VYPR

CVEs

8,907 total · page 122 of 179

  • CVE-2017-15999CriOct 29, 2017
    risk 0.64cvss 9.8epss 0.00

    In the "NQ Contacts Backup & Restore" application 1.1 for Android, no HTTPS is used for transmitting login and synced user data. When logging in, the username is transmitted in cleartext along with an SHA-1 hash of the password. The attacker can either crack this hash or use it…

  • CVE-2017-15994CriOct 29, 2017
    risk 0.64cvss 9.8epss 0.00

    rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has significant use beyond the rsync developers, e.g., the code has been copied for use…

  • CVE-2017-15976CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.03

    ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-2008-3604.

  • CVE-2017-15975CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.03

    Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability than CVE-2008-4461.

  • CVE-2017-15974CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.04

    tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.

  • CVE-2017-15973CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.02

    Sokial Social Network Script 1.0 allows SQL Injection via the id parameter to admin/members_view.php.

  • CVE-2017-15972CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.02

    SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15971.

  • CVE-2017-15971CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.02

    Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15972.

  • CVE-2017-15970CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.03

    PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.

  • CVE-2017-15969CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.02

    PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_catalog/category.

  • CVE-2017-15968CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.02

    MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.

  • CVE-2017-15967CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.02

    Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template.

  • CVE-2017-15966CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.04

    The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php.

  • CVE-2017-15965CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.04

    The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.

  • CVE-2017-15964CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.03

    Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI.

  • CVE-2017-15963CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.02

    iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter.

  • CVE-2017-15962CriOct 29, 2017
    risk 0.68cvss 9.8epss 0.18

    iStock Management System 1.0 allows Arbitrary File Upload via user/profile.

  • CVE-2017-15961CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.03

    iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.

  • CVE-2017-15960CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.03

    Article Directory Script 3.0 allows SQL Injection via the id parameter to author.php or category.php.

  • CVE-2017-15959CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.02

    Adult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-2007-6576.

  • CVE-2017-15958CriOct 29, 2017
    risk 0.67cvss 9.8epss 0.03

    D-Park Pro Domain Parking Script 1.0 allows SQL Injection via the username to admin/loginform.php.

  • CVE-2017-15946CriOct 28, 2017
    risk 0.64cvss 9.8epss 0.00

    In the com_tag component 1.7.6 for Joomla!, a SQL injection vulnerability is located in the `tag` parameter to index.php. The request method to execute is GET.

  • CVE-2014-3600CriOct 27, 2017
    risk 0.57cvss 9.8epss 0.01

    XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.

  • CVE-2014-3579CriOct 27, 2017
    risk 0.57cvss 9.8epss 0.03

    XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.

  • CVE-2016-5003CriOct 27, 2017
    risk 0.67cvss 9.8epss 0.42

    The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.

  • CVE-2017-5053CriOct 27, 2017
    risk 0.63cvss 9.6epss 0.01

    An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to Array.prototype.indexOf.

  • CVE-2017-15366CriOct 26, 2017
    risk 0.64cvss 9.8epss 0.00

    Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password. This password is left behind in a cleartext log file during client installation on laptops. This password can be used to gain full admin/system…

  • CVE-2014-2023CriOct 26, 2017
    risk 0.67cvss 9.8epss 0.09

    Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API request to (1) unsubscribe_forum.php or (2) unsubscribe_topic.php in…

  • CVE-2012-1622CriOct 26, 2017
    risk 0.64cvss 9.8epss 0.03

    Apache OFBiz 10.04.x before 10.04.02 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2017-15919CriOct 26, 2017
    risk 0.64cvss 9.8epss 0.02

    The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php.

  • CVE-2017-15907CriOct 26, 2017
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in phpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to newsdesk/newsdesk.php.

  • CVE-2017-15909CriOct 26, 2017
    risk 0.64cvss 9.8epss 0.01

    D-Link DGS-1500 Ax devices before 2.51B021 have a hardcoded password, which allows remote attackers to obtain shell access.

  • CVE-2017-15222CriOct 24, 2017
    risk 0.73cvss 9.8epss 0.82

    Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.

  • CVE-2017-14695CriOct 24, 2017
    risk 0.57cvss 9.8epss 0.00

    Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability…

  • CVE-2015-5172CriOct 24, 2017
    risk 0.57cvss 9.8epss 0.00

    Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.

  • CVE-2015-5171CriOct 24, 2017
    risk 0.57cvss 9.8epss 0.00

    The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire existing sessions.

  • CVE-2014-1203CriOct 24, 2017
    risk 0.68cvss 9.8epss 0.56

    The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to admin/domain/ip_login_set/d_ip_login_get.php.

  • CVE-2017-15081CriOct 24, 2017
    risk 0.67cvss 9.8epss 0.07

    In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.

  • CVE-2014-3741CriOct 23, 2017
    risk 0.57cvss 9.8epss 0.02

    The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in the lpr command.

  • CVE-2012-4570CriOct 23, 2017
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2017-15580CriOct 23, 2017
    risk 0.70cvss 9.8epss 0.36

    osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a…

  • CVE-2017-15381CriOct 23, 2017
    risk 0.64cvss 9.8epss 0.00

    SQL Injection exists in E-Sic 1.0 via the f parameter to esiclivre/restrito/inc/buscacep.php (aka the zip code search script).

  • CVE-2017-15379CriOct 23, 2017
    risk 0.64cvss 9.8epss 0.03

    An authentication bypass exists in the E-Sic 1.0 /index (aka login) URI via '=''or' values for the username and password.

  • CVE-2017-12796CriOct 23, 2017
    risk 0.64cvss 9.8epss 0.06

    The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenticate users when deserializing XML input into ReportSchema objects. The result is that remote unauthenticated users are able to execute…

  • CVE-2017-7130CriOct 23, 2017
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the third-party "SQLite" product. Versions before 3.19.3 allow remote attackers to cause a…

  • CVE-2017-7129CriOct 23, 2017
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the third-party "SQLite" product. Versions before 3.19.3 allow remote attackers to cause a…

  • CVE-2017-7128CriOct 23, 2017
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in certain Apple products. iOS before 11 is affected. macOS before 10.13 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue involves the third-party "SQLite" product. Versions before 3.19.3 allow remote attackers to cause a…

  • CVE-2017-7126CriOct 23, 2017
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before 5.30 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

  • CVE-2017-7125CriOct 23, 2017
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before 5.30 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

  • CVE-2017-7124CriOct 23, 2017
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before 5.30 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.