Search Results (29910 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-27832 1 Redhat 1 Quay 2024-11-21 9.0 Critical
A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notification. This flaw allows an attacker to trick a user into performing a malicious action to impersonate the target user. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVE-2020-27794 1 Radare 1 Radare2 2024-11-21 9.1 Critical
A double free issue was discovered in radare2 in cmd_info.c:cmd_info(). Successful exploitation could lead to modification of unexpected memory locations and potentially causing a crash.
CVE-2020-27780 1 Linux-pam 1 Linux-pam 2024-11-21 9.8 Critical
A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.
CVE-2020-27745 2 Debian, Schedmd 2 Debian Linux, Slurm 2024-11-21 9.8 Critical
Slurm before 19.05.8 and 20.x before 20.02.6 has an RPC Buffer Overflow in the PMIx MPI plugin.
CVE-2020-27744 1 Westerndigital 6 My Cloud Ex2 Ultra, My Cloud Ex4100, My Cloud Firmware and 3 more 2024-11-21 9.8 Critical
An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privileges.
CVE-2020-27743 1 Pam Tacplus Project 1 Pam Tacplus 2024-11-21 9.8 Critical
libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id.
CVE-2020-27739 1 Citadel 1 Webcit 2024-11-21 9.8 Critical
A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in users' sessions. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread.
CVE-2020-27730 2 F5, Netapp 2 Nginx Controller, Cloud Backup 2024-11-21 9.8 Critical
In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilities.
CVE-2020-27689 1 Imomobile 2 Verve Connect Vh510, Verve Connect Vh510 Firmware 2024-11-21 9.8 Critical
The Relish (Verve Connect) VH510 device with firmware before 1.0.1.6L0516 contains undocumented default admin credentials for the web management interface. A remote attacker could exploit this vulnerability to login and execute commands on the device, as well as upgrade the firmware image to a malicious version.
CVE-2020-27678 3 Illumos, Joyent, Omniosce 3 Illumos, Smartos, Omnios 2024-11-21 9.8 Critical
An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_user_name in lib/libpam/pam_framework.c.
CVE-2020-27664 1 Strapi 1 Strapi 2024-11-21 9.8 Critical
admin/src/containers/InputModalStepperProvider/index.js in Strapi before 3.2.5 has unwanted /proxy?url= functionality.
CVE-2020-27660 1 Synology 1 Safeaccess 2024-11-21 9.6 Critical
SQL injection vulnerability in request.cgi in Synology SafeAccess before 1.2.3-0234 allows remote attackers to execute arbitrary SQL commands via the domain parameter.
CVE-2020-27654 1 Synology 1 Router Manager 2024-11-21 9.8 Critical
Improper access control vulnerability in lbd in Synology Router Manager (SRM) before 1.2.4-8081 allows remote attackers to execute arbitrary commands via port (1) 7786/tcp or (2) 7787/tcp.
CVE-2020-27637 1 R-project 1 Cran 2024-11-21 9.8 Critical
The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the install.packages() function from the interpreter. Update to version 4.0.3
CVE-2020-27636 1 Microchip 1 Mplab Network Creator 2024-11-21 9.1 Critical
In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.
CVE-2020-27635 1 Capgemini 1 Picotcp 2024-11-21 9.1 Critical
In PicoTCP 1.7.0, TCP ISNs are improperly random.
CVE-2020-27634 1 Contiki-ng 1 Contiki-ng 2024-11-21 9.1 Critical
In Contiki 4.5, TCP ISNs are improperly random.
CVE-2020-27633 1 Butok 1 Fnet 2024-11-21 9.1 Critical
In FNET 4.6.3, TCP ISNs are improperly random.
CVE-2020-27631 1 Oryx-embedded 1 Cyclonetcp 2024-11-21 9.8 Critical
In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random.
CVE-2020-27630 1 Silabs 1 Uc\/tcp-ip 2024-11-21 9.8 Critical
In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.