Dynamic APM container may allow a remote attacker to achieve root access with a blank password.

CVE-2020-35466CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-306

The Blackfire Docker image through 2020-12-14 contains a blank password for the root user. Systems deployed using affected versions of the Blackfire container may allow a remote attacker to achieve root access with a blank password.

← PreviousPage 374 / 7034Next →