87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,051–1,100 of 1,734 in KEV · page 22 of 35
| ID | Title | Summary |
|---|---|---|
| CVE-2020-8243 | Ivanti Pulse Connect Secure Code Execution Vulnerability KEVIvanti | Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom temp… |
| CVE-2020-8218 | Pulse Connect Secure Code Injection Vulnerability KEVPulse Secure | A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web… |
| CVE-2020-8196 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability KEVCitrix | Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability. |
| CVE-2020-8195 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability KEVCitrix | Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability. |
| CVE-2020-8193 | Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability KEVCitrix | Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated acce… |
| CVE-2020-7961 | Liferay Portal Deserialization of Untrusted Data Vulnerability KEVLiferay | Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services. |
| CVE-2020-7796 | Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability KEVSynacor | Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled. |
| CVE-2020-7247 | OpenSMTPD Remote Code Execution Vulnerability KEVOpenBSD | smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafte… |
| CVE-2020-6820 | Mozilla Firefox And Thunderbird Use-After-Free Vulnerability KEVMozilla | Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a us… |
| CVE-2020-6819 | Mozilla Firefox And Thunderbird Use-After-Free Vulnerability KEVMozilla | Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition crea… |
| CVE-2020-6572 | Google Chrome Media Use-After-Free Vulnerability KEVGoogle | Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page. |
| CVE-2020-6418 | Google Chromium V8 Type Confusion Vulnerability KEVGoogle | Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This… |
| CVE-2020-6287 | SAP NetWeaver Missing Authentication for Critical Function Vulnerability KEVSAP | SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execut… |
| CVE-2020-6207 | SAP Solution Manager Missing Authentication for Critical Function Vulnerability KEVSAP | SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of a… |
| CVE-2020-5902 | F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability KEVF5 | F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages. |
| CVE-2020-5849 | Unraid Authentication Bypass Vulnerability KEVUnraid | Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-202… |
| CVE-2020-5847 | Unraid Remote Code Execution Vulnerability KEVUnraid | Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable wi… |
| CVE-2020-5741 | Plex Media Server Remote Code Execution Vulnerability KEVPlex | Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a mal… |
| CVE-2020-5735 | Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability KEVAmcrest | Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the dev… |
| CVE-2020-5722 | Grandstream Networks UCM6200 Series SQL Injection Vulnerability KEVGrandstream | Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root. |
| CVE-2020-5410 | VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability KEVVMware Tanzu | Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files. |
| CVE-2020-5135 | SonicWall SonicOS Buffer Overflow Vulnerability KEVSonicWall | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malici… |
| CVE-2020-4430 | IBM Data Risk Manager Directory Traversal Vulnerability KEVIBM | IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a speciall… |
| CVE-2020-4428 | IBM Data Risk Manager Remote Code Execution Vulnerability KEVIBM | IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.� |
| CVE-2020-4427 | IBM Data Risk Manager Security Bypass Vulnerability KEVIBM | IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML aut… |
| CVE-2020-4006 | Multiple VMware Products Command Injection Vulnerability KEVVMware | VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with net… |
| CVE-2020-3992 | VMware ESXi OpenSLP Use-After-Free Vulnerability KEVCVSS 9.8VMware | VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remot… |
| CVE-2020-3952 | VMware vCenter Server Information Disclosure Vulnerability KEVVMware | VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does… |
| CVE-2020-3950 | VMware Multiple Products Privilege Escalation Vulnerability KEVVMware | VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries th… |
| CVE-2020-3837 | Apple Multiple Products Memory Corruption Vulnerability KEVApple | Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges. |
| CVE-2020-36193 | PEAR Archive_Tar Improper Link Resolution Vulnerability KEVPEAR | PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Appli… |
| CVE-2020-3580 | Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability KEVCVSS 6.1Cisco | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by th… |
| CVE-2020-35730 | Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability KEVRoundcube | Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link ref… |
| CVE-2020-3569 | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability KEVCisco | Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow… |
| CVE-2020-3566 | Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability KEVCisco | Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow… |
| CVE-2020-3452 | Cisco ASA and FTD Read-Only Path Traversal Vulnerability KEVCVSS 7.5Cisco | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. … |
| CVE-2020-3433 | Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability KEVCVSS 7.8Cisco | Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by… |
| CVE-2020-3259 | Cisco ASA and FTD Information Disclosure Vulnerability KEVCVSS 7.5Cisco | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory c… |
| CVE-2020-3161 | Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability KEVCisco | Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root p… |
| CVE-2020-3153 | Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability KEVCVSS 6.5Cisco | Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be ab… |
| CVE-2020-3118 | Cisco IOS XR Software Discovery Protocol Format String Vulnerability KEVCisco | Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent … |
| CVE-2020-29583 | Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability KEVZyxel | Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfw… |
| CVE-2020-29574 | CyberoamOS (CROS) SQL Injection Vulnerability KEVCVSS 9.8Sophos | CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely. |
| CVE-2020-29557 | D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability KEVD-Link | D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution. |
| CVE-2020-28949 | PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability KEVPEAR | PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository a… |
| CVE-2020-2883 | Oracle WebLogic Server Unspecified Vulnerability KEVOracle | Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with net… |
| CVE-2020-27950 | Apple Multiple Products Memory Initialization Vulnerability KEVApple | Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory. |
| CVE-2020-27932 | Apple Multiple Products Type Confusion Vulnerability KEVApple | Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges. |
| CVE-2020-27930 | Apple Multiple Products Memory Corruption Vulnerability KEVApple | Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously craft… |
| CVE-2020-26919 | Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability KEVNETGEAR | Netgear JGS516PE devices contain a missing function level access control vulnerability. |