87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,151–1,200 of 1,734 in KEV · page 24 of 35

IDTitleSummary
CVE-2020-11651SaltStack Salt Authentication Bypass Vulnerability
KEVSaltStack
SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerabili…
CVE-2020-1147Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source mar…
CVE-2020-11261Qualcomm Multiple Chipsets Improper Input Validation Vulnerability
KEVQualcomm
Memory corruption due to improper check to return error when user application requests memory allocation of a huge size in Snapdragon Auto, Snapdragon Compute,…
CVE-2020-11023JQuery Cross-Site Scripting (XSS) Vulnerability
KEVJQuery
JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM man…
CVE-2020-10987Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
KEVTenda
Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter.
CVE-2020-1054Microsoft Win32k Privilege Escalation Vulnerability
KEVCVSS 7.0Microsoft
Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful explo…
CVE-2020-1040Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authentic…
CVE-2020-1027Microsoft Windows Kernel Privilege Escalation Vulnerability
KEVMicrosoft
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnera…
CVE-2020-10221rConfig OS Command Injection Vulnerability
KEVrConfig
rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metac…
CVE-2020-1020Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript …
CVE-2020-10199Sonatype Nexus Repository Remote Code Execution Vulnerability
KEVSonatype
Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution.
CVE-2020-10189Zoho ManageEngine Desktop Central File Upload Vulnerability
KEVZoho
Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution.
CVE-2020-10181Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability
KEVSumavision
Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges …
CVE-2020-10148SolarWinds Orion Authentication Bypass Vulnerability
KEVSolarWinds
SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.
CVE-2020-0986Microsoft Windows Kernel Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Windows kernel contains an unspecified vulnerability when handling objects in memory that allows attackers to escalate privileges and execute code in…
CVE-2020-0968Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execut…
CVE-2020-0938Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript …
CVE-2020-0878Microsoft Edge and Internet Explorer Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.
CVE-2020-0796Microsoft SMBv3 Remote Code Execution Vulnerability
KEVCVSS 10.0Microsoft
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker wh…
CVE-2020-0787Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability…
CVE-2020-0688Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.
CVE-2020-0683Microsoft Windows Installer Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access res…
CVE-2020-0674Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation c…
CVE-2020-0646Microsoft .NET Framework Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution.
CVE-2020-0638Microsoft Update Notification Manager Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.
CVE-2020-0618Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability
KEVCVSS 8.8Microsoft
Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit…
CVE-2020-0601Microsoft Windows CryptoAPI Spoofing Vulnerability
KEVMicrosoft
Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker…
CVE-2020-0069Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability
KEVMediaTek
Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl hand…
CVE-2020-0041Android Kernel Out-of-Bounds Write Vulnerability
KEVAndroid
Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privile…
CVE-2019-9978WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability
KEVWordPress
WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Wa…
CVE-2019-9875Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
KEVSitecore
Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacke…
CVE-2019-9874Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability
KEVSitecore
Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attac…
CVE-2019-9670Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference
KEVSynacor
Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.
CVE-2019-9621Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability
KEVSynacor
Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.
CVE-2019-9082ThinkPHP Remote Code Execution Vulnerability
KEVThinkPHP
ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_arr…
CVE-2019-8720WebKitGTK Memory Corruption Vulnerability
KEVWebKitGTK
WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution.
CVE-2019-8605Apple Multiple Products Use-After-Free Vulnerability
KEVApple
A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malicious application to execute code with system privileges.
CVE-2019-8526Apple macOS Use-After-Free Vulnerability
KEVApple
Apple macOS contains a use-after-free vulnerability that could allow for privilege escalation.
CVE-2019-8506Apple Multiple Products Type Confusion Vulnerability
KEVApple
A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
CVE-2019-8394Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
KEVZoho
Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.
CVE-2019-7609Kibana Arbitrary Code Execution
KEVElastic
Kibana contain an arbitrary code execution flaw in the Timelion visualizer.
CVE-2019-7483SonicWall SMA100 Directory Traversal Vulnerability
KEVSonicWall
In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on th…
CVE-2019-7481SonicWall SMA100 SQL Injection Vulnerability
KEVCVSS 7.5SonicWall
SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.
CVE-2019-7287Apple iOS Memory Corruption Vulnerability
KEVApple
Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution.
CVE-2019-7286Apple Multiple Products Memory Corruption Vulnerability
KEVApple
Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation.
CVE-2019-7256Nice Linear eMerge E3-Series OS Command Injection Vulnerability
KEVNice
Nice Linear eMerge E3-Series contains an OS command injection vulnerability that allows an attacker to conduct remote code execution.
CVE-2019-7238Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability
KEVSonatype
Sonatype Nexus Repository Manager before 3.15.0 has an incorrect access control vulnerability. Exploitation allows for remote code execution.
CVE-2019-7195QNAP Photo Station Path Traversal Vulnerability
KEVQNAP
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.
CVE-2019-7194QNAP Photo Station Path Traversal Vulnerability
KEVQNAP
QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.
CVE-2019-7193QNAP QTS Improper Input Validation Vulnerability
KEVQNAP
QNAP QTS contains an improper input validation vulnerability allowing remote attackers to inject code on the system.
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.