Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2020-5849
Known exploited
Unraid 6.8.0 allows authentication bypass.
CVSS Score
7.5
EPSS Score
0.937
Published
2020-03-16
CVE-2020-0787
Known exploited
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.
CVSS Score
7.8
EPSS Score
0.572
Published
2020-03-12
CVE-2020-0796
Known exploited
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.
CVSS Score
10.0
EPSS Score
0.944
Published
2020-03-12
CVE-2020-10181
Known exploited
goform/formEMR30 in Sumavision Enhanced Multimedia Router (EMR) 3.0.4.27 allows creation of arbitrary users with elevated privileges (administrator) on a device, as demonstrated by a setString=new_user<*1*>administrator<*1*>123456 request.
CVSS Score
9.8
EPSS Score
0.299
Published
2020-03-11
CVE-2020-6207
Known exploited
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.
CVSS Score
10.0
EPSS Score
0.943
Published
2020-03-10
CVE-2020-0041
Known exploited
In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-145988638References: Upstream kernel
CVSS Score
7.8
EPSS Score
0.229
Published
2020-03-10
CVE-2020-0069
Known exploited
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754
CVSS Score
7.8
EPSS Score
0.011
Published
2020-03-10
CVE-2016-11021
Known exploited
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.
CVSS Score
7.2
EPSS Score
0.904
Published
2020-03-09
CVE-2020-10221
Known exploited
lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.
CVSS Score
8.8
EPSS Score
0.911
Published
2020-03-08
CVE-2020-10189
Known exploited
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
CVSS Score
9.8
EPSS Score
0.942
Published
2020-03-06


Contact Us

Shodan ® - All rights reserved