Vulnerabilites CVE
Base de donnees CVE enrichie avec CISA KEV et NVD
| CVE ID | CVSS | Severite | KEV | Observations |
|---|---|---|---|---|
| CVE-2020-29390 Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-28926 ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug res... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-25537 File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission. | 9.8 | CRITICAL | — | 0 |
| CVE-2020-24786 An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before buil... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-29127 An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web browser), the portal can be accessed with root privi... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-29381 An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. Command injection can occur in "uploa... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-29377 An issue was discovered on V-SOL V1600D V2.03.69 OLT devices. The string K0LTdi@gnos312$ is compared to the password provided by the the remote attacker. If it matches, access is provided. | 9.8 | CRITICAL | — | 0 |
| CVE-2020-29376 An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. There is an !j@l#y$z%x6x7q8c9z) passw... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-7714 All versions of package confucious are vulnerable to Prototype Pollution via the set function. | 9.8 | CRITICAL | — | 0 |
| CVE-2017-15681 In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE. | 9.8 | CRITICAL | — | 0 |
| CVE-2020-27745 Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-19876 An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An EnMon PHP script was vulnerable to SQL injection, a different vulnerability than CVE-2019-10006. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-19875 An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (using Python scripts) via the AprolCluster script that is invoked via sudo and thus ... | 9.8 | CRITICAL | — | 0 |
| CVE-2019-19874 An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allowed injection and execution of arbitrary unintended commands on the web server, ... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-7521 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method o... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-7522 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in SFAPV9601 - APC Easy UPS On-Line Software (V2.0 and earlier) when accessing a vulnerable method o... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-28073 SourceCodester Library Management System 1.0 is affected by SQL Injection allowing an attacker to bypass the user authentication and impersonate any user on the system. | 9.8 | CRITICAL | — | 0 |
| CVE-2020-29128 petl before 1.68, in some configurations, allows resolution of entities in an XML document. | 9.8 | CRITICAL | — | 0 |
| CVE-2020-27251 A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious port ranges, which could result... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-28070 SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter. | 9.8 | CRITICAL | — | 0 |
| CVE-2020-29062 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, ... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-7715 All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function. | 9.8 | CRITICAL | — | 0 |
| CVE-2020-25049 An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. StatusBarService has insufficient DEX access control. The Samsung ID is SVE-2020-17797 (August 2020). | 9.8 | CRITICAL | — | 0 |
| CVE-2020-29061 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, ... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-29060 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, ... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-25052 An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. H-Arx allows attackers to execute arbitrary code or cause a denial of service (memory corruption) because... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-25053 An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. RKP allows arbitrary code execution. The Samsung ID is SVE-2020-17435 (August 2020). | 9.8 | CRITICAL | — | 0 |
| CVE-2020-25055 An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows attackers (who control an unprivileged SecureFolder process) to bypass admin res... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-29059 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, ... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-25058 An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. The network_management service does not properly restrict configuration changes. The LG ID is LVE-SMP-200012 ... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-29058 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, ... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-15588 An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendReque... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-25061 An issue was discovered on LG mobile devices with Android OS 9 and 10 software on the VZW network. lge_property allows property overwrites. The LG ID is LVE-SMP-200016 (July 2020). | 9.8 | CRITICAL | — | 0 |
| CVE-2020-25062 An issue was discovered on LG mobile devices with Android OS 9 and 10 software. LGTelephonyProvider allows a bypass of intended privilege restrictions. The LG ID is LVE-SMP-200017 (July 2020). | 9.8 | CRITICAL | — | 0 |
| CVE-2020-29056 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, ... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-7716 All versions of package deeps are vulnerable to Prototype Pollution via the set function. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-19872 An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject and execute arbitrary unintended commands via an unspecified attack scenario, a di... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-29054 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, ... | 9.8 | CRITICAL | — | 0 |
| CVE-2015-9551 An issue was discovered on TOTOLINK A850R-V1 through 1.0.1-B20150707.1612 and F1-V2 through 1.1-B20150708.1646 devices. There is Remote Code Execution in the management interface via the formSysCmd sy... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-28329 Barco wePresent WiPG-1600W firmware includes a hardcoded API account and password that is discoverable by inspecting the firmware image. A malicious actor could use this password to access authenticat... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-25159 499ES EtherNet/IP (ENIP) Adaptor Source Code is vulnerable to a stack-based buffer overflow, which may allow an attacker to send a specially crafted packet that may result in a denial-of-service condi... | 9.8 | CRITICAL | — | 0 |
| CVE-2020-7719 Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function. | 9.8 | CRITICAL | — | 0 |
| CVE-2020-7720 The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions. | 9.8 | CRITICAL | — | 0 |
| CVE-2020-7721 All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function. | 9.8 | CRITICAL | — | 0 |
| CVE-2020-7722 All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function. | 9.8 | CRITICAL | — | 0 |
| CVE-2020-7723 All versions of package promisehelpers are vulnerable to Prototype Pollution via the insert function. | 9.8 | CRITICAL | — | 0 |
| CVE-2020-7724 All versions of package tiny-conf are vulnerable to Prototype Pollution via the set function. | 9.8 | CRITICAL | — | 0 |
| CVE-2020-7725 All versions of package worksmith are vulnerable to Prototype Pollution via the setValue function. | 9.8 | CRITICAL | — | 0 |
| CVE-2020-7726 All versions of package safe-object2 are vulnerable to Prototype Pollution via the setter function. | 9.8 | CRITICAL | — | 0 |
| CVE-2020-7727 All versions of package gedi are vulnerable to Prototype Pollution via the set function. | 9.8 | CRITICAL | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.