Latest CVE Feed
-
9.8
CRITICALCVE-2020-7999
The Intellian Aptus application 1.0.2 for Android has hardcoded values for DOWNLOAD_API_KEY and FILE_DOWNLOAD_API_KEY.... Read more
Affected Products : aptus- EPSS Score: %0.36
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19825
On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"} POST to the boafrm/formLogin URI, leading to a CAPTCHA bypass. (Also, the CAPTCHA text is not needed once the attacker has determined ... Read more
Affected Products : n150rt_firmware n300rt_firmware n200re_firmware a3002ru_firmware a702r_firmware n301rt_firmware n302r_firmware n100re_firmware n200re a3002ru +6 more products- EPSS Score: %0.62
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-3445
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash.... Read more
Affected Products : sos_webpages- EPSS Score: %4.02
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4864
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side Request Forgery (SSRF) issue.... Read more
- EPSS Score: %30.46
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-5214
In NetHack before 3.6.5, detecting an unknown configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared sys... Read more
Affected Products : nethack- EPSS Score: %1.84
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-3071
NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.... Read more
- EPSS Score: %1.24
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-3214
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.... Read more
Affected Products : vtiger_crm- EPSS Score: %89.07
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-3215
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.... Read more
Affected Products : vtiger_crm- EPSS Score: %73.67
- Published: Jan. 29, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7956
HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.... Read more
Affected Products : nomad- EPSS Score: %0.24
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8440
controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a resume.... Read more
Affected Products : simplejobscript- EPSS Score: %3.28
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8547
phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.... Read more
Affected Products : phplist- EPSS Score: %3.29
- Published: Feb. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8591
eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.... Read more
Affected Products : eg_manager- EPSS Score: %0.14
- Published: Feb. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8592
eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password feature).... Read more
Affected Products : eg_manager- EPSS Score: %0.31
- Published: Feb. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-3072
An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a password to access... Read more
- EPSS Score: %1.58
- Published: Nov. 14, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-5686
ZPanel 10.0.1 has insufficient entropy for its password reset process.... Read more
Affected Products : zpanel- EPSS Score: %14.44
- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-7052
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script... Read more
- EPSS Score: %42.70
- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10786
network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument.... Read more
Affected Products : network-manager- EPSS Score: %1.36
- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8125
Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using klona.... Read more
Affected Products : klona- EPSS Score: %1.07
- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-20447
Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint.... Read more
Affected Products : jobberbase- EPSS Score: %0.31
- Published: Feb. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2681
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.... Read more
- EPSS Score: %43.17
- Published: Feb. 05, 2020
- Modified: Nov. 21, 2024