VYPR

CVEs

101,977 total · page 1490 of 2,040

  • CVE-2018-21202HigApr 28, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D7800 before 1.0.1.30, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.24, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR3700v4 before…

  • CVE-2017-18863HigApr 28, 2020
    risk 0.46cvss 7.1epss 0.01

    Certain NETGEAR devices are affected by command execution via a PHP form. This affects WN604 3.3.3 and earlier, WNAP210v2 3.5.20.0 and earlier, WNAP320 3.5.20.0 and earlier, WNDAP350 3.5.20.0 and earlier, WNDAP360 3.5.20.0 and earlier, WNDAP620 2.0.11 and earlier, WNDAP660…

  • CVE-2017-18861HigApr 28, 2020
    risk 0.52cvss 8.0epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects ReadyNAS Surveillance 1.4.3-15-x86 and earlier and ReadyNAS Surveillance 1.1.4-5-ARM and earlier.

  • CVE-2016-11056HigApr 28, 2020
    risk 0.57cvss 8.8epss 0.02

    Certain NETGEAR devices are affected by anonymous root access. This affects ReadyNAS Surveillance 1.1.1-3-armel and earlier and ReadyNAS Surveillance 1.4.1-3-amd64 and earlier.

  • CVE-2016-11054HigApr 28, 2020
    risk 0.47cvss 7.2epss 0.02

    NETGEAR DGN2200v4 devices before 2017-01-06 are affected by command execution and an FTP insecure root directory.

  • CVE-2020-1745HigApr 28, 2020
    risk 0.56cvss 8.6epss 0.05

    A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final and before and was fixed in 2.0.30.Final. A remote, unauthenticated attacker could exploit this vulnerability to read web…

  • CVE-2020-12078HigApr 28, 2020
    risk 0.01cvss 8.8epss 0.10

    An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker can exploit this by adding an excluded IP address to the global discovery settings (internally called exclude_ip). This exclude_ip…

  • CVE-2018-21181HigApr 28, 2020
    risk 0.47cvss 7.2epss 0.01

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D7800 before 1.0.1.28, EX2700 before 1.0.1.32, EX6200v2 before 1.0.1.56, R7500v2 before 1.0.3.24, R7800 before 1.0.2.40, R9000 before 1.0.3.6, WN2000RPTv3 before…

  • CVE-2020-5567HigApr 28, 2020
    risk 0.49cvss 7.5epss 0.01

    Improper authentication vulnerability in Cybozu Garoon 4.0.0 to 4.10.3 allows remote attackers to obtain data in Application Menu.

  • CVE-2020-9481HigApr 27, 2020
    risk 0.49cvss 7.5epss 0.02

    Apache ATS 6.0.0 to 6.2.3, 7.0.0 to 7.1.9, and 8.0.0 to 8.0.6 is vulnerable to a HTTP/2 slow read attack.

  • CVE-2020-7067HigApr 27, 2020
    risk 0.42cvss 7.5epss 0.04

    In PHP versions 7.2.x below 7.2.30, 7.3.x below 7.3.17 and 7.4.x below 7.4.5, if PHP is compiled with EBCDIC support (uncommon), urldecode() function can be made to access locations past the allocated memory, due to erroneously using signed numbers as array indexes.

  • CVE-2020-1762HigApr 27, 2020
    risk 0.39cvss 7.0epss 0.01

    An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to…

  • CVE-2018-21177HigApr 27, 2020
    risk 0.47cvss 7.2epss 0.01

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 before 1.0.0.57, R6100 before 1.0.1.20, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.92, WNDR4300 before 1.0.2.94, WNDR4300v2 before…

  • CVE-2018-21176HigApr 27, 2020
    risk 0.47cvss 7.2epss 0.02

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 before 1.0.0.57, R6100 before 1.0.1.20, R7500 before 1.0.0.122, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.92, WNDR4300 before 1.0.2.94,…

  • CVE-2018-21175HigApr 27, 2020
    risk 0.47cvss 7.2epss 0.02

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 before 1.0.0.57, R6100 before 1.0.1.20, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.92, WNDR4300 before 1.0.2.94, WNDR4300v2 before…

  • CVE-2018-21174HigApr 27, 2020
    risk 0.47cvss 7.2epss 0.02

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 before 1.0.0.57, R7500 before 1.0.0.122, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.92, WNDR4300 before 1.0.2.94, WNDR4300v2 before…

  • CVE-2018-21170HigApr 27, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects EX2700 before 1.0.1.28, R7800 before 1.0.2.40, WN2000RPTv3 before 1.0.1.20, WN3000RPv3 before 1.0.2.50, and WN3100RPv2 before 1.0.0.56.

  • CVE-2018-21169HigApr 27, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D7000 before 2018-03-01, D7800 before 1.0.1.31, D8500 before 1.0.3.36, JNR1010v2 before 1.1.0.46, JR6150 before 1.0.1.14, JWNR2010v5 before 1.1.0.46, PR2000 before 2018-03-01,…

  • CVE-2018-21168HigApr 27, 2020
    risk 0.49cvss 7.5epss 0.01

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D7000 before 1.0.1.52, D7800 before 1.0.1.31, D8500 before 1.0.3.36, JNR1010v2 before 1.1.0.46, JR6150 before 1.0.1.14, JWNR2010v5 before 1.1.0.46, PR2000 before 1.0.0.20, R6050 before…

  • CVE-2018-21158HigApr 27, 2020
    risk 0.57cvss 8.8epss 0.01

    NETGEAR R7800 devices before 1.0.2.46 are affected by incorrect configuration of security settings.

  • CVE-2018-21156HigApr 27, 2020
    risk 0.47cvss 7.2epss 0.01

    Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects D6220 before 1.0.0.38, D6400 before 1.0.0.74, D7000v2 before 1.0.0.74, D8500 before 1.0.3.39, DGN2200v4 before 1.0.0.102, DGN2200Bv4 before 1.0.0.102, EX3700 before 1.0.0.70, EX3800…

  • CVE-2018-21100HigApr 27, 2020
    risk 0.52cvss 8.0epss 0.01

    NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

  • CVE-2018-21099HigApr 27, 2020
    risk 0.52cvss 8.0epss 0.01

    NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

  • CVE-2020-11941HigApr 27, 2020
    risk 0.58cvss 8.8epss 0.05

    An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery.

  • CVE-2019-15234HigApr 27, 2020
    risk 0.49cvss 7.5epss 0.02

    SHAREit through 4.0.6.177 does not check the full message length from the received packet header (which is used to allocate memory for the next set of data). This could lead to a system denial of service due to uncontrolled memory allocation. This is different from…

  • CVE-2019-14941HigApr 27, 2020
    risk 0.49cvss 7.5epss 0.02

    SHAREit through 4.0.6.177 does not check the body length from the received packet header (which is used to allocate memory for the next set of data). This could lead to a system denial of service due to uncontrolled memory allocation.

  • CVE-2018-21096HigApr 27, 2020
    risk 0.48cvss 7.4epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4, WNAP210v2 before 3.7.11.4, WNDAP350 before 3.7.11.4, WNDAP360 before 3.7.11.4, WNDAP660 before 3.7.11.4, WNDAP620 before 2.1.7,…

  • CVE-2020-7135HigApr 27, 2020
    risk 0.51cvss 7.8epss 0.01

    A potential security vulnerability has been identified in the disk drive firmware installers named Supplemental Update / Online ROM Flash Component on HPE servers running Linux. The vulnerable software is included in the HPE Service Pack for ProLiant (SPP) releases 2018.06.0,…

  • CVE-2020-1806HigApr 27, 2020
    risk 0.46cvss 7.1epss 0.01

    Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities. Certain driver program does not sufficiently validate certain parameters received, that would lead to several bytes out of bound read. Successful exploit may…

  • CVE-2020-1805HigApr 27, 2020
    risk 0.46cvss 7.1epss 0.01

    Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities. Certain driver program does not sufficiently validate certain parameters received, that would lead to several bytes out of bound read. Successful exploit may…

  • CVE-2020-1804HigApr 27, 2020
    risk 0.46cvss 7.1epss 0.01

    Huawei Honor V10 smartphones with versions earlier than 10.0.0.156(C00E156R2P4) has three out of bounds vulnerabilities. Certain driver program does not sufficiently validate certain parameters received, that would lead to several bytes out of bound read. Successful exploit may…

  • CVE-2020-12266HigApr 27, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage. The devices automatically query these pages to update dashboards and other statistics, but the pages can…

  • CVE-2020-12242HigApr 27, 2020
    risk 0.54cvss 7.8epss 0.01

    Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a different user account.

  • CVE-2020-12138HigApr 27, 2020
    risk 0.57cvss 8.8epss 0.03

    AMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of several driver routines that map physical memory into the virtual address space of the calling process. This could enable low-privileged users to achieve NT…

  • CVE-2020-12120HigApr 27, 2020
    risk 0.49cvss 7.5epss 0.02

    The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's owner password that can be used to modify orders via SOAP. Attackers can also retrieve information about orders or buyers.

  • CVE-2019-20002HigApr 27, 2020
    risk 0.51cvss 7.8epss 0.01

    Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.

  • CVE-2018-21094HigApr 27, 2020
    risk 0.48cvss 7.3epss 0.01

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4, WNAP210v2 before 3.7.11.4, WNDAP350 before 3.7.11.4, WNDAP360 before 3.7.11.4, WNDAP660…

  • CVE-2018-21093HigApr 27, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D8500 before 1.0.3.42, EX3700 before 1.0.0.70, EX3800 before 1.0.0.70, EX6000 before 1.0.0.30, EX6100 before 1.0.2.24, EX6120 before 1.0.0.40, EX6130 before…

  • CVE-2020-12273HigApr 27, 2020
    risk 0.00cvss 7.5epss 0.01

    In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.

  • CVE-2020-10996HigApr 27, 2020
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.41.2. A bundled script inadvertently sets a static transition_key for SST processes in place of the random key expected.

  • CVE-2020-10664HigApr 27, 2020
    risk 0.49cvss 7.5epss 0.01

    The IGMP component in VxWorks 6.8.3 IPNET CVE patches created in 2019 has a NULL Pointer Dereference.

  • CVE-2020-12254HigApr 26, 2020
    risk 0.51cvss 7.8epss 0.00

    Avira Antivirus before 5.0.2003.1821 on Windows allows privilege escalation or a denial of service via abuse of a symlink.

  • CVE-2020-12070HigApr 24, 2020
    risk 0.49cvss 7.5epss 0.02

    The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulnerability in every ajax search request via the sql field to includes/class-aws-search.php.

  • CVE-2020-11004HigApr 24, 2020
    risk 0.00cvss 7.7epss 0.01

    SQL Injection was discovered in Admidio before version 3.3.13. The main cookie parameter is concatenated into a SQL query without any input validation/sanitization, thus an attacker without logging in, can send a GET request with arbitrary SQL queries appended to the cookie…

  • CVE-2020-11013HigApr 24, 2020
    risk 0.00cvss 8.5epss 0.01

    Their is an information disclosure vulnerability in Helm from version 3.1.0 and before version 3.2.0. `lookup` is a Helm template function introduced in Helm v3. It is able to lookup resources in the cluster to check for the existence of specific resources and get details about…

  • CVE-2020-6828HigApr 24, 2020
    risk 0.49cvss 7.5epss 0.01

    A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user's profile directory. One exploitation vector for this would be to supply a user.js file providing arbitrary…

  • CVE-2020-6822HigApr 24, 2020
    risk 0.57cvss 8.8epss 0.01

    On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0,…

  • CVE-2020-6821HigApr 24, 2020
    risk 0.49cvss 7.5epss 0.01

    When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This…

  • CVE-2020-6820HigKEVApr 24, 2020
    risk 0.65cvss 8.1epss 0.06

    Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

  • CVE-2020-6819HigKEVApr 24, 2020
    risk 0.65cvss 8.1epss 0.03

    Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.