• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2020-5759
Grandstream, Ucm6204 Firmware
Gac2500_firmware, Gac2500, Gvc3202_firmware, Gvc3202, Gxv3275_firmware, Gxv3275, Gxv3240_firmware, Gxv3240, Gxp2200_firmware, Gxp2200
2020-07-23
N/A
9.8 CRITICAL
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authenticated remote attacker can execute commands as the root user by issuing a specially crafted "unset" command.
CVE-2020-5758
Grandstream, Ucm6204 Firmware
Gac2500_firmware, Gac2500, Gvc3202_firmware, Gvc3202, Gxv3275_firmware, Gxv3275, Gxv3240_firmware, Gxv3240, Gxp2200_firmware, Gxp2200
2020-07-23
N/A
8.8 HIGH
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can execute commands as the root user by sending a crafted HTTP GET to the UCM's "Old" HTTPS API.
CVE-2020-5757
Grandstream, Ucm6204 Firmware
Gac2500_firmware, Gac2500, Gvc3202_firmware, Gvc3202, Gxv3275_firmware, Gxv3275, Gxv3240_firmware, Gxv3240, Gxp2200_firmware, Gxp2200
2020-07-23
N/A
9.8 CRITICAL
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authenticated remote attacker can bypass command injection mitigations and execute commands as the root user by sending a crafted HTTP POST to the UCM's "New" HTTPS API.
CVE-2020-5756
Grandstream, Gwn7000 Firmware
Gac2500_firmware, Gac2500, Gvc3202_firmware, Gvc3202, Gxv3275_firmware, Gxv3275, Gxv3240_firmware, Gxv3240, Gxp2200_firmware, Gxp2200
2020-07-22
N/A
8.8 HIGH
Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router.
CVE-2020-5755
2021-07-21
N/A
7.8 HIGH
Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%WrDataPKG" directory against renaming. This could allow attackers to trigger a crash or wait upon Webroot service restart to rewrite and hijack dlls in this directory for privilege escalation.
CVE-2020-5754
2020-06-22
N/A
9.1 CRITICAL
Webroot endpoint agents prior to version v9.0.28.48 allows remote attackers to trigger a type confusion vulnerability over its listening TCP port, resulting in crashing or reading memory contents of the Webroot endpoint agent.
CVE-2020-5753
2022-04-07
N/A
5.3 MEDIUM
Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's Signal phone and disclose currently used DNS server due to ICE Candidate handling before call is answered or declined.
CVE-2020-5752
Druva, Insync Client
Insync_client, Insync
2022-11-29
N/A
7.8 HIGH
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
CVE-2020-5751
2020-05-11
N/A
5.4 MEDIUM
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted operator.
CVE-2020-5750
2020-05-11
N/A
6.1 MEDIUM
Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feature.
« Previous 1 … 3,409 3,410 3,411 3,412 3,413 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE