Latest CVE Feed
-
9.8
CRITICALCVE-2020-11105
An issue was discovered in USC iLab cereal through 1.3.0. It employs caching of std::shared_ptr values, using the raw pointer address as a unique identifier. This becomes problematic if an std::shared_ptr variable goes out of scope and is freed, and a new... Read more
Affected Products : cereal- Published: Mar. 30, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11101
Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.... Read more
Affected Products : airlink_mobility_manager- Published: Dec. 26, 2022
- Modified: Apr. 14, 2025
-
9.8
CRITICALCVE-2020-11079
node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This has been fixed in 0.2.1.... Read more
Affected Products : node-dns-sync- Published: May. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10990
An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component.... Read more
Affected Products : mercury- Published: Mar. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-12815
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.... Read more
- Published: Jul. 19, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10938
GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.... Read more
- Published: Mar. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10849
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos7885, Exynos8895, and Exynos9810 chipsets) software. The Gatekeeper trustlet allows a brute-force attack on the screen lock password. The Samsung ID is SVE-2019-1457... Read more
- Published: Mar. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10794
Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to unauthenticated path traversal that allows an attacker to download the application database. This can be combined with CVE-2020-10795 for remote root access.... Read more
- Published: May. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10656
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's WriteWindowMouseWithChunksV2 API. The vulnerability allows an anonymous remote attacker to execute arbitrary ... Read more
Affected Products : insider_threat_management_server- Published: Jan. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10620
Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network access to directly communicate with SoftPAC, including, for example, stopping the service remotely.... Read more
Affected Products : softpac_project- Published: May. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10599
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow a vulnerable ActiveX component to be exploited resulting in a buffer overflow, which may lead to a denial-of-service condition and execution of arbitrary code.... Read more
- Published: Apr. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10611
Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type confusion condition. Authe... Read more
Affected Products : scada_data_gateway- Published: Apr. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10595
pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental prompting by a Kerberos library. It may overflow a buffer provided by the underlying Kerberos library by a single '\0' byte if an attacke... Read more
- Published: Mar. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10582
A SQL injection on the /admin/display_errors.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to execute arbitrary SQL requests (including data reading and modification) on the database.... Read more
Affected Products : automatic_device_management- Published: Mar. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10567
An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate... Read more
Affected Products : responsive_filemanager- Published: Mar. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10335
A vulnerability was found in SourceCodester Garbage Collection Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injectio... Read more
Affected Products : garbage_collection_management_system- Published: Oct. 24, 2024
- Modified: Oct. 28, 2024
-
9.8
CRITICALCVE-2020-10654
Ping Identity PingID SSH before 4.0.14 contains a heap buffer overflow in PingID-enrolled servers. This condition can be potentially exploited into a Remote Code Execution vector on the authenticating endpoint.... Read more
Affected Products : pingid_ssh_integration- Published: May. 13, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10549
rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.... Read more
Affected Products : rconfig- Published: Jun. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10561
An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web management background, resulting in command execution vulnerabilities.... Read more
- Published: Jun. 24, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10574
An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of a typo in the JSON validation.... Read more
Affected Products : janus- Published: Mar. 14, 2020
- Modified: Nov. 21, 2024