87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,051–1,100 of 1,734 in KEV · page 22 of 35

IDTitleSummary
CVE-2020-8243Ivanti Pulse Connect Secure Code Execution Vulnerability
KEVIvanti
Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom temp…
CVE-2020-8218Pulse Connect Secure Code Injection Vulnerability
KEVPulse Secure
A code injection vulnerability exists in Pulse Connect Secure that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web…
CVE-2020-8196Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
KEVCitrix
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.
CVE-2020-8195Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability
KEVCitrix
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability.
CVE-2020-8193Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability
KEVCitrix
Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an authorization bypass vulnerability that may allow unauthenticated acce…
CVE-2020-7961Liferay Portal Deserialization of Untrusted Data Vulnerability
KEVLiferay
Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.
CVE-2020-7796Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability
KEVSynacor
Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled.
CVE-2020-7247OpenSMTPD Remote Code Execution Vulnerability
KEVOpenBSD
smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafte…
CVE-2020-6820Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
KEVMozilla
Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a us…
CVE-2020-6819Mozilla Firefox And Thunderbird Use-After-Free Vulnerability
KEVMozilla
Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition crea…
CVE-2020-6572Google Chrome Media Use-After-Free Vulnerability
KEVGoogle
Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.
CVE-2020-6418Google Chromium V8 Type Confusion Vulnerability
KEVGoogle
Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This…
CVE-2020-6287SAP NetWeaver Missing Authentication for Critical Function Vulnerability
KEVSAP
SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execut…
CVE-2020-6207SAP Solution Manager Missing Authentication for Critical Function Vulnerability
KEVSAP
SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of a…
CVE-2020-5902F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability
KEVF5
F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages.
CVE-2020-5849Unraid Authentication Bypass Vulnerability
KEVUnraid
Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-202…
CVE-2020-5847Unraid Remote Code Execution Vulnerability
KEVUnraid
Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable wi…
CVE-2020-5741Plex Media Server Remote Code Execution Vulnerability
KEVPlex
Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a mal…
CVE-2020-5735Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability
KEVAmcrest
Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the dev…
CVE-2020-5722Grandstream Networks UCM6200 Series SQL Injection Vulnerability
KEVGrandstream
Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request. Exploitation can allow for code execution as root.
CVE-2020-5410VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability
KEVVMware Tanzu
Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.
CVE-2020-5135SonicWall SonicOS Buffer Overflow Vulnerability
KEVSonicWall
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code by sending a malici…
CVE-2020-4430IBM Data Risk Manager Directory Traversal Vulnerability
KEVIBM
IBM Data Risk Manager contains a directory traversal vulnerability that could allow a remote authenticated attacker to traverse directories and send a speciall…
CVE-2020-4428IBM Data Risk Manager Remote Code Execution Vulnerability
KEVIBM
IBM Data Risk Manager contains an unspecified vulnerability which could allow a remote, authenticated attacker to execute commands on the system.�
CVE-2020-4427IBM Data Risk Manager Security Bypass Vulnerability
KEVIBM
IBM Data Risk Manager contains a security bypass vulnerability that could allow a remote attacker to bypass security restrictions when configured with SAML aut…
CVE-2020-4006Multiple VMware Products Command Injection Vulnerability
KEVVMware
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector contain a command injection vulnerability. An attacker with net…
CVE-2020-3992VMware ESXi OpenSLP Use-After-Free Vulnerability
KEVCVSS 9.8VMware
VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remot…
CVE-2020-3952VMware vCenter Server Information Disclosure Vulnerability
KEVVMware
VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does…
CVE-2020-3950VMware Multiple Products Privilege Escalation Vulnerability
KEVVMware
VMware Fusion, Remote Console (VMRC) for Mac, and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries th…
CVE-2020-3837Apple Multiple Products Memory Corruption Vulnerability
KEVApple
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability that could allow an application to execute code with kernel privileges.
CVE-2020-36193PEAR Archive_Tar Improper Link Resolution Vulnerability
KEVPEAR
PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Appli…
CVE-2020-3580Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability
KEVCVSS 6.1Cisco
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by th…
CVE-2020-35730Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
KEVRoundcube
Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows an attacker to send a plain text e-mail message with Javascript in a link ref…
CVE-2020-3569Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
KEVCisco
Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow…
CVE-2020-3566Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability
KEVCisco
Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow…
CVE-2020-3452Cisco ASA and FTD Read-Only Path Traversal Vulnerability
KEVCVSS 7.5Cisco
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs. …
CVE-2020-3433Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
KEVCVSS 7.8Cisco
Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by…
CVE-2020-3259Cisco ASA and FTD Information Disclosure Vulnerability
KEVCVSS 7.5Cisco
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory c…
CVE-2020-3161Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
KEVCisco
Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root p…
CVE-2020-3153Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
KEVCVSS 6.5Cisco
Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be ab…
CVE-2020-3118Cisco IOS XR Software Discovery Protocol Format String Vulnerability
KEVCisco
Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent …
CVE-2020-29583Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability
KEVZyxel
Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfw…
CVE-2020-29574CyberoamOS (CROS) SQL Injection Vulnerability
KEVCVSS 9.8Sophos
CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.
CVE-2020-29557D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability
KEVD-Link
D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution.
CVE-2020-28949PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability
KEVPEAR
PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository a…
CVE-2020-2883Oracle WebLogic Server Unspecified Vulnerability
KEVOracle
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with net…
CVE-2020-27950Apple Multiple Products Memory Initialization Vulnerability
KEVApple
Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory.
CVE-2020-27932Apple Multiple Products Type Confusion Vulnerability
KEVApple
Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel privileges.
CVE-2020-27930Apple Multiple Products Memory Corruption Vulnerability
KEVApple
Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously craft…
CVE-2020-26919Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability
KEVNETGEAR
Netgear JGS516PE devices contain a missing function level access control vulnerability.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.