Latest CVE Feed
-
9.8
CRITICALCVE-2020-11967
In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating ... Read more
- Published: Apr. 21, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11969
If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication. This affects Apache TomEE 8.0.0-M1 - 8.0.1, Apache TomE... Read more
Affected Products : tomee- Published: Jun. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11942
An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.... Read more
Affected Products : open-audit- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12001
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and lat... Read more
- Published: Jun. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11974
In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.... Read more
Affected Products : dolphinscheduler- Published: Dec. 18, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11878
The Jitsi Meet (aka docker-jitsi-meet) stack on Docker before stable-4384-1 uses default passwords (such as passw0rd) for system accounts.... Read more
Affected Products : meet- Published: Apr. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11873
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. A stack-based buffer overflow in the logging tool could allow an attacker to gain privileges. The LG ID is LVE-SMP-200005 (April 2020).... Read more
Affected Products : android- Published: Apr. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11857
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow remote attackers to access the OBR host as a non-admin user... Read more
Affected Products : operation_bridge_reporter- Published: Sep. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11849
Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager. Affecting versions prior to 4.7.3 and 4.8.1 hot fix 1. The vulnerability could allow information exposure that can result in an elevation of privilege or an u... Read more
- Published: Jul. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11829
Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros.codebook V2.0.0_5493e40_200722.... Read more
Affected Products : coloros- Published: Nov. 19, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11817
In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As a result of that, an attacker can execute a command on the server. This specific attack only occurs with the Maintenance Mode setting.... Read more
Affected Products : rukovoditel- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11805
Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.... Read more
- Published: Sep. 25, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11812
Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the filters[0][value] or filters[1][value] parameter.... Read more
Affected Products : rukovoditel- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11800
Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.... Read more
- Published: Oct. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11799
Z-Cron 5.6 Build 04 allows an unprivileged attacker to elevate privileges by modifying a privileged user's task. This can also affect all users who are signed in on the system if a shell is placed in a location that other unprivileged users have access to... Read more
Affected Products : z-cron- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11796
In JetBrains Space through 2020-04-22, the password authentication implementation was insecure.... Read more
Affected Products : space- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10608
A vulnerability was found in code-projects Courier Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /login.php. The manipulation of the argument txtusername leads to sql injection. The attack may... Read more
Affected Products : courier_management_system- Published: Nov. 01, 2024
- Modified: Nov. 05, 2024
-
9.8
CRITICALCVE-2021-21346
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed inp... Read more
Affected Products : fedora debian_linux communications_policy_management oncommand_insight jmeter retail_xstore_point_of_service webcenter_portal xstream activemq banking_platform +7 more products- Published: Mar. 23, 2021
- Modified: May. 23, 2025
-
9.8
CRITICALCVE-2020-11851
Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in the execution of arbitrary code.... Read more
Affected Products : arcsight_logger- Published: Nov. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10571
The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary ... Read more
Affected Products : chartify- Published: Nov. 14, 2024
- Modified: Nov. 19, 2024