Latest CVE Feed
-
9.8
CRITICALCVE-2019-8352
By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able to capture this network traffic, they could decrypt these... Read more
Affected Products : patrol_agent- EPSS Score: %5.44
- Published: May. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7224
The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load.... Read more
- EPSS Score: %0.62
- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7628
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.... Read more
- EPSS Score: %1.33
- Published: Apr. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7630
git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.... Read more
Affected Products : git-add-remote- EPSS Score: %1.23
- Published: Apr. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7640
pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any sanitization.... Read more
Affected Products : pixl-class- EPSS Score: %0.65
- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7645
All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating systems.... Read more
Affected Products : chrome-launcher- EPSS Score: %0.58
- Published: May. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-13921
**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.... Read more
Affected Products : skywalking- EPSS Score: %5.76
- Published: Aug. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7702
All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.... Read more
Affected Products : templ8- EPSS Score: %0.39
- Published: Aug. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7703
All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.... Read more
Affected Products : nis-utils- EPSS Score: %0.41
- Published: Aug. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8908
An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" screen, and uploading an image file, as demonstrated by a .php filename and th... Read more
Affected Products : wtcms- EPSS Score: %0.84
- Published: Feb. 18, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7698
This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endpoint, isn’t being sanitized.... Read more
Affected Products : gerapy- EPSS Score: %0.42
- Published: Jul. 29, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8948
PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.... Read more
- EPSS Score: %0.27
- Published: Feb. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7715
All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.... Read more
Affected Products : deep-get-set- EPSS Score: %0.80
- Published: Sep. 01, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8985
On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code executio... Read more
- EPSS Score: %71.81
- Published: Feb. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7781
This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:... Read more
Affected Products : connection-tester- EPSS Score: %0.56
- Published: Dec. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7861
AnySupport (Remote support solution) before 2019.3.21.0 allows directory traversing because of swprintf function to copy file from a management PC to a client PC. This can be lead to arbitrary file execution.... Read more
- EPSS Score: %1.10
- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7981
sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection when within_bounding_box is used in conjunction with untrusted sw_lat, sw_lng, ne_lat, or ne_lng data.... Read more
Affected Products : geocoder- EPSS Score: %0.63
- Published: Jan. 25, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9125
An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer overflow vulnerability that does not require authentication via the HNAP_AUTH HTTP header.... Read more
- EPSS Score: %1.46
- Published: Feb. 25, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8088
panel_login.php in UseBB 1.0.12 allows type juggling for login bypass because != is used instead of !== for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.... Read more
Affected Products : usebb- EPSS Score: %0.15
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-9204
SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL commands.... Read more
Affected Products : incident_manager- EPSS Score: %13.41
- Published: Mar. 28, 2019
- Modified: Nov. 21, 2024