Latest CVE Feed
-
9.8
CRITICALCVE-2020-9068
Huawei AR3200 products with versions of V200R007C00SPC900, V200R007C00SPCa00, V200R007C00SPCb00, V200R007C00SPCc00, V200R009C00SPC500 have an improper authentication vulnerability. Attackers need to perform some operations to exploit the vulnerability. Su... Read more
- EPSS Score: %0.16
- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7609
node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled by users without any sanitization.... Read more
Affected Products : node-rules- EPSS Score: %0.42
- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12429
Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and authentication bypass in the login pages: admin/change-password.php, admin/check_availability.php, admin/index.php, change-password.php, c... Read more
Affected Products : online_course_registration- EPSS Score: %0.54
- Published: Apr. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-5622
Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-798: Use of Hard-coded Credentials.... Read more
Affected Products : file_transfer_appliance- EPSS Score: %0.35
- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12627
Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key.... Read more
- EPSS Score: %0.38
- Published: May. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-1961
Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL expressions, leading to Remote Code Execution (RCE) was discove... Read more
Affected Products : syncope- EPSS Score: %7.13
- Published: May. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8790
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication attempts, which could allow a remote attacker to discover user credentials an... Read more
Affected Products : oklok- EPSS Score: %1.04
- Published: May. 04, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12735
reset.php in DomainMOD 4.13.0 uses insufficient entropy for password reset requests, leading to account takeover.... Read more
Affected Products : domainmod- EPSS Score: %0.54
- Published: May. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12006
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to overwrite files outside the application’s control.... Read more
Affected Products : webaccess- EPSS Score: %5.03
- Published: May. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12753
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 software. Arbitrary code execution can occur via the bootloader because of an EL1/EL3 coldboot vulnerability involving raw_resources. The LG ID is LVE-SMP-200006 (May 20... Read more
Affected Products : android- EPSS Score: %3.90
- Published: May. 11, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-17562
A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all versions prior to 4.13.1. The vulnerability is due to the lack of validation of the mac parameter in baremetal virtual router. If you inser... Read more
Affected Products : cloudstack- EPSS Score: %1.90
- Published: May. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-0221
Airbrush FW's scratch memory allocator is susceptible to numeric overflow. When the overflow occurs, the next allocation could potentially return a pointer within the previous allocation's memory, which could lead to improper memory access.Product: Androi... Read more
Affected Products : android- EPSS Score: %0.15
- Published: May. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-13091
pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the read_pickle() function is documented a... Read more
Affected Products : pandas- EPSS Score: %0.81
- Published: May. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8434
Jenzabar JICS (aka Internet Campus Solution) before 9.0.1 Patch 3, 9.1 before 9.1.2 Patch 2, and 9.2 before 9.2.2 Patch 8 has session cookies that are a deterministic function of the username. There is a hard-coded password to supply a PBKDF feeding into ... Read more
Affected Products : internet_campus_solution- EPSS Score: %0.28
- Published: May. 19, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-6091
An exploitable authentication bypass vulnerability exists in the ESPON Web Control functionality of Epson EB-1470Ui MAIN: 98009273ESWWV107 MAIN2: 8X7325WWV303. A specially crafted series of HTTP requests can cause authentication bypass resulting in inform... Read more
- EPSS Score: %0.35
- Published: May. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-5537
Cybozu Desktop for Windows 2.0.23 to 2.2.40 allows remote code execution via unspecified vectors.... Read more
Affected Products : desktop- EPSS Score: %3.26
- Published: May. 25, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-8171
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:There are certain end-points containi... Read more
Affected Products : airos ag-hp-2g16 ag-hp-2g20 ag-hp-5g23 ag-hp-5g27 airgrid_m airgrid_m2 airgrid_m5 ar ar-hp +41 more products- EPSS Score: %6.93
- Published: May. 26, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-6242
SAP Business Objects Business Intelligence Platform (Live Data Connect), versions 1.0, 2.0, 2.1, 2.2, 2.3, allows an attacker to logon on the Central Management Console without password in case of the BIPRWS application server was not protected with some ... Read more
Affected Products : businessobjects_business_intelligence_platform- EPSS Score: %0.23
- Published: May. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-8941
Lexiglot through 2014-11-20 allows SQL injection via an admin.php?page=users&from_id= or admin.php?page=history&limit= URI.... Read more
Affected Products : lexiglot- EPSS Score: %0.26
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-8945
admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.... Read more
Affected Products : lexiglot- EPSS Score: %17.76
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024