| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-2587 | Cri | 0.64 | 9.9 | 0.02 | Jan 15, 2020 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via… | ||
| CVE-2020-2586 | Cri | 0.64 | 9.9 | 0.02 | Jan 15, 2020 | Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via… | ||
| CVE-2020-2555 | Cri | 0.86 | 9.8 | 0.97 | KEV | Jan 15, 2020 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| CVE-2020-2551 | Cri | 0.83 | 9.8 | 0.93 | KEV | Jan 15, 2020 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with… | |
| CVE-2020-2546 | Cri | 0.64 | 9.8 | 0.05 | Jan 15, 2020 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - JavaEE). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access… | ||
| CVE-2015-5952 | Cri | 0.64 | 9.8 | 0.03 | Jan 15, 2020 | Directory traversal vulnerability in Thomson Reuters for FATCA before 5.2 allows remote attackers to execute arbitrary files via the item parameter. | ||
| CVE-2007-4773 | Cri | 0.64 | 9.8 | 0.02 | Jan 15, 2020 | Systrace before 1.6.0 has insufficient escape policy enforcement. | ||
| CVE-2005-4891 | Cri | 0.67 | 9.8 | 0.02 | Jan 15, 2020 | Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements. | ||
| CVE-2015-7874 | Cri | 0.68 | 9.8 | 0.14 | Jan 15, 2020 | Buffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary code via a long nickname. | ||
| CVE-2020-0654 | Cri | 0.59 | 9.1 | 0.03 | Jan 14, 2020 | A security feature bypass vulnerability exists in Microsoft OneDrive App for Android.This could allow an attacker to bypass the passcode or fingerprint requirements of the App.The security update addresses the vulnerability by correcting the way Microsoft OneDrive App for… | ||
| CVE-2020-0646 | Cri | 0.87 | 9.8 | 0.99 | KEV | Jan 14, 2020 | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'. | |
| CVE-2020-0610 | Cri | 0.72 | 9.8 | 0.68 | Jan 14, 2020 | A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution… | ||
| CVE-2020-0609 | Cri | 0.73 | 9.8 | 0.78 | Jan 14, 2020 | A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution… | ||
| CVE-2011-2715 | Cri | 0.64 | 9.8 | 0.01 | Jan 14, 2020 | An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names. | ||
| CVE-2011-3203 | Cri | 0.64 | 9.8 | 0.02 | Jan 14, 2020 | A Code Execution vulnerability exists the attachment parameter to index.php in Jcow CMS 4.x to 4.2 and 5.2 to 5.2. | ||
| CVE-2020-5505 | Cri | 0.67 | 9.8 | 0.44 | Jan 14, 2020 | Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-php"} to the /api/files/ URI. | ||
| CVE-2015-8367 | Cri | 0.64 | 9.8 | 0.06 | Jan 14, 2020 | The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization. | ||
| CVE-2015-8366 | Cri | 0.64 | 9.8 | 0.05 | Jan 14, 2020 | Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execute arbitrary code via vectors related to indexes. | ||
| CVE-2019-0219 | Cri | 0.64 | 9.8 | 0.08 | Jan 14, 2020 | A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI. | ||
| CVE-2020-6958 | Cri | 0.59 | 9.1 | 0.02 | Jan 14, 2020 | An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service. | ||
| CVE-2012-4750 | Cri | 0.67 | 9.8 | 0.09 | Jan 13, 2020 | A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, which could let a remote malicious user execute arbitrary code or cause a Denial of Service | ||
| CVE-2020-6948 | Cri | 0.57 | 9.8 | 0.03 | Jan 13, 2020 | A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call that mishandles the URL, repository, username, and password. | ||
| CVE-2013-6225 | Cri | 0.69 | 9.8 | 0.27 | Jan 13, 2020 | LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability | ||
| CVE-2014-5381 | Cri | 0.67 | 9.8 | 0.07 | Jan 13, 2020 | Grand MA 300 allows a brute-force attack on the PIN. | ||
| CVE-2020-6840 | Cri | 0.64 | 9.8 | 0.02 | Jan 11, 2020 | In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c. | ||
| CVE-2020-6839 | Cri | 0.64 | 9.8 | 0.01 | Jan 11, 2020 | In mruby 2.1.0, there is a stack-based buffer overflow in mrb_str_len_to_dbl in string.c. | ||
| CVE-2020-6838 | Cri | 0.64 | 9.8 | 0.01 | Jan 11, 2020 | In mruby 2.1.0, there is a use-after-free in hash_values_at in mrbgems/mruby-hash-ext/src/hash-ext.c. | ||
| CVE-2020-6836 | Cri | 0.57 | 9.8 | 0.02 | Jan 11, 2020 | grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concatenates them in an eval call. If a value of the formula is taken from… | ||
| CVE-2020-6835 | Cri | 0.64 | 9.8 | 0.02 | Jan 10, 2020 | An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking. | ||
| CVE-2012-4284 | Cri | 0.72 | 9.8 | 0.70 | Jan 10, 2020 | A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary code | ||
| CVE-2011-5020 | Cri | 0.64 | 9.8 | 0.01 | Jan 10, 2020 | An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011. | ||
| CVE-2020-6162 | Cri | 0.59 | 9.1 | 0.02 | Jan 10, 2020 | An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crashes at startup in the hidegroups_init function in dirlist.c. | ||
| CVE-2014-5093 | Cri | 0.67 | 9.8 | 0.04 | Jan 10, 2020 | Status2k does not remove the install directory allowing credential reset. | ||
| CVE-2013-7380 | Cri | 0.64 | 9.8 | 0.02 | Jan 10, 2020 | The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability | ||
| CVE-2014-5081 | Cri | 0.68 | 9.8 | 0.10 | Jan 10, 2020 | sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass | ||
| CVE-2014-4984 | Cri | 0.64 | 9.8 | 0.03 | Jan 10, 2020 | Déjà Vu Crescendo Sales CRM has remote SQL Injection | ||
| CVE-2014-4982 | Cri | 0.64 | 9.8 | 0.05 | Jan 10, 2020 | LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server. | ||
| CVE-2020-6756 | Cri | 0.68 | 9.8 | 0.11 | Jan 9, 2020 | languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter. | ||
| CVE-2019-20374 | Cri | 0.63 | 9.6 | 0.02 | Jan 9, 2020 | A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability is then triggered due to… | ||
| CVE-2012-3807 | Cri | 0.69 | 9.8 | 0.32 | Jan 9, 2020 | Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution. | ||
| CVE-2012-2226 | Cri | 0.67 | 9.8 | 0.07 | Jan 9, 2020 | Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file. | ||
| CVE-2012-2714 | Cri | 0.64 | 9.8 | 0.03 | Jan 9, 2020 | The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier. | ||
| CVE-2012-1259 | Cri | 0.67 | 9.8 | 0.04 | Jan 9, 2020 | Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbitrary SQL commands via the (1) addip parameter to… | ||
| CVE-2019-6330 | Cri | 0.64 | 9.8 | 0.02 | Jan 9, 2020 | A potential security vulnerability has been identified in the software solution HP Access Control versions prior to 16.7. This vulnerability could potentially grant elevation of privilege. | ||
| CVE-2019-4651 | Cri | 0.64 | 9.8 | 0.01 | Jan 9, 2020 | IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170962. | ||
| CVE-2014-3449 | Cri | 0.64 | 9.8 | 0.03 | Jan 9, 2020 | BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability | ||
| CVE-2014-3448 | Cri | 0.64 | 9.8 | 0.04 | Jan 9, 2020 | BSS Continuity CMS 4.2.22640.0 has a Remote Code Execution vulnerability due to unauthenticated file upload | ||
| CVE-2014-2651 | Cri | 0.64 | 9.8 | 0.02 | Jan 9, 2020 | Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface | ||
| CVE-2014-2650 | Cri | 0.64 | 9.8 | 0.03 | Jan 9, 2020 | Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface | ||
| CVE-2011-5266 | Cri | 0.64 | 9.8 | 0.01 | Jan 8, 2020 | Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass. |
- risk 0.64cvss 9.9epss 0.02
Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via…
- risk 0.64cvss 9.9epss 0.02
Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via…
- risk 0.86cvss 9.8epss 0.97
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with…
- risk 0.83cvss 9.8epss 0.93
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with…
- risk 0.64cvss 9.8epss 0.05
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - JavaEE). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access…
- risk 0.64cvss 9.8epss 0.03
Directory traversal vulnerability in Thomson Reuters for FATCA before 5.2 allows remote attackers to execute arbitrary files via the item parameter.
- risk 0.64cvss 9.8epss 0.02
Systrace before 1.6.0 has insufficient escape policy enforcement.
- risk 0.67cvss 9.8epss 0.02
Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements.
- risk 0.68cvss 9.8epss 0.14
Buffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary code via a long nickname.
- risk 0.59cvss 9.1epss 0.03
A security feature bypass vulnerability exists in Microsoft OneDrive App for Android.This could allow an attacker to bypass the passcode or fingerprint requirements of the App.The security update addresses the vulnerability by correcting the way Microsoft OneDrive App for…
- risk 0.87cvss 9.8epss 0.99
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
- risk 0.72cvss 9.8epss 0.68
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution…
- risk 0.73cvss 9.8epss 0.78
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution…
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.
- risk 0.64cvss 9.8epss 0.02
A Code Execution vulnerability exists the attachment parameter to index.php in Jcow CMS 4.x to 4.2 and 5.2 to 5.2.
- risk 0.67cvss 9.8epss 0.44
Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-php"} to the /api/files/ URI.
- risk 0.64cvss 9.8epss 0.06
The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization.
- risk 0.64cvss 9.8epss 0.05
Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execute arbitrary code via vectors related to indexes.
- risk 0.64cvss 9.8epss 0.08
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.
- risk 0.59cvss 9.1epss 0.02
An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.
- risk 0.67cvss 9.8epss 0.09
A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, which could let a remote malicious user execute arbitrary code or cause a Denial of Service
- risk 0.57cvss 9.8epss 0.03
A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call that mishandles the URL, repository, username, and password.
- risk 0.69cvss 9.8epss 0.27
LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability
- risk 0.67cvss 9.8epss 0.07
Grand MA 300 allows a brute-force attack on the PIN.
- risk 0.64cvss 9.8epss 0.02
In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c.
- risk 0.64cvss 9.8epss 0.01
In mruby 2.1.0, there is a stack-based buffer overflow in mrb_str_len_to_dbl in string.c.
- risk 0.64cvss 9.8epss 0.01
In mruby 2.1.0, there is a use-after-free in hash_values_at in mrbgems/mruby-hash-ext/src/hash-ext.c.
- risk 0.57cvss 9.8epss 0.02
grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concatenates them in an eval call. If a value of the formula is taken from…
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking.
- risk 0.72cvss 9.8epss 0.70
A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary code
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011.
- risk 0.59cvss 9.1epss 0.02
An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crashes at startup in the hidegroups_init function in dirlist.c.
- risk 0.67cvss 9.8epss 0.04
Status2k does not remove the install directory allowing credential reset.
- risk 0.64cvss 9.8epss 0.02
The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability
- risk 0.68cvss 9.8epss 0.10
sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
- risk 0.64cvss 9.8epss 0.03
Déjà Vu Crescendo Sales CRM has remote SQL Injection
- risk 0.64cvss 9.8epss 0.05
LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server.
- risk 0.68cvss 9.8epss 0.11
languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter.
- risk 0.63cvss 9.6epss 0.02
A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability is then triggered due to…
- risk 0.69cvss 9.8epss 0.32
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution.
- risk 0.67cvss 9.8epss 0.07
Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.
- risk 0.64cvss 9.8epss 0.03
The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier.
- risk 0.67cvss 9.8epss 0.04
Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbitrary SQL commands via the (1) addip parameter to…
- risk 0.64cvss 9.8epss 0.02
A potential security vulnerability has been identified in the software solution HP Access Control versions prior to 16.7. This vulnerability could potentially grant elevation of privilege.
- risk 0.64cvss 9.8epss 0.01
IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170962.
- risk 0.64cvss 9.8epss 0.03
BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability
- risk 0.64cvss 9.8epss 0.04
BSS Continuity CMS 4.2.22640.0 has a Remote Code Execution vulnerability due to unauthenticated file upload
- risk 0.64cvss 9.8epss 0.02
Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface
- risk 0.64cvss 9.8epss 0.03
Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface
- risk 0.64cvss 9.8epss 0.01
Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.