Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2020-06-15 CVE-2020-14034 Classic Buffer Overflow vulnerability in Meetecho Janus
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0.
network
low complexity
meetecho CWE-120
7.5
2020-06-15 CVE-2020-14033 Classic Buffer Overflow vulnerability in Meetecho Janus
An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0.
network
low complexity
meetecho CWE-120
7.5
2020-06-15 CVE-2019-20838 Out-of-bounds Read vulnerability in multiple products
libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.
network
low complexity
pcre apple splunk CWE-125
7.5
2020-06-15 CVE-2018-21246 Improper Authentication vulnerability in Caddyserver Caddy
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
7.5
2020-06-15 CVE-2020-14054 SQL Injection vulnerability in Sokkia Gnr5 Vanguard Firmware 1.2
SOKKIA GNR5 Vanguard WEB version 1.2 (build: 91f2b2c3a04d203d79862f87e2440cb7cefc3cd3) and hardware version 212 allows remote attackers to bypass admin authentication via a SQL injection attack that uses the User Name or Password field on the login page.
network
low complexity
sokkia CWE-89
7.5
2020-06-15 CVE-2020-14011 Insecure Default Initialization of Resource vulnerability in Lansweeper
Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin account, unless "Built-in admin" is manually unchecked.
network
low complexity
lansweeper CWE-1188
7.5
2020-06-15 CVE-2020-4216 Use of Hard-coded Credentials vulnerability in IBM Spectrum Protect Plus
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
network
low complexity
ibm CWE-798
7.5
2020-06-15 CVE-2020-0597 Out-of-bounds Read vulnerability in Intel products
Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 14.0.33 may allow an unauthenticated user to potentially enable denial of service via network access.
network
low complexity
intel CWE-125
7.5
2020-06-15 CVE-2020-0595 Use After Free vulnerability in Intel products
Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
network
low complexity
intel CWE-416
7.5
2020-06-15 CVE-2020-0594 Out-of-bounds Read vulnerability in Intel products
Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
network
low complexity
intel CWE-125
7.5