CVE Database

CVE-2020-29594CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML login.

CVE-2019-12768CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-425

An issue was discovered on D-Link DAP-1650 devices through v1.03b07 before 1.04B02_J65H Hot Fix. Attackers can bypass authentication via forceful browsing.

CVE-2020-35173CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The Amaze File Manager application before 3.4.2 for Android does not properly restrict intents for controlling the FTP server (aka services.ftpservice.FTPReceiver.ACTION_START_FTPSERVER and services.ftpservice.FTPReceiver.ACTION_STOP_FTPSERVER).

CVE-2020-11103CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

JsLink in Webswing before 2.6.12 LTS, and 2.7.x and 20.x before 20.1, allows remote code execution.

CVE-2020-12658CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-667

gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in question, so a DoS there doesn't make any sense, and there has been no additional information provided us (as upstream) to indicate why this would be a problem.

CVE-2016-9025CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php.

CVE-2016-9021CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Exponent CMS before 2.6.0 has improper input validation in storeController.php.

CVE-2016-9022CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Exponent CMS before 2.6.0 has improper input validation in usersController.php.

CVE-2016-9023CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.

CVE-2018-14067CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

Green Packet WiMax DV-360 2.10.14-g1.0.6.1 devices allow Command Injection, with unauthenticated remote command execution, via a crafted payload to the HTTPS port, because lighttpd listens on all network interfaces (including the external Internet) by default. NOTE: this may overlap CVE-2017-9980.

CVE-2019-7725CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies on PHP's serialization format when JSON can be used to eliminate the risk).

CVE-2019-7726CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

modules/banners/funcs/click.php in NukeViet before 4.3.04 has a SQL INSERT statement with raw header data from an HTTP request (e.g., Referer and User-Agent).

CVE-2020-25843CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-122

NHIServiSignAdapter fails to verify the length of digital credential files’ path which leads to a heap overflow loophole. Remote attackers can use the leak to execute code without privilege.

CVE-2020-25844CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-121

The digest generation function of NHIServiSignAdapter has not been verified for parameter’s length, which leads to a stack overflow loophole. Remote attackers can use the leak to execute code without privilege.

CVE-2020-25848CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.

CVE-2020-35851CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and execute arbitrary commands of the system.

CVE-2020-35902CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

An issue was discovered in the actix-codec crate before 0.3.0-beta.1 for Rust. There is a use-after-free in Framed.

CVE-2020-35926CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-330

An issue was discovered in the nanorand crate before 0.5.1 for Rust. It caused any random number generator (even ChaCha) to return all zeroes because integer truncation was mishandled.

CVE-2019-25009CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

An issue was discovered in the http crate before 0.1.20 for Rust. The HeaderMap::Drain API can use a raw pointer, defeating soundness.

CVE-2019-25010CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-843

An issue was discovered in the failure crate through 2019-11-13 for Rust. Type confusion can occur when __private_get_type_id__ is overridden.

CVE-2020-35858CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-787

An issue was discovered in the prost crate before 0.6.1 for Rust. There is stack consumption via a crafted message, causing a denial of service (e.g., x86) or possibly remote code execution (e.g., ARM).

CVE-2020-35860CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-476

An issue was discovered in the cbox crate through 2020-03-19 for Rust. The CBox API allows dereferencing raw pointers without a requirement for unsafe code.

CVE-2020-35862CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

An issue was discovered in the bitvec crate before 0.17.4 for Rust. BitVec to BitBox conversion leads to a use-after-free or double free.

CVE-2020-35863CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-444

An issue was discovered in the hyper crate before 0.12.34 for Rust. HTTP request smuggling can occur. Remote code execution can occur in certain situations with an HTTP server on the loopback interface.

CVE-2020-35869CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-134

An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because rusqlite::trace::log mishandles format strings.

CVE-2020-35870CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API use-after-free.

CVE-2020-35872CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via the repr(Rust) type.

CVE-2020-35873CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because sessions.rs has a use-after-free.

CVE-2020-35876CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-416

An issue was discovered in the rio crate through 2020-05-11 for Rust. A struct can be leaked, allowing attackers to obtain sensitive information, cause a use-after-free, or cause a data race.

CVE-2020-35877CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

An issue was discovered in the ozone crate through 2020-07-04 for Rust. Memory safety is violated because of out-of-bounds access.

CVE-2020-35878CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-119

An issue was discovered in the ozone crate through 2020-07-04 for Rust. Memory safety is violated because of the dropping of uninitialized memory.

CVE-2020-35885CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-415

An issue was discovered in the alpm-rs crate through 2020-08-20 for Rust. StrcCtx performs improper memory deallocation.

CVE-2020-35887CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

An issue was discovered in the arr crate through 2020-08-25 for Rust. There is a buffer overflow in Index and IndexMut.

CVE-2020-35888CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-908

An issue was discovered in the arr crate through 2020-08-25 for Rust. Uninitialized memory is dropped by Array::new_from_template.

CVE-2020-35949CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

An issue was discovered in the Quiz and Survey Master plugin before 7.0.1 for WordPress. It made it possible for unauthenticated attackers to upload arbitrary files and achieve remote code execution. If a quiz question could be answered by uploading a file, only the Content-Type header was checked during the upload, and thus the attacker could use text/plain for a .php file.

CVE-2020-28464CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine.

CVE-2020-7771CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

The package asciitable.js before 1.0.3 are vulnerable to Prototype Pollution via the main function.

CVE-2020-36112KEVCRITICALin_the_wild
CVSS 9.8
EPSS 89.49%
Priority 0

CSE Bookstore version 1.0 is vulnerable to time-based blind, boolean-based blind and OR error-based SQL injection in pubid parameter in bookPerPub.php and in cart.php. A successful exploitation of this vulnerability will lead to an attacker dumping the entire database on which the web application is running.

CVE-2020-26292CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-507

Creeper is an experimental dynamic, interpreted language. The binary release of Creeper Interpreter 1.1.3 contains potential malware. The compromised binary release was available for a few hours between December 26, 2020 at 3:22 PM EST to December 26, 2020 at 11:00 PM EST. If you used the source code, you are **NOT** affected. This only affects the binary releases. The binary of unknown quality has been removed from the release. If you have downloaded the binary, please delete it and run a reputable antivirus scanner to ensure that your computer is clean.

CVE-2020-35219CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

The ASUS DSL-N17U modem with firmware 1.1.0.2 allows attackers to access the admin interface by changing the admin password without authentication via a POST request to Advanced_System_Content.asp with the uiViewTools_username=admin&uiViewTools_Password= and uiViewTools_PasswordConfirm= substrings.

CVE-2020-36157CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered in the Ultimate Member plugin before 2.1.12 for WordPress, aka Unauthenticated Privilege Escalation via User Roles. Due to the lack of filtering on the role parameter that could be supplied during the registration process, an attacker could supply the role parameter with a WordPress capability (or any custom Ultimate Member role) and effectively be granted those privileges.

CVE-2020-26045CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

CVE-2021-3021CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

ISPConfig before 3.2.2 allows SQL injection.

CVE-2022-35201CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

Tenda-AC18 V15.03.05.05 was discovered to contain a remote command execution (RCE) vulnerability.

CVE-2020-36052CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

Directory traversal vulnerability in post-edit.php in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter.

CVE-2020-26759CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

clickhouse-driver before 0.1.5 allows a malicious clickhouse server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, due to a buffer overflow.

CVE-2020-10655CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouse API. The vulnerability allows an anonymous remote attacker to execute arbitrary code with local administrator privileges. The vulnerability is caused by improper deserialization.

CVE-2020-10656CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouseWithChunksV2 API. The vulnerability allows an anonymous remote attacker to execute arbitrary code with local administrator privileges. The vulnerability is caused by improper deserialization.

CVE-2020-10658CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-502

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteImage API. The vulnerability allows an anonymous remote attacker to execute arbitrary code with local administrator privileges. The vulnerability is caused by improper deserialization.

CVE-2012-10001CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

The Limit Login Attempts plugin before 1.7.1 for WordPress does not clear auth cookies upon a lockout, which might make it easier for remote attackers to conduct brute-force authentication attempts.

← PreviousPage 377 / 7034Next →