Export limit exceeded: 103014 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (103014 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-8004 | 1 St | 2 Stm32f1, Stm32f1 Firmware | 2024-11-21 | 7.5 High |
| STMicroelectronics STM32F1 devices have Incorrect Access Control. | ||||
| CVE-2020-7998 | 1 Super File Explorer Project | 1 Super File Explorer | 2024-11-21 | 8.8 High |
| An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default, there is no password set for the FTP or Web UI service. | ||||
| CVE-2020-7991 | 1 Adive | 1 Framework | 2024-11-21 | 8.8 High |
| Adive Framework 2.0.8 has admin/config CSRF to change the Administrator password. | ||||
| CVE-2020-7988 | 1 Phpipam | 1 Phpipam | 2024-11-21 | 8.8 High |
| An issue was discovered in tools/pass-change/result.php in phpIPAM 1.4. CSRF can be used to change the password of any user/admin, to escalate privileges, and to gain access to more data and functionality. This issue exists due to the lack of a requirement to provide the old password, and the lack of security tokens. | ||||
| CVE-2020-7984 | 1 Solarwinds | 1 N-central | 2024-11-21 | 7.5 High |
| SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information. The attacker can use a customer ID to self register and read any aspects of the agent/appliance configuration. | ||||
| CVE-2020-7983 | 1 Commscope | 2 Ruckus Zoneflex R500, Ruckus Zoneflex R500 Firmware | 2024-11-21 | 8.1 High |
| A CSRF issue in login.asp on Ruckus R500 3.4.2.0.384 devices allows remote attackers to access the panel or conduct SSRF attacks. | ||||
| CVE-2020-7982 | 1 Openwrt | 2 Lede, Openwrt | 2024-11-21 | 8.1 High |
| An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before 2020-01-25 prevents correct parsing of embedded checksums in the signed repository index, allowing a man-in-the-middle attacker to inject arbitrary package payloads (which are installed without verification). | ||||
| CVE-2020-7978 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.5 High |
| GitLab EE 12.6 and later through 12.7.2 allows Denial of Service. | ||||
| CVE-2020-7972 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.5 High |
| GitLab EE 12.2 has Insecure Permissions (issue 2 of 2). | ||||
| CVE-2020-7969 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.5 High |
| GitLab EE 8.0 and later through 12.7.2 allows Information Disclosure. | ||||
| CVE-2020-7968 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.5 High |
| GitLab EE 8.0 through 12.7.2 has Incorrect Access Control. | ||||
| CVE-2020-7966 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.5 High |
| GitLab EE 11.11 and later through 12.7.2 allows Directory Traversal. | ||||
| CVE-2020-7965 | 1 Webargs Project | 1 Webargs | 2024-11-21 | 8.8 High |
| flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request body is valid JSON, it will accept it even if the content type is application/x-www-form-urlencoded. This allows for JSON POST requests to be made across domains, leading to CSRF. | ||||
| CVE-2020-7954 | 1 Opservices | 1 Opmon | 2024-11-21 | 7.8 High |
| An issue was discovered in OpServices OpMon 9.3.2. Starting from the apache user account, it is possible to perform privilege escalation through the lack of correct configuration in the server's sudoers file, which by default allows the execution of programs (e.g. nmap) without the need for a password with sudo. | ||||
| CVE-2020-7953 | 1 Opservices | 1 Opmon | 2024-11-21 | 7.5 High |
| An issue was discovered in OpServices OpMon 9.3.2. Without authentication, it is possible to read server files (e.g., /etc/passwd) due to the use of the nmap -iL (aka input file) option. | ||||
| CVE-2020-7952 | 1 Valvesoftware | 1 Dota 2 | 2024-11-21 | 7.8 High |
| rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is affected by memory corruption. | ||||
| CVE-2020-7951 | 1 Valvesoftware | 1 Dota 2 | 2024-11-21 | 7.8 High |
| meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is affected by memory corruption. | ||||
| CVE-2020-7950 | 1 Valvesoftware | 1 Dota 2 | 2024-11-21 | 7.8 High |
| meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a vulnerable function call. | ||||
| CVE-2020-7949 | 1 Valvesoftware | 1 Dota 2 | 2024-11-21 | 7.8 High |
| schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a GetValue call. | ||||
| CVE-2020-7948 | 1 Auth0 | 1 Login By Auth0 | 2024-11-21 | 8.8 High |
| An issue was discovered in the Login by Auth0 plugin before 4.0.0 for WordPress. A user can perform an insecure direct object reference. | ||||