Latest CVE Feed
-
9.8
CRITICALCVE-2020-11708
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. Privilege escalation can occur via the /ajax/SetUserInfo messages parameter because of the EXECUTE() feature, which is for executing programs when certain events are triggered.... Read more
Affected Products : provide_ftp_server- Published: Apr. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11673
An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This is due to the usage of the callback wp_ajax_nopriv function in Includes/Tot... Read more
Affected Products : responsive_poll- Published: Apr. 13, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11656
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.... Read more
- Published: Apr. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11658
CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.... Read more
Affected Products : ca_api_developer_portal- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11651
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can ... Read more
- Actively Exploited
- Published: Apr. 30, 2020
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2020-11598
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and executing an ASHX file.... Read more
Affected Products : cipace- Published: Apr. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11597
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request and inject SQL statements in the user context of the db owner.... Read more
Affected Products : cipace- Published: Apr. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11630
An issue was discovered in EJBCA before 6.15.2.6 and 7.x before 7.3.1.2. In several sections of code, the verification of serialized objects sent between nodes (connected via the Peers protocol) allows insecure objects to be deserialized.... Read more
Affected Products : ejbca- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11558
An issue was discovered in libgpac.a in GPAC 0.8.0, as demonstrated by MP4Box. audio_sample_entry_Read in isomedia/box_code_base.c does not properly decide when to make gf_isom_box_del calls. This leads to various use-after-free outcomes involving mdia_Re... Read more
Affected Products : gpac- Published: Apr. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11535
An issue was discovered in ONLYOFFICE Document Server 5.5.0. An attacker can craft a malicious .docx file, and exploit XML injection to enter an attacker-controlled parameter into the x2t binary, to rewrite this binary and/or libxcb.so.1, and execute code... Read more
Affected Products : document_server- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11518
Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.... Read more
Affected Products : manageengine_adselfservice_plus- Published: Apr. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11545
Project Worlds Official Car Rental System 1 is vulnerable to multiple SQL injection issues, as demonstrated by the email and parameters (account.php), uname and pass parameters (login.php), and id parameter (book_car.php) This allows an attacker to dump t... Read more
Affected Products : official_car_rental_system- Published: Apr. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11455
LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileManager.php.... Read more
Affected Products : limesurvey- Published: Apr. 01, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11197
Possible integer overflow can occur when stream info update is called when total number of streams detected are zero while parsing TS clip with invalid data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdrag... Read more
- Published: Jan. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-8650
python-requests-Kerberos through 0.5 does not handle mutual authentication... Read more
- Published: Dec. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11105
An issue was discovered in USC iLab cereal through 1.3.0. It employs caching of std::shared_ptr values, using the raw pointer address as a unique identifier. This becomes problematic if an std::shared_ptr variable goes out of scope and is freed, and a new... Read more
Affected Products : cereal- Published: Mar. 30, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11101
Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.... Read more
Affected Products : airlink_mobility_manager- Published: Dec. 26, 2022
- Modified: Apr. 14, 2025
-
9.8
CRITICALCVE-2020-11079
node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This has been fixed in 0.2.1.... Read more
Affected Products : node-dns-sync- Published: May. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10990
An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component.... Read more
Affected Products : mercury- Published: Mar. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12815
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.... Read more
- Published: Jul. 19, 2019
- Modified: Nov. 21, 2024