CVE, Title, Vendor |
Description |
CVSS v3.1 Base Score |
Date Created |
Date Updated |
CVE-2020-8605
Trend Micro Web Security Virtual Appliance Remote Code Execution Vulnerability
Trend Micro
|
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance may allow remote attackers to execute arbitrary code on affected installations. An attacker can leverage this vulnerability to disclose information in the context of the IWSS user. An authenticated remote attacker could exploit a command injection vulnerability in the product, leading to remote code execution vulnerability. |
CVSSv3BaseScore:8.8(AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) |
05/27/2020 |
07/14/2020 |
CVE-2020-1350
Microsoft Windows DNS Server Remote Code Execution Vulnerability
Microsoft
|
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the Local System Account. Windows servers that are configured as DNS servers are at risk from this vulnerability. |
CVSSv3BaseScore:10.0(AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) |
07/14/2020 |
07/23/2020 |
CVE-2020-5902
F5 BIG-IP Remote Code Execution Vulnerability
F5
|
F5 BIG-IP is exposed to remote code execution vulnerability. The vulnerability that has been actively exploited in the wild allows attackers to read files, execute code or take complete control over vulnerable systems having network access. |
CVSSv3BaseScore:9.8(AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) |
07/01/2020 |
07/21/2020 |
CVE-2020-6287
SAP NetWeaver Application Server JAVA Multiple Vulnerabilities
SAP
|
SAP NetWeaver AS JAVA (LM Configuration Wizard) does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including the ability to create an administrative user, and therefore compromising Confidentiality, Integrity and Availability of the system, leading to Missing Authentication Check. An unauthenticated attacker can exploit this vulnerability through the Hypertext Transfer Protocol (HTTP) to take control of trusted SAP applications. |
CVSSv3BaseScore:10.0(AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) |
07/14/2020 |
07/16/2020 |
CVE-2020-15363
WordPress Theme NexosReal Estate 'search_order' SQL Injection Vulnerability
Nexos
|
NexosReal Estate Theme is exposed to remote SQL injection vulnerability that allows side-map/?search_order= SQL Injection. |
CVSSv3BaseScore:9.8(AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) |
06/28/2020 |
07/22/2020 |
CVE-2020-13866
WinGate Privilege Escalation Vulnerability
qbik
|
WinGate has insecure permissions for the installation directory, which allows local users to gain privileges by replacing an executable file with a Trojan horse. The WinGate directory hands full control to authenticated users, who can then run arbitrary code as SYSTEM after a WinGate restart or system reboot. |
CVSSv3BaseScore:7.8(AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) |
06/08/2020 |
06/11/2020 |
CVE-2020-2021
Palo Alto Networks PAN-OS Authentication Bypass in SAML Authentication Vulnerability
Palo Alto Networks
|
When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based attacker to access protected resources. The attacker must have network access to the vulnerable server to exploit this vulnerability. |
CVSSv3BaseScore:10.0(AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) |
06/29/2020 |
07/06/2020 |
CVE-2020-3952
VMware vCenter vmdir Information Disclosure Vulnerability
VMware
|
Under certain conditions vmdir does not correctly implement access controls. A malicious actor with network access to an affected vmdir deployment may be able to extract highly sensitive information which could be used to compromise vCenter Server or other services which are dependent upon vmdir for authentication. |
CVSSv3BaseScore:9.8(AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) |
04/10/2020 |
06/02/2020 |