Latest CVE Feed
-
9.8
CRITICALCVE-2020-11816
Rukovoditel 2.5.2 is affected by a SQL injection vulnerability because of improper handling of the reports_id (POST) parameter.... Read more
Affected Products : rukovoditel- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-6580
A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), Siveillance VMS 2018 R2 (All versions < V12.2a), Siveillance VMS 2018 R3 (All versions < V12.3a), Siveillance VMS 2019... Read more
- Published: Jun. 12, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-20100
An issue was discovered on August Connect devices. Insecure data transfer between the August app and August Connect during configuration allows attackers to discover home Wi-Fi credentials. This data transfer uses an unencrypted access point for these cre... Read more
- Published: Jan. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12338
Insufficient control flow management in the Open WebRTC Toolkit before version 4.3.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access.... Read more
Affected Products : open_webrtc_toolkit- Published: Nov. 13, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-6503
There is a deserialization vulnerability in Chatopera cosin v3.10.0. An attacker can execute commands during server-side deserialization by uploading maliciously constructed files. This is related to the TemplateController.java impsave method and the Main... Read more
Affected Products : cosin- Published: Jan. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12442
Ivanti Avalanche 6.3 allows a SQL injection that is vaguely associated with the Apache HTTP Server, aka Bug 683250.... Read more
Affected Products : avalanche- Published: Apr. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-7249
In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and would also allow one user of the system (who didn't have root access) to tamper with another's installs.... Read more
Affected Products : keybase- Published: Jan. 31, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8352
By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sent over the network to managed PATROL Agent services. If an attacker were able to capture this network traffic, they could decrypt these... Read more
Affected Products : patrol_agent- Published: May. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7224
The Aviatrix OpenVPN client through 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load.... Read more
- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7628
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.... Read more
- Published: Apr. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7645
All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating systems.... Read more
Affected Products : chrome-launcher- Published: May. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-13921
**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.... Read more
Affected Products : skywalking- Published: Aug. 05, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7702
All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.... Read more
Affected Products : templ8- Published: Aug. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7703
All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.... Read more
Affected Products : nis-utils- Published: Aug. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8908
An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" screen, and uploading an image file, as demonstrated by a .php filename and th... Read more
Affected Products : wtcms- Published: Feb. 18, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7698
This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endpoint, isn’t being sanitized.... Read more
Affected Products : gerapy- Published: Jul. 29, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8948
PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.... Read more
- Published: Feb. 20, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7715
All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.... Read more
Affected Products : deep-get-set- Published: Sep. 01, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-8985
On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code executio... Read more
- Published: Feb. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-7781
This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:... Read more
Affected Products : connection-tester- Published: Dec. 16, 2020
- Modified: Nov. 21, 2024