• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2020-28341
2020-11-10
N/A
7.8 HIGH
An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos990 chipsets) software. The S3K250AF Secure Element CC EAL 5+ chip allows attackers to execute arbitrary code and obtain sensitive information via a buffer overflow. The Samsung ID is SVE-2020-18632 (November 2020).
CVE-2020-28340
2020-11-10
N/A
9.8 CRITICAL
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via Secure Folder. The Samsung ID is SVE-2020-18546 (November 2020).
CVE-2020-2834
2020-04-17
N/A
8.2 HIGH
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
CVE-2020-28339
2021-07-21
N/A
8.8 HIGH
The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object Injection because of usces_unserialize. There is not a complete POP chain.
CVE-2020-28337
2022-01-01
N/A
7.2 HIGH
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker must have the credentials of an administrative user, upload a maliciously constructed ZIP file with file paths including relative paths (i.e., ../../), move this file into the backup directory, and execute a restore on this file.
CVE-2020-28334
Barco, Wepresent Wipg-1600w
Clickshare_button_r9861500d01_firmware, Clickshare_button_r9861500d01, Clickshare_cs-100_huddle_firmware, Clickshare_cs-100_huddle, Clickshare_cse-200_firmware, Clickshare_cse-200, Clickshare_cs-100_firmware, Clickshare_cs-100, Clickshare_cse-800_firmware, Clickshare_cse-800
2020-12-03
N/A
9.8 CRITICAL
Barco wePresent WiPG-1600W devices use Hard-coded Credentials (issue 2 of 2). Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco wePresent WiPG-1600W device has a hardcoded root password hash included in the firmware image. Exploiting CVE-2020-28329, CVE-2020-28330 and CVE-2020-28331 could potentially be used in a simple and automated exploit chain to go from unauthenticated remote attacker to root shell.
CVE-2020-28333
Barco, Wepresent Wipg-1600w
Clickshare_button_r9861500d01_firmware, Clickshare_button_r9861500d01, Clickshare_cs-100_huddle_firmware, Clickshare_cs-100_huddle, Clickshare_cse-200_firmware, Clickshare_cse-200, Clickshare_cs-100_firmware, Clickshare_cs-100, Clickshare_cse-800_firmware, Clickshare_cse-800
2021-07-21
N/A
9.8 CRITICAL
Barco wePresent WiPG-1600W devices allow Authentication Bypass. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W web interface does not use session cookies for tracking authenticated sessions. Instead, the web interface uses a "SEID" token that is appended to the end of URLs in GET requests. Thus the "SEID" would be exposed in web proxy logs and browser history. An attacker that is able to capture the "SEID" and originate requests from the same IP address (via a NAT device or web proxy) would be able to access the user interface of the device without having to know the credentials.
CVE-2020-28332
Barco, Wepresent Wipg-1600w
Clickshare_button_r9861500d01_firmware, Clickshare_button_r9861500d01, Clickshare_cs-100_huddle_firmware, Clickshare_cs-100_huddle, Clickshare_cse-200_firmware, Clickshare_cse-200, Clickshare_cs-100_firmware, Clickshare_cs-100, Clickshare_cse-800_firmware, Clickshare_cse-800
2020-12-03
N/A
9.8 CRITICAL
Barco wePresent WiPG-1600W devices download code without an Integrity Check. Affected Version(s): 2.5.1.8, 2.5.0.25, 2.5.0.24, 2.4.1.19. The Barco wePresent WiPG-1600W firmware does not perform verification of digitally signed firmware updates and is susceptible to processing and installing modified/malicious images.
CVE-2020-28331
Barco, Wepresent Wipg-1600w
Clickshare_button_r9861500d01_firmware, Clickshare_button_r9861500d01, Clickshare_cs-100_huddle_firmware, Clickshare_cs-100_huddle, Clickshare_cse-200_firmware, Clickshare_cse-200, Clickshare_cs-100_firmware, Clickshare_cs-100, Clickshare_cse-800_firmware, Clickshare_cse-800
2022-07-12
N/A
7.5 HIGH
Barco wePresent WiPG-1600W devices have Improper Access Control. Affected Version(s): 2.5.1.8. The Barco wePresent WiPG-1600W device has an SSH daemon included in the firmware image. By default, the SSH daemon is disabled and does not start at system boot. The system initialization scripts read a device configuration file variable to see if the SSH daemon should be started. The web interface does not provide a visible capability to alter this configuration file variable. However, a malicious actor can include this variable in a POST such that the SSH daemon will be started when the device boots.
CVE-2020-28330
Barco, Wepresent Wipg-1600w
Clickshare_button_r9861500d01_firmware, Clickshare_button_r9861500d01, Clickshare_cs-100_huddle_firmware, Clickshare_cs-100_huddle, Clickshare_cse-200_firmware, Clickshare_cse-200, Clickshare_cs-100_firmware, Clickshare_cs-100, Clickshare_cse-800_firmware, Clickshare_cse-800
2020-12-03
N/A
6.5 MEDIUM
Barco wePresent WiPG-1600W devices have Unprotected Transport of Credentials. Affected Version(s): 2.5.1.8. An attacker armed with hardcoded API credentials (retrieved by exploiting CVE-2020-28329) can issue an authenticated query to display the admin password for the main web user interface listening on port 443/tcp of a Barco wePresent WiPG-1600W device.
« Previous 1 … 3,810 3,811 3,812 3,813 3,814 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE