Latest CVE Feed
-
9.8
CRITICALCVE-2020-10849
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos7885, Exynos8895, and Exynos9810 chipsets) software. The Gatekeeper trustlet allows a brute-force attack on the screen lock password. The Samsung ID is SVE-2019-1457... Read more
- EPSS Score: %0.12
- Published: Mar. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10794
Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to unauthenticated path traversal that allows an attacker to download the application database. This can be combined with CVE-2020-10795 for remote root access.... Read more
- EPSS Score: %1.35
- Published: May. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10656
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouseWithChunksV2 API. The vulnerability allows an anonymous remote attacker to execute arbitrary ... Read more
Affected Products : insider_threat_management_server- EPSS Score: %6.60
- Published: Jan. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10620
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for example, stopping the service remotely.... Read more
Affected Products : softpac_project- EPSS Score: %0.28
- Published: May. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10599
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited resulting in a buffer overflow, which may lead to a denial-of-service condition and execution of arbitrary code.... Read more
- EPSS Score: %0.33
- Published: Apr. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10611
Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type confusion condition. Authe... Read more
Affected Products : scada_data_gateway- EPSS Score: %9.01
- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10595
pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental prompting by a Kerberos library. It may overflow a buffer provided by the underlying Kerberos library by a single '\0' byte if an attacke... Read more
- EPSS Score: %7.30
- Published: Mar. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10582
A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database.... Read more
Affected Products : automatic_device_management- EPSS Score: %0.51
- Published: Mar. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10567
An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate... Read more
Affected Products : responsive_filemanager- EPSS Score: %17.87
- Published: Mar. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10335
A vulnerability was found in SourceCodester Garbage Collection Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injectio... Read more
Affected Products : garbage_collection_management_system- Published: Oct. 24, 2024
- Modified: Oct. 28, 2024
-
9.8
CRITICALCVE-2020-10654
Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers. This condition can be potentially exploited into a Remote Code Execution vector on the authenticating endpoint.... Read more
Affected Products : pingid_ssh_integration- EPSS Score: %7.48
- Published: May. 13, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10549
rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.... Read more
Affected Products : rconfig- EPSS Score: %91.62
- Published: Jun. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10561
An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web management background, resulting in command execution vulnerabilities.... Read more
- EPSS Score: %1.57
- Published: Jun. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10574
An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of a typo in the JSON validation.... Read more
Affected Products : janus- EPSS Score: %0.42
- Published: Mar. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10507
The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Unrestricted file upload (RCE) , that would allow attackers to gain access in the hosting machine.... Read more
Affected Products : the_school_manage_system- EPSS Score: %0.42
- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10349
A vulnerability was found in SourceCodester Best House Rental Management System 1.0 and classified as critical. Affected by this issue is the function delete_tenant of the file /ajax.php?action=delete_tenant. The manipulation of the argument id leads to s... Read more
Affected Products : best_house_rental_management_system- Published: Oct. 24, 2024
- Modified: Oct. 30, 2024
-
9.8
CRITICALCVE-2020-10285
The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts to gain access.... Read more
- EPSS Score: %0.37
- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10374
A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot function in the Contact Support form.... Read more
Affected Products : prtg_network_monitor- EPSS Score: %4.89
- Published: Mar. 30, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10276
The password for the safety PLC is the default and thus easy to find (in manuals, etc.). This allows a manipulated program to be uploaded to the safety PLC, effectively disabling the emergency stop in case an object is too close to the robot. Navigation a... Read more
Affected Products : mir100_firmware mir100_firmware mir200_firmware mir250_firmware mir500_firmware mir1000_firmware er200_firmware er-lite_firmware er-flex_firmware er-one_firmware +11 more products- EPSS Score: %0.36
- Published: Jun. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10256
An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge prior to 0.7.3. An insecure random number generator was used to generate various keys. An attacker with access to ... Read more
- EPSS Score: %0.26
- Published: Oct. 27, 2020
- Modified: Nov. 21, 2024