Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2020-13965
Known exploited
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
CVSS Score
6.1
EPSS Score
0.766
Published
2020-06-09
CVE-2020-9859
Known exploited
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbitrary code with kernel privileges.
CVSS Score
7.8
EPSS Score
0.008
Published
2020-06-05
CVE-2020-5410
Known exploited
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.
CVSS Score
7.5
EPSS Score
0.956
Published
2020-06-02
CVE-2020-8816
Known exploited
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.
CVSS Score
9.1
EPSS Score
0.782
Published
2020-05-29
CVE-2020-1956
Known exploited
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.
CVSS Score
8.8
EPSS Score
0.973
Published
2020-05-22
CVE-2020-1054
Known exploited
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.
CVSS Score
7.0
EPSS Score
0.542
Published
2020-05-21
CVE-2020-5741
Known exploited
Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.
CVSS Score
7.2
EPSS Score
0.729
Published
2020-05-08
CVE-2020-4427
Known exploited
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security restrictions when configured with SAML authentication. By sending a specially crafted HTTP request, an attacker could exploit this vulnerability to bypass the authentication process and gain full administrative access to the system. IBM X-Force ID: 180532.
CVSS Score
9.0
EPSS Score
0.7
Published
2020-05-07
CVE-2020-4428
Known exploited
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.
CVSS Score
9.1
EPSS Score
0.617
Published
2020-05-07
CVE-2020-4430
Known exploited
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535.
CVSS Score
4.3
EPSS Score
0.685
Published
2020-05-07


Contact Us

Shodan ® - All rights reserved