Search Results (30017 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-7980 1 Intelliantech 1 Aptus Web 2024-11-21 9.8 Critical
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intellian default account might be needed.
CVE-2020-7956 1 Hashicorp 1 Nomad 2024-11-21 9.8 Critical
HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.
CVE-2020-7947 1 Auth0 1 Login By Auth0 2024-11-21 9.8 Critical
An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. It has numerous fields that can contain data that is pulled from different sources. One issue with this is that the data isn't sanitized, and no input validation is performed, before the exporting of the user data. This can lead to (at least) CSV injection if a crafted Excel document is uploaded.
CVE-2020-7941 1 Plone 1 Plone 2024-11-21 9.8 Critical
A privilege escalation issue in plone.app.contenttypes in Plone 4.3 through 5.2.1 allows users to PUT (overwrite) some content without needing write permission.
CVE-2020-7883 2 Microsoft, Wowsoft 2 Windows, Printchaser 2024-11-21 9.8 Critical
Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.
CVE-2020-7878 2 4nb, Microsoft 2 Videooffice, Windows 2024-11-21 9.8 Critical
An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-7878). This issue is due to missing support for integrity check.
CVE-2020-7869 2 Mastersoft, Microsoft 2 Zook, Windows 2024-11-21 9 Critical
An improper input validation vulnerability of ZOOK software (remote administration tool) could allow a remote attacker to create arbitrary file. The ZOOK viewer has the "Tight file CMD" function to create file. An attacker could create and execute arbitrary file in the ZOOK agent program using "Tight file CMD" without authority.
CVE-2020-7868 2 Helpu, Microsoft 2 Helpu, Windows 2024-11-21 9.6 Critical
A remote code execution vulnerability exists in helpUS(remote administration tool) due to improper validation of parameter of ShellExecutionExA function used for login.
CVE-2020-7819 2 Microsoft, Ntracker 2 Windows, Ntracker Usb Enterprise 2024-11-21 9.3 Critical
A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information.
CVE-2020-7805 1 Infomark 4 Iml500, Iml500 Firmware, Iml520 and 1 more 2024-11-21 9.8 Critical
An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This issue is a command injection allowing attackers to execute arbitrary OS commands.
CVE-2020-7794 1 Buns Project 1 Buns 2024-11-21 9.8 Critical
This affects all versions of package buns. The injection point is located in line 678 in index file lib/index.js in the exported function install(requestedModule).
CVE-2020-7786 1 Macfromip Project 1 Macfromip 2024-11-21 9.8 Critical
This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js.
CVE-2020-7785 1 Node-ps Project 1 Node-ps 2024-11-21 9.8 Critical
This affects all versions of package node-ps. The injection point is located in line 72 in lib/index.js.
CVE-2020-7784 1 Ts-process-promises Project 1 Ts-process-promises 2024-11-21 9.8 Critical
This affects all versions of package ts-process-promises. The injection point is located in line 45 in main entry of package in lib/process-promises.js. The vulnerability is demonstrated with the following PoC:
CVE-2020-7782 1 Spritesheet-js Project 1 Spritesheet-js 2024-11-21 9.8 Critical
This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 in lib/generator.js, which is triggered by main entry of the package.
CVE-2020-7781 1 Connection-tester Project 1 Connection-tester 2024-11-21 9.8 Critical
This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:
CVE-2020-7775 1 Freediskspace Project 1 Freediskproject 2024-11-21 9.8 Critical
This affects all versions of package freediskspace. The vulnerability arises out of improper neutralization of arguments in line 71 of freediskspace.js.
CVE-2020-7750 1 Mit 1 Scratch-svg-renderer 2024-11-21 9.6 Critical
This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function.
CVE-2020-7741 1 Hello.js Project 1 Hello.js 2024-11-21 9.9 Critical
This affects the package hellojs before 1.18.6. The code get the param oauth_redirect from url and pass it to location.assign without any check and sanitisation. So we can simply pass some XSS payloads into the url param oauth_redirect, such as javascript:alert(1).
CVE-2020-7730 1 Bestzip Project 1 Bestzip 2024-11-21 9.8 Critical
The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param.