• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2020-10825
Draytek, Vigor3900 Firmware
Vigor2925_firmware, Vigor_2925, Vigor_2925n, Vigor2925ac, Vigor2925fn, Vigor2925n-plus, Vigor2925vac, Vigor2925vn-plus, Vigor300b_firmware, Vigor300b
2020-06-23
N/A
9.8 CRITICAL
A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 3 of 3).
CVE-2020-10824
Draytek, Vigor3900 Firmware
Vigor2925_firmware, Vigor_2925, Vigor_2925n, Vigor2925ac, Vigor2925fn, Vigor2925n-plus, Vigor2925vac, Vigor2925vn-plus, Vigor300b_firmware, Vigor300b
2020-06-23
N/A
9.8 CRITICAL
A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 2 of 3).
CVE-2020-10823
Draytek, Vigor3900 Firmware
Vigor2925_firmware, Vigor_2925, Vigor_2925n, Vigor2925ac, Vigor2925fn, Vigor2925n-plus, Vigor2925vac, Vigor2925vn-plus, Vigor300b_firmware, Vigor300b
2020-06-23
N/A
9.8 CRITICAL
A stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 1 of 3).
CVE-2020-10821
2020-03-23
N/A
4.8 MEDIUM
Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.
CVE-2020-10820
2020-03-23
N/A
4.8 MEDIUM
Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter.
CVE-2020-1082
2022-05-23
N/A
7.8 HIGH
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1021, CVE-2020-1088.
CVE-2020-10819
2020-03-23
N/A
4.8 MEDIUM
Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter.
CVE-2020-10818
2020-03-25
N/A
7.2 HIGH
Artica Proxy 4.26 allows remote command execution for an authenticated user via shell metacharacters in the "Modify the hostname" field.
CVE-2020-10817
2020-04-01
N/A
8.8 HIGH
The custom-searchable-data-entry-system (aka Custom Searchable Data Entry System) plugin through 1.7.1 for WordPress allows SQL Injection. NOTE: this product is discontinued.
CVE-2020-10816
Manageengine Applications Manager, Zohocorp
Manageengine_adselfservice_plus, Application_control_plus, Desktop_central, Firewall_analyzer, Log360, Manageengine_access_manager_plus, Manageengine_ad360, Manageengine_adaudit_plus, Manageengine_admanager_plus, Manageengine_analytics_plus
2020-10-15
N/A
7.5 HIGH
Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.
« Previous 1 … 4,873 4,874 4,875 4,876 4,877 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE