87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,101–1,150 of 1,734 in KEV · page 23 of 35

IDTitleSummary
CVE-2020-2555Oracle Multiple Products Remote Code Execution Vulnerability
KEVOracle
Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover t…
CVE-2020-2551Oracle Fusion Middleware Unspecified Vulnerability
KEVOracle
Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP …
CVE-2020-25506D-Link DNS-320 Device Command Injection Vulnerability
KEVD-Link
D-Link DNS-320 device contains a command injection vulnerability in the sytem_mgr.cgi component that may allow for remote code execution.
CVE-2020-25223Sophos SG UTM Remote Code Execution Vulnerability
KEVSophos
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.
CVE-2020-25213WordPress File Manager Plugin Remote Code Execution Vulnerability
KEVWordPress
WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files o…
CVE-2020-2509QNAP Network-Attached Storage (NAS) Command Injection Vulnerability
KEVQNAP
QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.
CVE-2020-25079D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
KEVD-Link
D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL)…
CVE-2020-25078D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability
KEVD-Link
D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted produc…
CVE-2020-2506QNAP Helpdesk Improper Access Control Vulnerability
KEVQNAP Systems
QNAP Helpdesk contains an improper access control vulnerability which could allow an attacker to gain privileges or to read sensitive information.
CVE-2020-24557Trend Micro Multiple Products Improper Access Control Vulnerability
KEVTrend Micro
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an atta…
CVE-2020-24363TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability
KEVTP-Link
TP-link TL-WA855RE contains a missing authentication for critical function vulnerability. This vulnerability could allow an unauthenticated attacker (on the sa…
CVE-2020-2021Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
KEVPalo Alto Networks
Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.
CVE-2020-1956Apache Kylin OS Command Injection Vulnerability
KEVApache
Apache Kylin contains an OS command injection vulnerability which could permit an attacker to perform remote code execution.
CVE-2020-1938Apache Tomcat Improper Privilege Management Vulnerability
KEVCVSS 9.8Apache
Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are avail…
CVE-2020-17530Apache Struts Remote Code Execution Vulnerability
KEVApache
Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluated on raw user input in tag attributes, can lead to remote code executi…
CVE-2020-17519Apache Flink Improper Access Control Vulnerability
KEVApache
Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its R…
CVE-2020-17496vBulletin PHP Module Remote Code Execution Vulnerability
KEVvBulletin
The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widge…
CVE-2020-17463Fuel CMS SQL Injection Vulnerability
KEVFuel CMS
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
CVE-2020-17144Microsoft Exchange Server Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft Exchange Server improperly validates cmdlet arguments which allow an attacker to perform remote code execution.
CVE-2020-17087Microsoft Windows Kernel Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
CVE-2020-16846SaltStack Salt Shell Injection Vulnerability
KEVSaltStack
SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. Thi…
CVE-2020-1631Juniper Junos OS Path Traversal Vulnerability
KEVJuniper
A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-R…
CVE-2020-16017Google Chrome Use-After-Free Vulnerability
KEVGoogle
Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox…
CVE-2020-16013Google Chromium V8 Incorrect Implementation Vulnerabililty
KEVGoogle
Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a cra…
CVE-2020-16010Google Chrome for Android UI Heap Buffer Overflow Vulnerability
KEVGoogle
Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentia…
CVE-2020-16009Google Chromium V8 Type Confusion Vulnerability
KEVGoogle
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.…
CVE-2020-15999Google Chrome FreeType Heap Buffer Overflow Vulnerability
KEVGoogle
Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png…
CVE-2020-15505Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability
KEVIvanti
Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote cod…
CVE-2020-15415DrayTek Multiple Vigor Routers OS Command Injection Vulnerability
KEVDrayTek
DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remo…
CVE-2020-15069Sophos XG Firewall Buffer Overflow Vulnerability
KEVSophos
Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.
CVE-2020-14883Oracle WebLogic Server Unspecified Vulnerability
KEVOracle
Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.
CVE-2020-14882Oracle WebLogic Server Remote Code Execution Vulnerability
KEVOracle
Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related t…
CVE-2020-14871Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability
KEVOracle
Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability o…
CVE-2020-14864Oracle Business Intelligence Enterprise Edition Path Transversal
KEVOracle
Path traversal vulnerability, where an attacker can target the preview FilePath parameter of the getPreviewImage function to get access to arbitrary system fil…
CVE-2020-14750Oracle WebLogic Server Remote Code Execution Vulnerability
KEVOracle
Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is relat…
CVE-2020-1472Microsoft Netlogon Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel …
CVE-2020-14644Oracle WebLogic Server Remote Code Execution Vulnerability
KEVOracle
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access v…
CVE-2020-1464Microsoft Windows Spoofing Vulnerability
KEVMicrosoft
Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and lo…
CVE-2020-13965Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability
KEVRoundcube
Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment.
CVE-2020-13927Apache Airflow's Experimental API Authentication Bypass
KEVApache
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.
CVE-2020-1380Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.
CVE-2020-13671Drupal core Un-restricted Upload of File
KEVDrupal
Improper sanitization in the extension file names is present in Drupal core.
CVE-2020-1350Microsoft Windows DNS Server Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Accoun…
CVE-2020-12812Fortinet FortiOS SSL VPN Improper Authentication Vulnerability
KEVCVSS 9.8Fortinet
Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second fa…
CVE-2020-12641Roundcube Webmail Remote Code Execution Vulnerability
KEVRoundcube
Roundcube Webmail contains an remote code execution vulnerability that allows attackers to execute code via shell metacharacters in a configuration setting for…
CVE-2020-12271Sophos SFOS SQL Injection Vulnerability
KEVSophos
Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the U…
CVE-2020-11978Apache Airflow Command Injection
KEVApache
A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.
CVE-2020-11899Treck TCP/IP stack Out-of-Bounds Read Vulnerability
KEVTreck TCP/IP stack
The Treck TCP/IP stack contains an IPv6 out-of-bounds read vulnerability.
CVE-2020-11738WordPress Snap Creek Duplicator Plugin File Download Vulnerability
KEVWordPress
WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to…
CVE-2020-11652SaltStack Salt Path Traversal Vulnerability
KEVSaltStack
SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users w…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.