Latest CVE Feed
-
9.8
CRITICALCVE-2020-11812
Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the filters[0][value] or filters[1][value] parameter.... Read more
Affected Products : rukovoditel- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11800
Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.... Read more
- Published: Oct. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11799
Z-Cron 5.6 Build 04 allows an unprivileged attacker to elevate privileges by modifying a privileged user's task. This can also affect all users who are signed in on the system if a shell is placed in a location that other unprivileged users have access to... Read more
Affected Products : z-cron- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11796
In JetBrains Space through 2020-04-22, the password authentication implementation was insecure.... Read more
Affected Products : space- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10608
A vulnerability was found in code-projects Courier Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /login.php. The manipulation of the argument txtusername leads to sql injection. The attack may... Read more
Affected Products : courier_management_system- Published: Nov. 01, 2024
- Modified: Nov. 05, 2024
-
9.8
CRITICALCVE-2021-21346
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed inp... Read more
Affected Products : fedora debian_linux communications_policy_management oncommand_insight jmeter retail_xstore_point_of_service webcenter_portal xstream activemq banking_platform +7 more products- Published: Mar. 23, 2021
- Modified: May. 23, 2025
-
9.8
CRITICALCVE-2020-11851
Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in the execution of arbitrary code.... Read more
Affected Products : arcsight_logger- Published: Nov. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10571
The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary ... Read more
Affected Products : chartify- Published: Nov. 14, 2024
- Modified: Nov. 19, 2024
-
9.8
CRITICALCVE-2020-11729
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Long-term session cookies, uses to provide long-term session continuity, are not generated securely, enabling a brute-force attack that may be successful.... Read more
- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11717
An issue was discovered in Programi 014 31.01.2020. It has multiple SQL injection vulnerabilities.... Read more
Affected Products : bilanc- Published: Dec. 21, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11720
An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. During the installation, it sets up administrative access by default with the account admin and password 0000. After the installation, users/admins are not pro... Read more
Affected Products : bilanc- Published: Dec. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11710
An issue was discovered in docker-kong (for Kong) through 2.0.3. The admin API port may be accessible on interfaces other than 127.0.0.1. NOTE: The vendor argue that this CVE is not a vulnerability because it has an inaccurate bug scope and patch links. “... Read more
Affected Products : docker-kong- Published: Apr. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11705
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. /ajax/ImportCertificate allows an attacker to load an arbitrary certificate in .pfx format or overwrite arbitrary files via the fileName parameter.... Read more
Affected Products : provide_ftp_server- Published: Apr. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11708
An issue was discovered in ProVide (formerly zFTPServer) through 13.1. Privilege escalation can occur via the /ajax/SetUserInfo messages parameter because of the EXECUTE() feature, which is for executing programs when certain events are triggered.... Read more
Affected Products : provide_ftp_server- Published: Apr. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11673
An issue was discovered in the Responsive Poll through 1.3.4 for Wordpress. It allows an unauthenticated user to manipulate polls, e.g., delete, clone, or view a hidden poll. This is due to the usage of the callback wp_ajax_nopriv function in Includes/Tot... Read more
Affected Products : responsive_poll- Published: Apr. 13, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11656
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.... Read more
- Published: Apr. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11658
CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.... Read more
Affected Products : ca_api_developer_portal- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11651
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can ... Read more
- Actively Exploited
- Published: Apr. 30, 2020
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2020-11598
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. Upload.ashx allows remote attackers to execute arbitrary code by uploading and executing an ASHX file.... Read more
Affected Products : cipace- Published: Apr. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11597
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP POST request and inject SQL statements in the user context of the db owner.... Read more
Affected Products : cipace- Published: Apr. 06, 2020
- Modified: Nov. 21, 2024