Latest CVE Feed
-
9.8
CRITICALCVE-2020-5214
In NetHack before 3.6.5, detecting an unknown configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability affects systems that have NetHack installed suid/sgid and shared sys... Read more
Affected Products : nethack- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-3071
NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.... Read more
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-3214
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.... Read more
Affected Products : vtiger_crm- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-3215
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.... Read more
Affected Products : vtiger_crm- Published: Jan. 29, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7956
HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.... Read more
Affected Products : nomad- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8440
controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a resume.... Read more
Affected Products : simplejobscript- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8547
phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.... Read more
Affected Products : phplist- Published: Feb. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8591
eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.... Read more
Affected Products : eg_manager- Published: Feb. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8592
eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password feature).... Read more
Affected Products : eg_manager- Published: Feb. 03, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-3072
An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a password to access... Read more
- Published: Nov. 14, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-5686
ZPanel 10.0.1 has insufficient entropy for its password reset process.... Read more
Affected Products : zpanel- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-7052
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script... Read more
- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-10786
network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument.... Read more
Affected Products : network-manager- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8125
Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using klona.... Read more
Affected Products : klona- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-20447
Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint.... Read more
Affected Products : jobberbase- Published: Feb. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-2681
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.... Read more
- Published: Feb. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2012-6306
A vulnerability exists in HCView (aka Hardcoreview) 1.4 due to a write access violation with a GIF file.... Read more
Affected Products : hcview- Published: Feb. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-17268
The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected.... Read more
Affected Products : omniauth-weibo-oauth2- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4335
opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilities... Read more
Affected Products : opopensocialplugin- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-2052
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.... Read more
- Published: Feb. 11, 2020
- Modified: Mar. 31, 2025