Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2020-1068 |
|
Privilege Escalation in microsoft (CVE-2020-1068)
vulnerability in microsoft (CVE-2020-1068). Successful exploitation can lead to full system takeover.
|
| CVE-2020-0909 |
|
Vulnerability in dos (CVE-2020-0909)
vulnerability in dos (CVE-2020-0909). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-1023 |
|
Unrestricted File Upload in microsoft (CVE-2020-1023)
vulnerability in microsoft (CVE-2020-1023). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1024 |
|
Unrestricted File Upload in microsoft (CVE-2020-1024)
vulnerability in microsoft (CVE-2020-1024). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1028 |
|
Buffer Overflow in microsoft (CVE-2020-1028)
vulnerability in microsoft (CVE-2020-1028). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1048 |
|
Privilege Escalation in microsoft (CVE-2020-1048)
vulnerability in microsoft (CVE-2020-1048). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1051 |
|
Buffer Overflow in microsoft (CVE-2020-1051)
vulnerability in microsoft (CVE-2020-1051). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1010 |
|
Privilege Escalation in microsoft (CVE-2020-1010)
vulnerability in microsoft (CVE-2020-1010). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1035 |
|
Buffer Overflow in microsoft (CVE-2020-1035)
vulnerability in microsoft (CVE-2020-1035). Successful exploitation can lead to full system takeover.
|
| CVE-2020-1021 |
|
Privilege Escalation in microsoft (CVE-2020-1021)
vulnerability in microsoft (CVE-2020-1021). Successful exploitation can lead to full system takeover.
|
| CVE-2020-9484 |
|
Unsafe Deserialization in org.apache.tomcat:tomcat-catalina (CVE-2020-9484)
vulnerability in org.apache.tomcat:tomcat-catalina (CVE-2020-9484). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `7.0.104` or later.
|
| CVE-2020-3334 |
|
Vulnerability in c (CVE-2020-3334)
vulnerability in c (CVE-2020-3334). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-3303 |
|
Vulnerability in dos (CVE-2020-3303)
vulnerability in dos (CVE-2020-3303). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-3305 |
|
Vulnerability in dos (CVE-2020-3305)
vulnerability in dos (CVE-2020-3305). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-3306 |
|
Vulnerability in dos (CVE-2020-3306)
vulnerability in dos (CVE-2020-3306). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-3191 |
|
Vulnerability in c (CVE-2020-3191)
vulnerability in c (CVE-2020-3191). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-3195 |
|
Vulnerability in dos (CVE-2020-3195)
vulnerability in dos (CVE-2020-3195). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-3196 |
|
Vulnerability in dos (CVE-2020-3196)
vulnerability in dos (CVE-2020-3196). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-3254 |
|
Vulnerability in dos (CVE-2020-3254)
vulnerability in dos (CVE-2020-3254). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-3298 |
|
Out-of-Bounds Read in dos (CVE-2020-3298)
vulnerability in dos (CVE-2020-3298). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-3189 |
|
Vulnerability in dos (CVE-2020-3189)
vulnerability in dos (CVE-2020-3189). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-3255 |
|
Vulnerability in dos (CVE-2020-3255)
vulnerability in dos (CVE-2020-3255). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-3283 |
|
Buffer Overflow in dos (CVE-2020-3283)
vulnerability in dos (CVE-2020-3283). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-3179 |
|
Vulnerability in dos (CVE-2020-3179)
vulnerability in dos (CVE-2020-3179). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-11619 |
|
Unsafe Deserialization in fasterxml (CVE-2020-11619)
vulnerability in fasterxml (CVE-2020-11619). Successful exploitation can lead to full system takeover.
|
| CVE-2020-11111 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, an...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
|
| CVE-2020-11112 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/common...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
|
| CVE-2020-11113 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
|
| CVE-2020-10969 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
|
| CVE-2020-10968 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
|
| CVE-2020-10648 |
|
Vulnerability in denx (CVE-2020-10648)
vulnerability in denx (CVE-2020-10648). Successful exploitation can lead to full system takeover.
|
| CVE-2020-10672 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
|
| CVE-2020-10673 |
|
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
|
| CVE-2020-6984 |
|
Vulnerability in rockwellautomation (CVE-2020-6984)
vulnerability in rockwellautomation (CVE-2020-6984). Confidential information can be exposed externally.
|
| CVE-2020-6988 |
|
Authentication Bypass in rockwellautomation (CVE-2020-6988)
authentication bypass in rockwellautomation (CVE-2020-6988). Confidential information can be exposed externally.
|
| CVE-2019-18336 |
|
Vulnerability in siemens (CVE-2019-18336)
vulnerability in siemens (CVE-2019-18336). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-3167 |
|
OS Command Injection in cisco (CVE-2020-3167)
OS command injection in cisco (CVE-2020-3167). Successful exploitation can lead to full system takeover.
|
| CVE-2011-4088 |
|
ABRT might allow attackers to obtain sensitive information from crash reports.
ABRT might allow attackers to obtain sensitive information from crash reports.
|
| CVE-2019-19378 |
|
Out-of-Bounds Write in c (CVE-2019-19378)
out-of-bounds write in c (CVE-2019-19378). Successful exploitation can lead to full system takeover.
|
| CVE-2019-13721 |
|
Use-After-Free in google (CVE-2019-13721)
vulnerability in google (CVE-2019-13721). Successful exploitation can lead to full system takeover.
|
| CVE-2019-6852 |
|
Information Disclosure in schneider-electric (CVE-2019-6852)
vulnerability in schneider-electric (CVE-2019-6852). Confidential information can be exposed externally.
|
| CVE-2019-18197 |
|
Use-After-Free in nokogiri (CVE-2019-18197)
vulnerability in nokogiri (CVE-2019-18197). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `1.10.5` or later.
|
| CVE-2019-13529 |
|
Cross-Site Request Forgery (CSRF) in sma (CVE-2019-13529)
vulnerability in sma (CVE-2019-13529). Successful exploitation can lead to full system takeover.
|
| CVE-2019-15256 |
|
Vulnerability in dos (CVE-2019-15256)
vulnerability in dos (CVE-2019-15256). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-12698 |
|
Vulnerability in dos (CVE-2019-12698)
vulnerability in dos (CVE-2019-12698). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-12699 |
|
Vulnerability in cisco (CVE-2019-12699)
vulnerability in cisco (CVE-2019-12699). Successful exploitation can lead to full system takeover.
|
| CVE-2019-12673 |
|
Buffer Overflow in dos (CVE-2019-12673)
vulnerability in dos (CVE-2019-12673). Risk of unauthorized operations or information disclosure.
|
| CVE-2019-12674 |
|
Vulnerability in cisco (CVE-2019-12674)
vulnerability in cisco (CVE-2019-12674). Successful exploitation can lead to full system takeover.
|
| CVE-2019-12675 |
|
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and...
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and execute commands with root privileges in the host namespace. These vulnerabilities are due to insuff...
|
| CVE-2019-12676 |
|
Vulnerability in dos (CVE-2019-12676)
vulnerability in dos (CVE-2019-12676). Risk of unauthorized operations or information disclosure.
|