Latest CVE Feed
-
9.8
CRITICALCVE-2018-21054
An issue was discovered on Samsung mobile devices with M(6.0), N(7.x) and O(8.x) except exynos9610/9820 in all Platforms, M(6.0) except MSM8909 SC77xx/9830 exynos3470/5420, N(7.0) except MSM8939, N(7.1) except MSM8996 SDM6xx/M6737T software. There is an i... Read more
Affected Products : android msm8939 msm8909 msm8996 exynos_9820 exynos_9610 exynos_5420 msm9830 exynos_3470 sc7715 +4 more products- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-21058
An issue was discovered on Samsung mobile devices with N(7.0), O(8.0) (exynos7420 or Exynos 8890/8996 chipsets) software. Cache attacks can occur against the Keymaster AES-GCM implementation because T-Tables are used; the Cryptography Extension (CE) is no... Read more
- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-21075
An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. The Call+ application can load classes from an unintended path, leading to Code Execution. The Samsung ID is SVE-2017-10886 (April 2018).... Read more
Affected Products : android- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10631
An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0.2) control.... Read more
Affected Products : webaccess\/nms- Published: Apr. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10383
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated remote code execution in the com_mb24sysapi module.... Read more
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-6195
SAP Business Objects Business Intelligence Platform (CMC), version 4.1, 4.2, shows cleartext password in the response, leading to Information Disclosure. It involves social engineering in order to gain access to system and If password is known, it would g... Read more
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11820
Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the entities_id parameter.... Read more
Affected Products : rukovoditel- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-20730
Certain NETGEAR devices are affected by SQL injection. This affects D3600 before 1.0.0.68, D6000 before 1.0.0.68, D6200 before 1.1.00.28, D6220 before 1.0.0.40, D6400 before 1.0.0.74, D7000 before 1.0.1.60, D7000v2 before 1.0.0.74, D7800 before 1.0.1.34, ... Read more
Affected Products : wndr4500_firmware r7800_firmware d3600_firmware d6000_firmware d6200_firmware d7000_firmware ex8000_firmware jr6150_firmware r6050_firmware r6220_firmware +64 more products- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-20778
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. The Backup subsystem does not properly restrict operations or validate their input. The LG ID is LVE-SMP-190004 (June 2019).... Read more
Affected Products : android- Published: Apr. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-20780
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Certain security settings, related to whether packages are verified and accepted only from known sources, are mishandled. The LG ID is LVE-SMP-190002 (April... Read more
Affected Products : android- Published: Apr. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9277
An issue was discovered on D-Link DSL-2640B B2 EU_4.01B devices. Authentication can be bypassed when accessing cgi modules. This allows one to perform administrative tasks (e.g., modify the admin password) with no authentication.... Read more
- Published: Apr. 20, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-19104
The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application without authenticating by accessing a specific uniform resource locator (URL) , violating the access-control ... Read more
- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-10915
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.4587. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HandshakeResult method. The iss... Read more
Affected Products : one- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11939
In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overflow in concat_hash_string in ssh.c. Due to the granular nature of the overflow primitive and the ability to control ... Read more
Affected Products : ndpi- Published: Apr. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-21134
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects R6700 before 1.0.1.48, R7900 before 1.0.2.16, R6900 before 1.0.1.48, R7000P before 1.3.1.44, R6900P before 1.3.1.44, R6250 before 1.0.4.30, ... Read more
Affected Products : d7000_firmware ex6200_firmware ex7000_firmware r6300_firmware r6700_firmware r6900_firmware r6900p_firmware r7000_firmware r7000p_firmware r6400_firmware +50 more products- Published: Apr. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9294
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the u... Read more
- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-9068
Huawei AR3200 products with versions of V200R007C00SPC900, V200R007C00SPCa00, V200R007C00SPCb00, V200R007C00SPCc00, V200R009C00SPC500 have an improper authentication vulnerability. Attackers need to perform some operations to exploit the vulnerability. Su... Read more
- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7609
node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled by users without any sanitization.... Read more
Affected Products : node-rules- Published: Apr. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12429
Online Course Registration 2.0 has multiple SQL injections that would can lead to a complete database compromise and authentication bypass in the login pages: admin/change-password.php, admin/check_availability.php, admin/index.php, change-password.php, c... Read more
Affected Products : online_course_registration- Published: Apr. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-5622
Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-798: Use of Hard-coded Credentials.... Read more
Affected Products : file_transfer_appliance- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024