Search Results (10087 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-17061 1 Microsoft 2 Sharepoint Foundation, Sharepoint Server 2024-11-21 8.8 High
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2020-17051 1 Microsoft 11 Windows Server 1903, Windows Server 1909, Windows Server 2004 and 8 more 2024-11-21 9.8 Critical
Windows Network File System Remote Code Execution Vulnerability
CVE-2020-17042 1 Microsoft 22 Windows 10, Windows 10 1507, Windows 10 1607 and 19 more 2024-11-21 8.8 High
Windows Print Spooler Remote Code Execution Vulnerability
CVE-2020-17019 1 Microsoft 2 Excel, Office 2024-11-21 7.8 High
Microsoft Excel Remote Code Execution Vulnerability
CVE-2020-16608 1 Notable 1 Notable 2024-11-21 9.6 Critical
Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true).
CVE-2020-16279 1 Rangee 1 Rangeeos 2024-11-21 9.8 Critical
The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplied input being passed to the command line without sanitization.
CVE-2020-16229 1 Advantech 1 Webaccess\/hmi Designer 2024-11-21 7.8 High
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a type confusion condition, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.
CVE-2020-16217 1 Advantech 1 Webaccess\/hmi Designer 2024-11-21 7.8 High
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. A double free vulnerability caused by processing specially crafted project files may allow remote code execution, disclosure/modification of information, or cause the application to crash.
CVE-2020-16215 1 Advantech 1 Webaccess\/hmi Designer 2024-11-21 7.8 High
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause a stack-based buffer overflow, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.
CVE-2020-16213 1 Advantech 1 Webaccess\/hmi Designer 2024-11-21 7.8 High
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Processing specially crafted project files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.
CVE-2020-16207 1 Advantech 1 Webaccess\/hmi Designer 2024-11-21 7.8 High
Advantech WebAccess HMI Designer, Versions 2.1.9.31 and prior. Multiple heap-based buffer overflow vulnerabilities may be exploited by opening specially crafted project files that may overflow the heap, which may allow remote code execution, disclosure/modification of information, or cause the application to crash.
CVE-2020-16103 1 Gallagher 1 Command Centre 2024-11-21 8.8 High
Type confusion in Gallagher Command Centre Server allows a remote attacker to crash the server or possibly cause remote code execution. This issue affects: Gallagher Command Centre 8.30 versions prior to 8.30.1236(MR1); 8.20 versions prior to 8.20.1166(MR3); 8.10 versions prior to 8.10.1211(MR5); version 8.00 and prior versions.
CVE-2020-15929 1 Ortussolutions 1 Testbox 2024-11-21 9.8 Critical
In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.
CVE-2020-15926 1 Rocket.chat 1 Rocket.chat 2024-11-21 6.1 Medium
Rocket.Chat through 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side.
CVE-2020-15922 1 Midasolutions 1 Eframework 2024-11-21 9.8 Critical
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required.
CVE-2020-15920 1 Midasolutions 1 Eframework 2024-11-21 9.8 Critical
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required.
CVE-2020-15871 1 Sonatype 1 Nexus Repository Manager 3 2024-11-21 8.8 High
Sonatype Nexus Repository Manager OSS/Pro version before 3.25.1 allows Remote Code Execution.
CVE-2020-15867 1 Gogs 1 Gogs 2024-11-21 7.2 High
The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to this hook feature is granted to a user who does not have administrative privileges. NOTE: because this is mentioned in the documentation but not in the UI, it could be considered a "Product UI does not Warn User of Unsafe Actions" issue.
CVE-2020-15865 1 Stimulsoft 1 Reports 2024-11-21 9.8 Critical
A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-64 in the report XML file so that they will be compiled and executed on the server that processes this file. This can be used to fully compromise the server.
CVE-2020-15860 1 Parallels 1 Remote Application Server 2024-11-21 9.9 Critical
Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute any application in the backend operating system through the web application, despite the affected application not being published. In addition, it was discovered that it is possible to access any host in the internal domain, even if it has no published applications or the mentioned host is no longer associated with that server farm.