VYPR

CVEs

101,977 total · page 1479 of 2,040

  • CVE-2020-7659HigJun 1, 2020
    risk 0.49cvss 7.5epss 0.01

    reel through 0.6.1 allows Request Smuggling attacks due to incorrect Content-Length and Transfer encoding header parsing. It is possible to conduct HTTP request smuggling attacks by sending the Content-Length header twice. Furthermore, invalid Transfer Encoding headers were…

  • CVE-2020-4020HigJun 1, 2020
    risk 0.47cvss 7.2epss 0.02

    The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe files via a Protection Mechanism Failure.

  • CVE-2020-4019HigJun 1, 2020
    risk 0.51cvss 7.8epss 0.00

    The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted search path vulnerability.

  • CVE-2020-4018HigJun 1, 2020
    risk 0.57cvss 8.8epss 0.01

    The setup resources in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to complete the setup process via a cross-site request forgery (CSRF) vulnerability.

  • CVE-2020-8482HigMay 29, 2020
    risk 0.51cvss 7.8epss 0.00

    Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user to read file that contains confidential data

  • CVE-2020-7654HigMay 29, 2020
    risk 0.49cvss 7.5epss 0.01

    All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG.

  • CVE-2020-6937HigMay 29, 2020
    risk 0.49cvss 7.5epss 0.01

    A Denial of Service vulnerability in MuleSoft Mule CE/EE 3.8.x, 3.9.x, and 4.x released before April 7, 2020, could allow remote attackers to submit data which can lead to resource exhaustion.

  • CVE-2020-3957HigMay 29, 2020
    risk 0.46cvss 7.0epss 0.00

    VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful…

  • CVE-2020-1870HigMay 29, 2020
    risk 0.49cvss 7.5epss 0.01

    There is a denial of service vulnerability in some Huawei products. Due to improper memory management, memory leakage may occur in some special cases. Attackers can perform a series of operations to exploit this vulnerability. Successful exploit may cause a denial of service.…

  • CVE-2020-1832HigMay 29, 2020
    risk 0.57cvss 8.8epss 0.00

    E6878-370 products with versions of 10.0.3.1(H557SP27C233) and 10.0.3.1(H563SP1C00) have a stack buffer overflow vulnerability. The program copies an input buffer to an output buffer without verification. An attacker in the adjacent network could send a crafted message,…

  • CVE-2020-8816HigKEVMay 29, 2020
    risk 0.61cvss 7.2epss 0.78

    Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static lease.

  • CVE-2020-11039HigMay 29, 2020
    risk 0.52cvss 8.0epss 0.01

    In FreeRDP less than or equal to 2.0.0, when using a manipulated server with USB redirection enabled (nearly) arbitrary memory can be read and written due to integer overflows in length checks. This has been patched in 2.1.0.

  • CVE-2020-13634HigMay 29, 2020
    risk 0.51cvss 7.8epss 0.00

    In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xF1002558

  • CVE-2020-12675HigMay 29, 2020
    risk 0.57cvss 8.8epss 0.03

    The mappress-google-maps-for-wordpress plugin before 2.54.6 for WordPress does not correctly implement capability checks for AJAX functions related to creation/retrieval/deletion of PHP template files, leading to Remote Code Execution. NOTE: this issue exists because of an…

  • CVE-2020-4352HigMay 29, 2020
    risk 0.46cvss 7.0epss 0.00

    IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when running in restricted mode. IBM X-Force ID: 178427.

  • CVE-2020-13173HigMay 28, 2020
    risk 0.51cvss 7.8epss 0.00

    Initialization of the pcoip_credential_provider in Teradici PCoIP Standard Agent for Windows and PCoIP Graphics Agent for Windows versions 19.11.1 and earlier creates an insecure named pipe, which allows an attacker to intercept sensitive information or possibly elevate…

  • CVE-2020-5357HigMay 28, 2020
    risk 0.46cvss 7.1epss 0.00

    Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The vulnerability is limited to the Dell Dock Firmware Update Utilities during the time window while being executed by an…

  • CVE-2020-11079HigMay 28, 2020
    risk 0.49cvss 8.6epss 0.03

    node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This has been fixed in 0.2.1.

  • CVE-2020-4246HigMay 28, 2020
    risk 0.46cvss 7.1epss 0.01

    IBM Security Identity Governance and Intelligence 5.2.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 175481.

  • CVE-2020-4245HigMay 28, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Security Identity Governance and Intelligence 5.2.6 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 175423.

  • CVE-2020-4232HigMay 28, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Security Identity Governance and Intelligence 5.2.6 could allow an attacker to enumerate usernames to find valid login credentials which could be used to attempt further attacks against the system. IBM X-Force ID: 175336.

  • CVE-2020-13649HigMay 28, 2020
    risk 0.00cvss 7.5epss 0.02

    parser/js/js-scanner.c in JerryScript 2.2.0 mishandles errors during certain out-of-memory conditions, as demonstrated by a scanner_reverse_info_list NULL pointer dereference and a scanner_scan_all assertion failure.

  • CVE-2020-7812HigMay 28, 2020
    risk 0.51cvss 7.8epss 0.01

    Ezhttptrans.ocx ActiveX Control in Kaoni ezHTTPTrans 1.0.0.70 and prior versions contain a vulnerability that could allow remote attacker to download arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution by rebooting the…

  • CVE-2020-11950HigMay 28, 2020
    risk 0.57cvss 8.8epss 0.03

    VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a script (with resultant execution of OS commands). For example, this affects IT9388-HT devices.

  • CVE-2020-13643HigMay 28, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The live editor feature did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The live_editor_panels_data $_POST variable allows for…

  • CVE-2020-13642HigMay 28, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the SiteOrigin Page Builder plugin before 2.10.16 for WordPress. The action_builder_content function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The panels_data $_POST variable allows for…

  • CVE-2020-13641HigMay 28, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with…

  • CVE-2020-8605HigMay 27, 2020
    risk 0.67cvss 8.8epss 0.88

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installations. Authentication is required to exploit this vulnerability.

  • CVE-2020-8604HigMay 27, 2020
    risk 0.59cvss 7.5epss 0.90

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.

  • CVE-2020-11075HigMay 27, 2020
    risk 0.00cvss 7.7epss 0.02

    In Anchore Engine version 0.7.0, a specially crafted container image manifest, fetched from a registry, can be used to trigger a shell escape flaw in the anchore engine analyzer service during an image analysis process. The image analysis operation can only be executed by an…

  • CVE-2020-10936HigMay 27, 2020
    risk 0.51cvss 7.8epss 0.01

    Sympa before 6.2.56 allows privilege escalation.

  • CVE-2020-13630HigMay 27, 2020
    risk 0.46cvss 7.0epss 0.01

    ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.

  • CVE-2020-4379HigMay 27, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 179158.

  • CVE-2020-4350HigMay 27, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 178424.

  • CVE-2020-4349HigMay 27, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Scale 5.0.0.0 through 5.0.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 178423.

  • CVE-2020-4226HigMay 27, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM MobileFirst Platform Foundation 8.0.0.0 stores highly sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 175207.

  • CVE-2020-13386HigMay 27, 2020
    risk 0.47cvss 7.3epss 0.00

    In SmartDraw 2020 27.0.0.0, the installer gives inherited write permissions to the Authenticated Users group on the SmartDraw 2020 installation folder. Additionally, when the product is installed, two scheduled tasks are created on the machine, SDMsgUpdate (Local) and…

  • CVE-2020-13623HigMay 27, 2020
    risk 0.49cvss 7.5epss 0.01

    JerryScript 2.2.0 allows attackers to cause a denial of service (stack consumption) via a proxy operation.

  • CVE-2020-13622HigMay 27, 2020
    risk 0.00cvss 7.5epss 0.01

    JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a Proxy object returns unintended data.

  • CVE-2020-9046HigMay 26, 2020
    risk 0.57cvss 8.8epss 0.00

    A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.

  • CVE-2020-6830HigMay 26, 2020
    risk 0.49cvss 7.5epss 0.01

    For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token. This vulnerability…

  • CVE-2020-12391HigMay 26, 2020
    risk 0.49cvss 7.5epss 0.01

    Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that should have been blocked, albeit with a unique opaque origin. This vulnerability affects Firefox < 76.

  • CVE-2020-12387HigMay 26, 2020
    risk 0.53cvss 8.1epss 0.01

    A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.

  • CVE-2020-12393HigMay 26, 2020
    risk 0.51cvss 7.8epss 0.01

    The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and…

  • CVE-2020-8168HigMay 26, 2020
    risk 0.57cvss 8.8epss 0.01

    We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:Attackers can abuse multiple end-points not protected against…

  • CVE-2020-3811HigMay 26, 2020
    risk 0.49cvss 7.5epss 0.02

    qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.

  • CVE-2020-13482HigMay 25, 2020
    risk 0.41cvss 7.4epss 0.01

    EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.

  • CVE-2020-13458HigMay 25, 2020
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.

  • CVE-2020-13425HigMay 23, 2020
    risk 0.46cvss 7.1epss 0.01

    TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a denial of service when battery capacity is exhausted.

  • CVE-2020-13415HigMay 22, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized to access Aviatrix), aka XML Signature…