Latest CVE Feed
-
9.8
CRITICALCVE-2020-10287
The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well documented functionality that helps customer set up however, out of our research, we found multiple produ... Read more
- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10074
GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link.... Read more
Affected Products : gitlab- Published: Mar. 13, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10064
Improper Input Frame Validation in ieee802154 Processing. Zephyr versions >= v1.14.2, >= v2.2.0 contain Stack-based Buffer Overflow (CWE-121), Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/sec... Read more
Affected Products : zephyr- Published: May. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10070
In the Zephyr Project MQTT code, improper bounds checking can result in memory corruption and possibly remote code execution. NCC-ZEP-031 This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions.... Read more
Affected Products : zephyr- Published: Jun. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10022
A malformed JSON payload that is received from an UpdateHub server may trigger memory corruption in the Zephyr OS. This could result in a denial of service in the best case, or code execution in the worst case. See NCC-NCC-016 This issue affects: zephyrpr... Read more
Affected Products : zephyr- Published: May. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10284
The CE21 Suite plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.2.0. This is due to hardcoded encryption key in the 'ce21_authentication_phrase' function. This makes it possible for unauthenticated attackers ... Read more
Affected Products : ce21_suite- Published: Nov. 09, 2024
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2020-10018
WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memory han... Read more
- Published: Mar. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-0902
An elevation of privilege vulnerability exists in Service Fabric File Store Service under certain conditions, aka 'Service Fabric Elevation of Privilege'.... Read more
Affected Products : service_fabric- Published: Mar. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-10279
A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. This vulnerability affects unknown code of the file /com/esafenet/servlet/policy/PrintPolicyService.java. The manipulation of the argument policyId leads to sql injection. The ... Read more
Affected Products : cdg- Published: Oct. 23, 2024
- Modified: Nov. 04, 2024
-
9.8
CRITICALCVE-2024-10244
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ISDO Software Web Software allows SQL Injection.This issue affects Web Software: before 3.6.... Read more
Affected Products :- Published: Dec. 19, 2024
- Modified: Dec. 19, 2024
-
9.8
CRITICALCVE-2005-3056
TWiki allows arbitrary shell command execution via the Include function... Read more
Affected Products : twiki- Published: Nov. 01, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-0594
Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access.... Read more
- Published: Jun. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10825
A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 3 of 3).... Read more
Affected Products : vigor2960_firmware vigor300b_firmware vigor3900_firmware vigor2960 vigor300b vigor3900- Published: Mar. 26, 2020
- Modified: May. 05, 2025
-
9.8
CRITICALCVE-2020-0456
There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170378843... Read more
Affected Products : android- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-0455
There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170372514... Read more
Affected Products : android- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-0445
There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-168264527... Read more
Affected Products : android- Published: Nov. 10, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-0452
In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileg... Read more
- Published: Nov. 10, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2005-2354
Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues.... Read more
Affected Products : nvu- Published: Nov. 05, 2019
- Modified: Nov. 20, 2024
-
9.8
CRITICALCVE-2020-0354
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android... Read more
Affected Products : android- Published: Sep. 18, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-0471
In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetooth connection due to improper input validation. This could lead to remote escalation of privilege between two Bluetooth devices by a pro... Read more
Affected Products : android- Published: Jan. 11, 2021
- Modified: Nov. 21, 2024