• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2020-1068
2021-07-21
N/A
7.8 HIGH
An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1010, CVE-2020-1079.
CVE-2020-10678
2021-07-21
N/A
8.8 HIGH
In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can leverage a bug to escalate privileges.
CVE-2020-10675
2023-02-03
N/A
7.5 HIGH
The Library API in buger jsonparser through 2019-12-04 allows attackers to cause a denial of service (infinite loop) via a Delete call.
CVE-2020-10674
2020-03-20
N/A
9.8 CRITICAL
PerlSpeak through 2.01 allows attackers to execute arbitrary OS commands, as demonstrated by use of system and 2-argument open.
CVE-2020-10673
Agile Plm, Oracle
Fujitsu_m10-1_firmware, Fujitsu_m10-1, Fujitsu_m10-4_firmware, Fujitsu_m10-4, Fujitsu_m10-4s_firmware, Fujitsu_m10-4s, Fujitsu_m12-1_firmware, Fujitsu_m12-1, Fujitsu_m12-2_firmware, Fujitsu_m12-2
2021-12-07
N/A
8.8 HIGH
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
CVE-2020-10672
2021-12-07
N/A
8.8 HIGH
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
CVE-2020-10671
Canon, Oce Colorwave 500, Oce Colorwave 500 Firmware
Eos-1d_x_firmware, Eos-1d_x, Eos-1d_x_mkii_firmware, Eos-1d_x_mkii, Eos-1d_c_firmware, Eos-1d_c, Eos_5d_mark_iii_firmware, Eos_5d_mark_iii, Eos_5d_mark_iv_firmware, Eos_5d_mark_iv
2020-03-23
N/A
8.8 HIGH
The Canon Oce Colorwave 500 4.0.0.0 printer's web application is missing any form of CSRF protections. This is a system-wide issue. An attacker could perform administrative actions by targeting a logged-in administrative user. NOTE: this is fixed in the latest version.
CVE-2020-10670
Canon, Oce Colorwave 500, Oce Colorwave 500 Firmware
Eos-1d_x_firmware, Eos-1d_x, Eos-1d_x_mkii_firmware, Eos-1d_x_mkii, Eos-1d_c_firmware, Eos-1d_c, Eos_5d_mark_iii_firmware, Eos_5d_mark_iii, Eos_5d_mark_iv_firmware, Eos_5d_mark_iv
2020-03-23
N/A
6.1 MEDIUM
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in the parameter settingId of the settingDialogContent.jsp page. NOTE: this is fixed in the latest version.
CVE-2020-1067
2021-07-21
N/A
8.8 HIGH
A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
CVE-2020-10669
Canon, Oce Colorwave 500, Oce Colorwave 500 Firmware
Eos-1d_x_firmware, Eos-1d_x, Eos-1d_x_mkii_firmware, Eos-1d_x_mkii, Eos-1d_c_firmware, Eos-1d_c, Eos_5d_mark_iii_firmware, Eos_5d_mark_iii, Eos_5d_mark_iv_firmware, Eos_5d_mark_iv
2020-03-24
N/A
7.5 HIGH
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to authentication bypass on the page /home.jsp. An unauthenticated attacker able to connect to the device's web interface can get a copy of the documents uploaded by any users. NOTE: this is fixed in the latest version.
« Previous 1 … 4,888 4,889 4,890 4,891 4,892 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE