VYPR

CVEs

97,194 total · page 1364 of 1,944

  • CVE-2020-1085HigJul 14, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in the way that the Windows Function Discovery Service handles objects in memory, aka 'Windows Function Discovery Service Elevation of Privilege Vulnerability'.

  • CVE-2020-5246HigJul 14, 2020
    risk 0.00cvss 7.7epss 0.01

    Traccar GPS Tracking System before version 4.9 has a LDAP injection vulnerability. It occurs when user input is being used in LDAP search filter. By providing specially crafted input, an attacker can modify the logic of the LDAP query and get admin privileges. The issue only…

  • CVE-2020-5374HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.01

    Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain a hard-coded cryptographic key vulnerability. A remote unauthenticated attacker may exploit this vulnerability to gain access to the appliance data for…

  • CVE-2019-12784HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the login form can accept submissions from external websites. In conjunction with CVE-2019-12783, this can be used by attackers to "crowdsource" bruteforce login attempts on the target site, allowing them…

  • CVE-2020-15074HigJul 14, 2020
    risk 0.49cvss 7.5epss 0.01

    OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circumvent the initial token expiry timestamp.

  • CVE-2020-13847HigJul 14, 2020
    risk 0.49cvss 7.5epss 0.01

    Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF file.

  • CVE-2020-13846HigJul 14, 2020
    risk 0.49cvss 7.5epss 0.01

    Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.

  • CVE-2020-13845HigJul 14, 2020
    risk 0.49cvss 7.5epss 0.01

    Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a…

  • CVE-2020-11827HigJul 14, 2020
    risk 0.51cvss 7.8epss 0.00

    In GOG Galaxy 1.2.67, there is a service that is vulnerable to weak file/service permissions: GalaxyClientService.exe. An attacker can put malicious code in a Trojan horse GalaxyClientService.exe. After that, the attacker can re-start this service as an unprivileged user to…

  • CVE-2020-13935HigJul 14, 2020
    risk 0.00cvss 7.5epss 0.88

    The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could…

  • CVE-2020-13934HigJul 14, 2020
    risk 0.54cvss 7.5epss 0.64

    An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial…

  • CVE-2020-7587HigJul 14, 2020
    risk 0.53cvss 8.2epss 0.02

    A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3),…

  • CVE-2020-7584HigJul 14, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIMATIC S7-200 SMART CPU family (All versions >= V2.2 < V2.5.1). Affected devices do not properly handle large numbers of new incomming connections and could crash under certain circumstances. An attacker may leverage this to cause a…

  • CVE-2020-7578HigJul 14, 2020
    risk 0.53cvss 8.1epss 0.01

    A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2). Authenticated users could have access to resources they normally would not have. This vulnerability could allow an attacker to view internal…

  • CVE-2020-7577HigJul 14, 2020
    risk 0.53cvss 8.1epss 0.01

    A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2). Through the use of several vulnerable fields of the application, an authenticated user could perform an SQL Injection attack by passing a modified…

  • CVE-2020-11955HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on Rittal PDU-3C002DEC through 5.15.70 and CMCIII-PU-9333E0FB through 3.15.70 devices. There are insecure permissions.

  • CVE-2020-11953HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered on Rittal PDU-3C002DEC through 5.15.40 and CMCIII-PU-9333E0FB through 3.15.70_4 devices. Attackers can execute code.

  • CVE-2020-10045HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An error in the challenge-response procedure could allow an attacker to replay authentication traffic and gain access to protected areas of the web…

  • CVE-2020-10044HigJul 14, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with access to the network could be able to install specially crafted firmware to the device.

  • CVE-2020-10039HigJul 14, 2020
    risk 0.53cvss 8.1epss 0.01

    A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker in a privileged network position between a legitimate user and the web server might be able to conduct a Man-in-the-middle attack and…

  • CVE-2020-10037HigJul 14, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). By performing a flooding attack against the web server, an attacker might be able to gain read access to the device's memory, possibly revealing…

  • CVE-2020-6292HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.01

    Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration.

  • CVE-2020-6291HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.01

    SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Session Expiration

  • CVE-2020-6289HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.00

    SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to browsing malicious site.

  • CVE-2020-4512HigJul 14, 2020
    risk 0.47cvss 7.2epss 0.02

    IBM QRadar SIEM 7.3 and 7.4 could allow a remote privileged user to execute commands.

  • CVE-2020-15711HigJul 14, 2020
    risk 0.57cvss 8.8epss 0.00

    In MISP before 2.4.129, setting a favourite homepage was not CSRF protected.

  • CVE-2020-14300HigJul 13, 2020
    risk 0.57cvss 8.8epss 0.00

    The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the…

  • CVE-2020-15050HigJul 13, 2020
    risk 0.56cvss 7.5epss 0.51

    An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the server via Directory Traversal.

  • CVE-2020-14298HigJul 13, 2020
    risk 0.57cvss 8.8epss 0.00

    The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malicious or compromised container…

  • CVE-2020-5766HigJul 13, 2020
    risk 0.49cvss 7.5epss 0.06

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to determine the value of database fields.

  • CVE-2020-15689HigJul 13, 2020
    risk 0.49cvss 7.5epss 0.01

    Appweb before 7.2.2 and 8.x before 8.1.0, when built with CGI support, mishandles an HTTP request with a Range header that lacks an exact range. This may result in a NULL pointer dereference and cause a denial of service.

  • CVE-2019-4591HigJul 13, 2020
    risk 0.51cvss 7.8epss 0.00

    IBM Maximo Asset Management 7.6.0 and 7.6.1 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 167451.

  • CVE-2019-20907HigJul 13, 2020
    risk 0.42cvss 7.5epss 0.06

    In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.

  • CVE-2019-20898HigJul 13, 2020
    risk 0.49cvss 7.5epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. The affected versions are before version 8.8.0.

  • CVE-2020-6114HigJul 10, 2020
    risk 0.47cvss 7.2epss 0.02

    An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to…

  • CVE-2020-8199HigJul 10, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Citrix ADC Gateway Linux client versions before 1.0.0.137 results in local privilege escalation to root.

  • CVE-2020-8197HigJul 10, 2020
    risk 0.57cvss 8.8epss 0.02

    Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access to execute arbitrary commands.

  • CVE-2020-8190HigJul 10, 2020
    risk 0.49cvss 7.5epss 0.01

    Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation.

  • CVE-2020-8187HigJul 10, 2020
    risk 0.49cvss 7.5epss 0.02

    Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 allows unauthenticated users to perform a denial of service attack.

  • CVE-2020-7815HigJul 10, 2020
    risk 0.51cvss 7.8epss 0.01

    XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by setting the arguments to the vulnerable method. this can be leveraged for code execution. File download vulnerability in ____COMPONENT____ of TOBESOFT XPLATFORM…

  • CVE-2020-3974HigJul 10, 2020
    risk 0.51cvss 7.8epss 0.00

    VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitation of this issue may…

  • CVE-2020-7814HigJul 10, 2020
    risk 0.51cvss 7.8epss 0.01

    RAONWIZ v2018.0.2.50 and eariler versions contains a vulnerability that could allow remote files to be downloaded and excuted by lack of validation to file extension, witch can used as remote-code-excution attacks by hackers File download & execution vulnerability in…

  • CVE-2020-4305HigJul 9, 2020
    risk 0.58cvss 8.8epss 0.05

    IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could allow a remote attacker to execute arbitrary code on the system, caused by the deserialization of untrusted data. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this…

  • CVE-2020-15093HigJul 9, 2020
    risk 0.49cvss 8.6epss 0.01

    The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a minimum threshold of unique signatures before the metadata is…

  • CVE-2020-15092HigJul 9, 2020
    risk 0.47cvss 7.2epss 0.01

    In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with maliciously crafted content in a number of data fields. This risk is present whether the source data for the timeline is stored on Google Sheets or in a JSON…

  • CVE-2020-13994HigJul 9, 2020
    risk 0.58cvss 8.8epss 0.07

    An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A privileged user can achieve code execution on the server via a ticket because of improper access control of uploaded resources. This might be exploitable in conjunction with CVE-2020-13992 by an unauthenticated…

  • CVE-2020-13993HigJul 9, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Mods for HESK 3.1.0 through 2019.1.0. A blind time-based SQL injection issue allows remote unauthenticated attackers to retrieve information from the database via a ticket.

  • CVE-2020-12426HigJul 9, 2020
    risk 0.57cvss 8.8epss 0.02

    Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects…

  • CVE-2020-12423HigJul 9, 2020
    risk 0.51cvss 7.8epss 0.00

    When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox may have loaded the DLL, leading to arbitrary code execution. *Note: This issue only affects the Windows operating system; other…

  • CVE-2020-12422HigJul 9, 2020
    risk 0.57cvss 8.8epss 0.02

    In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds write, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.