VYPR

CVEs

1,665 total · page 20 of 34

  • CVE-2021-27876HigKEVMar 1, 2021
    risk 0.75cvss 8.1epss 0.14

    An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an…

  • CVE-2021-1732HigKEVFeb 25, 2021
    risk 0.78cvss 7.8epss 0.78

    Windows Win32k Elevation of Privilege Vulnerability

  • CVE-2021-21973MedKEVFeb 24, 2021
    risk 0.53cvss 5.3epss 0.88

    The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin…

  • CVE-2021-21972CriKEVFeb 24, 2021
    risk 0.93cvss 9.8epss 1.00

    The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter…

  • CVE-2021-27104CriKEVFeb 16, 2021
    risk 0.86cvss 9.8epss 0.56

    Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.

  • CVE-2021-27103CriKEVFeb 16, 2021
    risk 0.83cvss 9.8epss 0.11

    Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.

  • CVE-2021-27102HigKEVFeb 16, 2021
    risk 0.69cvss 7.8epss 0.04

    Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.

  • CVE-2021-27101CriKEVFeb 16, 2021
    risk 0.82cvss 9.8epss 0.06

    Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.

  • CVE-2021-21315HigKEVFeb 16, 2021
    risk 0.58cvss 7.1epss 0.91

    The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was…

  • CVE-2021-25298HigKEVFeb 15, 2021
    risk 0.78cvss 8.8epss 0.75

    Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can…

  • CVE-2021-25297HigKEVFeb 15, 2021
    risk 0.77cvss 8.8epss 0.56

    Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead…

  • CVE-2021-25296HigKEVFeb 15, 2021
    risk 0.78cvss 8.8epss 0.72

    Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which…

  • CVE-2021-21311HigKEVFeb 11, 2021
    risk 0.59cvss 7.2epss 0.90

    Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected. This is fixed in version…

  • CVE-2021-21017HigKEVFeb 11, 2021
    risk 0.76cvss 8.8epss 0.86

    Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code…

  • CVE-2021-23874HigKEVFeb 10, 2021
    risk 0.65cvss 8.2epss 0.01

    Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.

  • CVE-2021-21148HigKEVFeb 9, 2021
    risk 0.71cvss 8.8epss 0.20

    Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-22502CriKEVFeb 8, 2021
    risk 0.86cvss 9.8epss 0.97

    Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.

  • CVE-2021-20016CriKEVFeb 4, 2021
    risk 0.85cvss 9.8epss 0.37

    A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.

  • CVE-2020-2506HigKEVFeb 3, 2021
    risk 0.60cvss 7.3epss 0.02

    The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP…

  • CVE-2020-25506CriKEVFeb 2, 2021
    risk 0.84cvss 9.8epss 1.00

    D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.

  • CVE-2020-29557CriKEVJan 29, 2021
    risk 0.80cvss 9.8epss 0.54

    An issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackers to achieve pre-authentication remote code execution.

  • CVE-2021-3156HigKEVJan 26, 2021
    risk 0.67cvss 7.8epss 0.99

    Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

  • CVE-2020-36193HigKEVJan 18, 2021
    risk 0.59cvss 7.5epss 0.71

    Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

  • CVE-2020-6572HigKEVJan 14, 2021
    risk 0.70cvss 8.8epss 0.11

    Use after free in Media in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

  • CVE-2021-1647HigKEVJan 12, 2021
    risk 0.66cvss 7.8epss 0.39

    Microsoft Defender Remote Code Execution Vulnerability

  • CVE-2021-3129CriKEVJan 12, 2021
    risk 0.86cvss 9.8epss 1.00

    Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitrary code because of insecure usage of file_get_contents() and file_put_contents(). This is exploitable on sites using debug mode with Laravel before 8.4.2.

  • CVE-2020-16017CriKEVJan 8, 2021
    risk 0.75cvss 9.6epss 0.03

    Use after free in site isolation in Google Chrome prior to 86.0.4240.198 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-16013HigKEVJan 8, 2021
    risk 0.69cvss 8.8epss 0.03

    Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.198 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-17519HigKEVJan 5, 2021
    risk 0.65cvss 7.5epss 0.98

    A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager…

  • CVE-2020-10148CriKEVDec 29, 2020
    risk 0.83cvss 9.8epss 0.92

    The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds…

  • CVE-2020-35730MedKEVDec 28, 2020
    risk 0.47cvss 6.1epss 0.33

    An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.

  • CVE-2020-29583CriKEVDec 22, 2020
    risk 0.83cvss 9.8epss 0.90

    Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin…

  • CVE-2020-29574CriKEVDec 11, 2020
    risk 0.82cvss 9.8epss 0.05

    An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

  • CVE-2020-17530CriKEVDec 11, 2020
    risk 0.79cvss 9.8epss 0.96

    Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

  • CVE-2020-17144HigKEVDec 10, 2020
    risk 0.70cvss 8.4epss 0.37

    Microsoft Exchange Remote Code Execution Vulnerability

  • CVE-2020-27950MedKEVDec 8, 2020
    risk 0.49cvss 5.5epss 0.17

    A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental…

  • CVE-2020-27932HigKEVDec 8, 2020
    risk 0.64cvss 7.8epss 0.10

    A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina…

  • CVE-2020-27930HigKEVDec 8, 2020
    risk 0.64cvss 7.8epss 0.22

    A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS…

  • CVE-2020-4006CriKEVNov 23, 2020
    risk 0.73cvss 9.1epss 0.24

    VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.

  • CVE-2020-13671HigKEVNov 20, 2020
    risk 0.70cvss 8.8epss 0.04

    Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0…

  • CVE-2020-28949HigKEVNov 19, 2020
    risk 0.65cvss 7.8epss 0.85

    Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.

  • CVE-2020-17087HigKEVNov 11, 2020
    risk 0.63cvss 7.8epss 0.05

    Windows Kernel Local Elevation of Privilege Vulnerability

  • CVE-2020-13927CriKEVNov 10, 2020
    risk 0.80cvss 9.8epss 1.00

    The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From Airflow 1.10.11 the default has been changed to deny all requests by default and is documented at…

  • CVE-2020-16846CriKEVNov 6, 2020
    risk 0.80cvss 9.8epss 1.00

    An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.

  • CVE-2020-16010CriKEVNov 3, 2020
    risk 0.75cvss 9.6epss 0.06

    Heap buffer overflow in UI in Google Chrome on Android prior to 86.0.4240.185 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-16009HigKEVNov 3, 2020
    risk 0.66cvss 8.8epss 0.49

    Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-15999CriKEVNov 3, 2020
    risk 0.71cvss 9.6epss 0.44

    Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-14750CriKEVNov 2, 2020
    risk 0.87cvss 9.8epss 0.99

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2018-19953MedKEVOct 28, 2020
    risk 0.60cvss 6.1epss 0.24

    If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS…

  • CVE-2018-19949CriKEVOct 28, 2020
    risk 0.84cvss 9.8epss 0.24

    If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS…