VYPR

CVEs

101,977 total · page 1493 of 2,040

  • CVE-2020-10712HigApr 22, 2020
    risk 0.46cvss 7.0epss 0.01

    A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to gain access to those logs, to read and write to the storage backing the internal image registry. The…

  • CVE-2018-21126HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WAC505 before 5.0.0.17 and WAC510 before 5.0.0.17.

  • CVE-2018-21125HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    NETGEAR WAC510 devices before 5.0.0.17 are affected by authentication bypass.

  • CVE-2018-21124HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    NETGEAR WAC510 devices before 5.0.0.17 are affected by privilege escalation.

  • CVE-2018-21123HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects WC7500 before 6.5.3.9, WC7520 before 6.5.3.9, WC7600v1 before 6.5.3.9, and WC7600v2 before 6.5.3.9.

  • CVE-2018-21121HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by authentication bypass. This affects GS810EMX before 1.0.0.5, XS512EM before 1.0.0.6, and XS724EM before 1.0.0.6.

  • CVE-2018-21120HigApr 22, 2020
    risk 0.52cvss 8.0epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4, WNAP210v2 before 3.7.11.4, WNDAP350 before 3.7.11.4, WNDAP360 before 3.7.11.4, WNDAP660 before 3.7.11.4, WNDAP620 before 2.1.7,…

  • CVE-2018-21118HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    NETGEAR XR500 devices before 2.3.2.32 are affected by authentication bypass.

  • CVE-2017-18768HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by CSRF. This affects EX6100 before 1.0.2.16_1.1.130, EX6100v2 before 1.0.1.70, EX6150v2 before 1.0.1.54, EX6200v2 before 1.0.1.50, EX6400 before 1.0.1.60, EX7300 before 1.0.1.60, and WN3000RPv3 before 1.0.2.44.

  • CVE-2017-18764HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.02

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.55, D7000 before 1.0.1.50, D7800 before 1.0.1.28, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.10, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.18,…

  • CVE-2017-18762HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.02

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D3600 before 1.0.0.68, D6000 before 1.0.0.68, D6100 before 1.0.0.57, R6100 before 1.0.1.16, R6900P before 1.2.0.22, R7000 before 1.0.9.10, R7000P before 1.2.0.22, R7100LG…

  • CVE-2020-8477HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.02

    The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.

  • CVE-2020-8474HigApr 22, 2020
    risk 0.51cvss 7.8epss 0.00

    Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system functionality, allowing an authenticated attacker to cause system functions to stop or malfunction.

  • CVE-2018-21117HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    NETGEAR XR500 devices before 2.3.2.32 are affected by remote code execution by unauthenticated attackers via the traceroute handler.

  • CVE-2018-21116HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    NETGEAR XR500 devices before 2.3.2.32 are affected by remote code execution by unauthenticated attackers.

  • CVE-2018-21115HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    NETGEAR XR500 devices before 2.3.2.32 are affected by remote code execution by unauthenticated attackers.

  • CVE-2018-21113HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.02

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6100 before 1.0.0.58, D7800 before 1.0.1.42, R6100 before 1.0.1.28, R7500 before 1.0.0.130, R7500v2 before 1.0.3.36, R7800 before 1.0.2.52, R8900 before 1.0.4.12, R9000 before…

  • CVE-2017-18787HigApr 22, 2020
    risk 0.51cvss 7.8epss 0.01

    Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050, before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and…

  • CVE-2017-18786HigApr 22, 2020
    risk 0.51cvss 7.8epss 0.01

    Certain NETGEAR devices are affected by command injection. This affects D6200 before 1.1.00.24, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6050 before 1.0.1.12, WNR1000v4 before 1.1.0.44, WNR2020 before 1.1.0.44, and…

  • CVE-2017-18782HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JR6150 before 1.0.1.12, JNR1010v2 before 1.1.0.44, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080 before 1.0.0.26,…

  • CVE-2017-18781HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JNR1010v2 before 1.1.0.44, JWNR2010v5 before 1.1.0.44, JR6150 before 1.0.1.12, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080 before 1.0.0.26,…

  • CVE-2017-18779HigApr 22, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by a buffer overflow. This affects D6200 before 1.1.00.24, D7000 before 1.0.1.52, JNR1010v2 before 1.1.0.44, JR6150 before 1.0.1.12, JWNR2010v5 before 1.1.0.44, PR2000 before 1.0.0.20, R6020 before 1.0.0.26, R6050 before 1.0.1.12, R6080…

  • CVE-2017-18777HigApr 22, 2020
    risk 0.51cvss 7.8epss 0.00

    Certain NETGEAR devices are affected by administrative password disclosure. This affects D6220 before V1.0.0.28, D6400 before V1.0.0.60, D8500 before V1.0.3.29, DGN2200v4 before 1.0.0.82, DGN2200Bv4 before 1.0.0.82, R6300v2 before 1.0.4.8, R6400 before 1.0.1.20, R6700 before…

  • CVE-2017-18776HigApr 22, 2020
    risk 0.55cvss 8.4epss 0.00

    Certain NETGEAR devices are affected by authentication bypass. This affects D6100 before V1.0.0.55, D7000 before V1.0.1.50, D7800 before V1.0.1.24, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, R6100 before 1.0.1.12, R6220 before 1.1.0.50, R7500 before 1.0.0.108,…

  • CVE-2017-18775HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by CSRF. This affects R6100 before 1.0.1.12, R7500 before 1.0.0.108, WNDR3700v4 before 1.0.2.86, WNDR4300v1 before 1.0.2.88, WNDR4300v2 before 1.0.0.48, WNDR4500v3 before 1.0.0.48, and WNR2000v5 before 1.0.0.42.

  • CVE-2017-18772HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.01

    Certain NETGEAR devices are affected by authentication bypass. This affects EX3700 before 1.0.0.64, EX3800 before 1.0.0.64, EX6120 before 1.0.0.32, EX6130 before 1.0.0.16, R6300v2 before 1.0.4.12, R6700 before 1.0.1.26, R6900 before 1.0.1.22, R7000 before 1.0.9.6, R7300DST…

  • CVE-2020-11795HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.01

    In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.

  • CVE-2020-11693HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.02

    JetBrains YouTrack before 2020.1.659 was vulnerable to DoS that could be caused by attaching a malformed TIFF file to an issue.

  • CVE-2020-11691HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.01

    In JetBrains Hub before 2020.1.12099, content spoofing in the Hub OAuth error message was possible.

  • CVE-2020-11688HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.01

    In JetBrains TeamCity before 2019.2.1, the application state is kept alive after a user ends his session.

  • CVE-2020-11687HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.01

    In JetBrains TeamCity before 2019.2.2, password values were shown in an unmasked format on several pages.

  • CVE-2020-11685HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.01

    In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.

  • CVE-2020-11539HigApr 22, 2020
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered on Tata Sonata Smart SF Rush 1.12 devices. It has been identified that the smart band has no pairing (mode 0 Bluetooth LE security level) The data being transmitted over the air is not encrypted. Adding to this, the data being sent to the smart band…

  • CVE-2020-12059HigApr 22, 2020
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.

  • CVE-2020-12051HigApr 21, 2020
    risk 0.49cvss 7.5epss 0.01

    The CentralAuth extension through REL1_34 for MediaWiki allows remote attackers to obtain sensitive hidden account information via an api.php?action=query&meta=globaluserinfo&guiuser= request. In other words, the information can be retrieved via the action API even though access…

  • CVE-2019-4327HigApr 21, 2020
    risk 0.49cvss 7.5epss 0.01

    "HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to application's encrypted files."

  • CVE-2019-17525HigApr 21, 2020
    risk 0.61cvss 8.8epss 0.06

    The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and conduct brute-force attacks.

  • CVE-2017-18799HigApr 21, 2020
    risk 0.49cvss 7.5epss 0.01

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6200v2 before 1.0.3.14, R6250 before 1.0.4.8, R6300v2 before 1.0.4.8, R6700 before 1.1.1.20, R7000 before 1.0.7.10, R7000P/R6900P before 1.0.0.56, R7100LG before 1.0.0.30, R7900…

  • CVE-2017-18794HigApr 21, 2020
    risk 0.55cvss 8.4epss 0.01

    Certain NETGEAR devices are affected by command injection. This affects R6300v2 before 1.0.4.8_10.0.77, R6400 before 1.0.1.24, R6700 before 1.0.1.26, R7000 before 1.0.9.10, R7100LG before 1.0.0.32, R7900 before 1.0.1.18, R8000 before 1.0.3.54, R8500 before 1.0.2.100, and D6100…

  • CVE-2017-18792HigApr 21, 2020
    risk 0.55cvss 8.4epss 0.01

    NETGEAR D6100 devices before 1.0.0.50_0.0.50 are affected by command injection.

  • CVE-2017-18791HigApr 21, 2020
    risk 0.57cvss 8.8epss 0.00

    Certain NETGEAR devices are affected by CSRF. This affects R6050/JR6150 before 1.0.1.7, PR2000 before 1.0.0.17, R6220 before 1.1.0.50, WNDR3700v5 before 1.1.0.48, JNR1010v2 before 1.1.0.40, JWNR2010v5 before 1.1.0.40, WNR1000v4 before 1.1.0.40, WNR2020 before 1.1.0.40, WNR2050…

  • CVE-2020-8895HigApr 21, 2020
    risk 0.51cvss 7.8epss 0.00

    Untrusted Search Path vulnerability in the windows installer of Google Earth Pro versions prior to 7.3.3 allows an attacker to insert malicious local files to execute unauthenticated remote code on the targeted system.

  • CVE-2020-1757HigApr 21, 2020
    risk 0.53cvss 8.1epss 0.02

    A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which…

  • CVE-2020-1699HigApr 21, 2020
    risk 0.49cvss 7.5epss 0.02

    A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to cause information disclosure on the host machine…

  • CVE-2020-10787HigApr 21, 2020
    risk 0.57cvss 8.8epss 0.03

    An elevation of privilege in Vesta Control Panel through 0.9.8-26 allows an attacker to gain root system access from the admin account via v-change-user-password (aka the user password change script).

  • CVE-2020-10786HigApr 21, 2020
    risk 0.58cvss 8.8epss 0.05

    A remote command execution in Vesta Control Panel through 0.9.8-26 allows any authenticated user to execute arbitrary commands on the system via cron jobs.

  • CVE-2019-8961HigApr 21, 2020
    risk 0.49cvss 7.5epss 0.02

    A Denial of Service vulnerability related to stack exhaustion has been identified in FlexNet Publisher lmadmin.exe 11.16.2. Because the message reading function calls itself recursively given a certain condition in the received message, an unauthenticated remote attacker can…

  • CVE-2019-8960HigApr 21, 2020
    risk 0.49cvss 7.5epss 0.01

    A Denial of Service vulnerability related to command handling has been identified in FlexNet Publisher lmadmin.exe version 11.16.2. The message reading function used in lmadmin.exe can, given a certain message, call itself again and then wait for a further message. With a…

  • CVE-2020-1967HigApr 21, 2020
    risk 0.53cvss 7.5epss 0.53

    Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or…

  • CVE-2020-11828HigApr 21, 2020
    risk 0.49cvss 7.5epss 0.01

    In ColorOS (oppo mobile phone operating system, based on AOSP frameworks/native code position/services/surfaceflinger surfaceflinger.CPP), RGB is defined on the stack but uninitialized, so when the screenShot function to RGB value assignment, will not initialize the value is…