Latest CVE Feed
-
9.8
CRITICALCVE-2013-1401
Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPress allow a remote attacker to add, edit, and delete an answer and delete a poll.... Read more
Affected Products : wordpress_poll- EPSS Score: %4.56
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25190
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials of third-party services in cleartext.... Read more
- EPSS Score: %0.09
- Published: Dec. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25197
A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.... Read more
- EPSS Score: %3.56
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25147
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to SQL Injection due to the fact that it is possible to inject malicious SQL statements in malformed parameter types. This can occur via username[0] to ... Read more
Affected Products : observium- EPSS Score: %0.37
- Published: Sep. 25, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25109
An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The number of DNS queries/responses (set in a DNS header) is not checked against the data present. This may lead to successful Denial-of-Service, and possibly Remote Code Executi... Read more
Affected Products : nut\/os- EPSS Score: %16.48
- Published: Dec. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25112
An issue was discovered in the IPv6 stack in Contiki through 3.0. There are inconsistent checks for IPv6 header extension lengths. This leads to Denial-of-Service and potential Remote Code Execution via a crafted ICMPv6 echo packet.... Read more
Affected Products : contiki-os- EPSS Score: %16.48
- Published: Dec. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-29060
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN... Read more
Affected Products : 72408a_firmware 9008a_firmware 9016a_firmware 92408a_firmware 92416a_firmware 9288_firmware 97016_firmware 97024p_firmware 97028p_firmware 97042p_firmware +46 more products- EPSS Score: %0.38
- Published: Nov. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25110
An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The length byte of a domain name in a DNS query/response is not checked, and is used for internal memory operations. This may lead to successful Denial-of-Service, and possibly R... Read more
Affected Products : nut\/os- EPSS Score: %16.48
- Published: Dec. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25189
The affected product is vulnerable to three stack-based buffer overflows, which may allow an unauthenticated attacker to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09).... Read more
- EPSS Score: %1.43
- Published: Nov. 21, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-29047
The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.... Read more
Affected Products : wp_hotel_booking- EPSS Score: %78.38
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25055
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The persona service allows attackers (who control an unprivileged SecureFolder process) to bypass admin restrictions in KnoxContainer. The Samsung ID is SVE-2020-... Read more
Affected Products : android- EPSS Score: %0.13
- Published: Aug. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25052
An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. H-Arx allows attackers to execute arbitrary code or cause a denial of service (memory corruption) because indexes are mishandled. The Samsung ID is SVE-2020-174... Read more
- EPSS Score: %0.18
- Published: Aug. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25074
The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use this to achieve remote code execution.... Read more
- EPSS Score: %12.81
- Published: Nov. 10, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25053
An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. RKP allows arbitrary code execution. The Samsung ID is SVE-2020-17435 (August 2020).... Read more
- EPSS Score: %0.19
- Published: Aug. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25022
An issue was discovered in Noise-Java through 2020-08-27. AESGCMFallbackCipherState.encryptWithAd() allows out-of-bounds access.... Read more
Affected Products : noise-java- EPSS Score: %0.63
- Published: Sep. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25010
An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to upload a malicious script file by constructing a POST type request and writing a p... Read more
- EPSS Score: %2.48
- Published: Dec. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25011
A sensitive information disclosure vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to get username and password by request /cgi-bin/webadminget.cgi script via th... Read more
- EPSS Score: %0.62
- Published: Dec. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25175
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.... Read more
- EPSS Score: %0.24
- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-25020
MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.... Read more
- EPSS Score: %2.20
- Published: Aug. 29, 2020
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2020-25014
A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet.... Read more
Affected Products : zld zld_firmware access_points_firmware usg_flex_100 usg_flex_200 usg_flex_500 usg_flex_700 usg_flex_100w usg_20w-vpn vpn100 +43 more products- EPSS Score: %2.00
- Published: Nov. 27, 2020
- Modified: Dec. 12, 2024