VYPR

CVEs

8,985 total · page 116 of 180

  • CVE-2017-17870CriDec 27, 2017
    risk 0.67cvss 9.8epss 0.03

    The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.

  • CVE-2017-17849CriDec 27, 2017
    risk 0.70cvss 9.8epss 0.35

    A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response.

  • CVE-2017-16727CriDec 22, 2017
    risk 0.59cvss 9.1epss 0.00

    A Credentials Management issue was discovered in Moxa NPort W2150A versions prior to 1.11, and NPort W2250A versions prior to 1.11. The default password is empty on the device. An unauthorized user can access the device without a password. An unauthorized user has the ability to…

  • CVE-2017-17033CriDec 21, 2017
    risk 0.64cvss 9.8epss 0.06

    A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

  • CVE-2017-17032CriDec 21, 2017
    risk 0.64cvss 9.8epss 0.03

    A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

  • CVE-2017-17031CriDec 21, 2017
    risk 0.64cvss 9.8epss 0.03

    A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

  • CVE-2017-17030CriDec 21, 2017
    risk 0.64cvss 9.8epss 0.03

    A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

  • CVE-2017-17029CriDec 21, 2017
    risk 0.64cvss 9.8epss 0.03

    A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

  • CVE-2017-17028CriDec 21, 2017
    risk 0.64cvss 9.8epss 0.07

    A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

  • CVE-2017-17027CriDec 21, 2017
    risk 0.64cvss 9.8epss 0.03

    A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

  • CVE-2015-7224CriDec 21, 2017
    risk 0.64cvss 9.8epss 0.01

    puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password when a 'mysql_user' user parameter contains a host with a netmask.

  • CVE-2017-17411CriDec 21, 2017
    risk 0.74cvss 9.8epss 0.92

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper…

  • CVE-2017-17821CriDec 21, 2017
    risk 0.64cvss 9.8epss 0.01

    WTF/wtf/FastBitVector.h in WebKit, as distributed in Safari Technology Preview Release 46, allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact because it calls the FastBitVectorWordOwner::resizeSlow function (in…

  • CVE-2012-2576CriDec 20, 2017
    risk 0.72cvss 9.8epss 0.67

    SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.

  • CVE-2017-6094CriDec 20, 2017
    risk 0.64cvss 9.8epss 0.00

    CPEs used by subscribers on the access network receive their individual configuration settings from a central GAPS instance. A CPE identifies itself by the MAC address of its WAN interface and a certain "chk" value (48bit) derived from the MAC. The algorithm used to compute the…

  • CVE-2017-16725CriDec 20, 2017
    risk 0.64cvss 9.8epss 0.09

    A Stack-based Buffer Overflow issue was discovered in Xiongmai Technology IP Cameras and DVRs using the NetSurveillance Web interface. The stack-based buffer overflow vulnerability has been identified, which may allow an attacker to execute code remotely or crash the device.…

  • CVE-2017-17794CriDec 20, 2017
    risk 0.64cvss 9.8epss 0.00

    validate_form_preferences in admin/preferences.php in BlogoText through 3.7.6 allows attackers to bypass intended access restrictions via vectors related to an e-mail address field.

  • CVE-2017-17790CriDec 20, 2017
    risk 0.64cvss 9.8epss 0.05

    The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|' character, a different vulnerability than CVE-2017-17405. NOTE: situations…

  • CVE-2017-17779CriDec 20, 2017
    risk 0.64cvss 9.8epss 0.00

    Paid To Read Script 2.0.5 has SQL injection via the referrals.php id parameter.

  • CVE-2017-17777CriDec 20, 2017
    risk 0.64cvss 9.8epss 0.01

    Paid To Read Script 2.0.5 has authentication bypass in the admin panel via a direct request, as demonstrated by the admin/viewvisitcamp.php fn parameter and the admin/userview.php uid parameter.

  • CVE-2017-17761CriDec 19, 2017
    risk 0.67cvss 9.8epss 0.05

    An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) unauthenticated user to run arbitrary commands. This binary requires the "system" XML element for specifying the command. For…

  • CVE-2017-17759CriDec 19, 2017
    risk 0.68cvss 9.8epss 0.13

    Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the configuration) via a wc.dll?wwMaint~EditConfig request (which reaches an older version of a West Wind Web Connection HTTP service).

  • CVE-2017-17107CriDec 19, 2017
    risk 0.64cvss 9.8epss 0.04

    Zivif PR115-204-P-RS V2.3.4.2103 web cameras contain a hard-coded cat1029 password for the root user. The SONIX operating system's setup renders this password unchangeable and it can be used to access the device via a TELNET session.

  • CVE-2017-17106CriDec 19, 2017
    risk 0.66cvss 9.8epss 0.25

    Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request. This vulnerability exists because of a lack of authentication checks in requests to CGI pages.

  • CVE-2017-17105CriDec 19, 2017
    risk 0.73cvss 9.8epss 0.85

    Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the web interface, as demonstrated by a cgi-bin/iptest.cgi?cmd=iptest.cgi&-time="15042…

  • CVE-2017-16949CriDec 19, 2017
    risk 0.70cvss 9.8epss 0.39

    An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the attacker to override the settings for allowed file extensions and upload file size, related to inc/cores/file-uploader.php and…

  • CVE-2017-15877CriDec 19, 2017
    risk 0.64cvss 9.8epss 0.00

    Insecure Permissions vulnerability in db.php file in GPWeb 8.4.61 allows remote attackers to view the password and user database.

  • CVE-2017-15875CriDec 19, 2017
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in Password Recovery in GPWeb 8.4.61 allows remote attackers to execute arbitrary SQL commands via the "checkemail" parameter.

  • CVE-2017-15524CriDec 19, 2017
    risk 0.59cvss 9.1epss 0.00

    The Application Firewall Pack (AFP, aka Web Application Firewall) component on Kemp Load Balancer devices with software before 7.2.40.1 allows a Security Feature Bypass via an HTTP POST request.

  • CVE-2017-17721CriDec 18, 2017
    risk 0.67cvss 9.8epss 0.07

    CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter.

  • CVE-2017-17651CriDec 18, 2017
    risk 0.67cvss 9.8epss 0.03

    Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.

  • CVE-2017-17645CriDec 18, 2017
    risk 0.67cvss 9.8epss 0.03

    Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.

  • CVE-2017-17643CriDec 18, 2017
    risk 0.67cvss 9.8epss 0.02

    FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.

  • CVE-2017-17739CriDec 18, 2017
    risk 0.68cvss 9.8epss 0.21

    The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files.

  • CVE-2017-17735CriDec 18, 2017
    risk 0.64cvss 9.8epss 0.00

    CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.

  • CVE-2017-17734CriDec 18, 2017
    risk 0.64cvss 9.8epss 0.00

    CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions.

  • CVE-2017-17733CriDec 18, 2017
    risk 0.66cvss 9.8epss 0.32

    Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.

  • CVE-2017-17731CriDec 18, 2017
    risk 0.71cvss 9.8epss 0.90

    DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.

  • CVE-2017-17730CriDec 18, 2017
    risk 0.64cvss 9.8epss 0.00

    DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.

  • CVE-2017-17717CriDec 17, 2017
    risk 0.64cvss 9.8epss 0.00

    Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature.

  • CVE-2017-17713CriDec 16, 2017
    risk 0.64cvss 9.8epss 0.00

    Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp parameter, the /register lat…

  • CVE-2017-3195CriDec 16, 2017
    risk 0.70cvss 9.8epss 0.46

    Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.

  • CVE-2017-3192CriDec 16, 2017
    risk 0.66cvss 9.8epss 0.28

    D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp page discloses the administrator password in base64 encoding in the returned web page. A remote attacker with access to this page…

  • CVE-2017-3191CriDec 16, 2017
    risk 0.66cvss 9.8epss 0.34

    D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate the POST request in such a manner as to access some…

  • CVE-2017-3186CriDec 16, 2017
    risk 0.64cvss 9.8epss 0.10

    ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all devices. A remote attacker can take complete control of a device using default admin credentials.

  • CVE-2017-3185CriDec 16, 2017
    risk 0.64cvss 9.8epss 0.02

    ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through…

  • CVE-2017-3184CriDec 16, 2017
    risk 0.65cvss 9.8epss 0.14

    ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory reset page. An unauthenticated, remote attacker can exploit this vulnerability by directly accessing the…

  • CVE-2017-14090CriDec 16, 2017
    risk 0.59cvss 9.1epss 0.00

    A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted.

  • CVE-2017-10904CriDec 16, 2017
    risk 0.64cvss 9.8epss 0.01

    Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

  • CVE-2017-17701CriDec 15, 2017
    risk 0.64cvss 9.8epss 0.00

    K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025c8 DeviceIoControl request.