VYPR

CVEs

101,977 total · page 1507 of 2,040

  • CVE-2020-10953HigMar 27, 2020
    risk 0.49cvss 7.5epss 0.01

    In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.

  • CVE-2020-10817HigMar 27, 2020
    risk 0.57cvss 8.8epss 0.02

    The custom-searchable-data-entry-system (aka Custom Searchable Data Entry System) plugin through 1.7.1 for WordPress allows SQL Injection. NOTE: this product is discontinued.

  • CVE-2020-5863HigMar 27, 2020
    risk 0.56cvss 8.6epss 0.01

    In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upload a new license to the system but cannot view or modify any other components…

  • CVE-2020-5862HigMar 27, 2020
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.2, under certain conditions, TMM may crash or stop processing new traffic with the DPDK/ENA driver on AWS systems while sending traffic. This issue does not affect any other platforms, hardware or virtual, or any…

  • CVE-2020-5861HigMar 27, 2020
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP 12.1.0-12.1.5, the TMM process may produce a core file in some cases when Ram Cache incorrectly optimizes stored data resulting in memory errors.

  • CVE-2020-5860HigMar 27, 2020
    risk 0.53cvss 8.1epss 0.01

    On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, in a High Availability (HA) network failover in Device Service Cluster (DSC), the failover service does not require a strong form of…

  • CVE-2020-5859HigMar 27, 2020
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP 15.1.0.1, specially formatted HTTP/3 messages may cause TMM to produce a core file.

  • CVE-2020-5858HigMar 27, 2020
    risk 0.51cvss 7.8epss 0.00

    On BIG-IP 15.0.0-15.0.1.2, 14.1.0-14.1.2.2, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, users with non-administrator roles (for example, Guest or Resource Administrator) with tmsh shell access can execute arbitrary commands…

  • CVE-2020-5857HigMar 27, 2020
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, undisclosed HTTP behavior may lead to a denial of service.

  • CVE-2015-8536HigMar 27, 2020
    risk 0.57cvss 8.8epss 0.00

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that could allow cross-site request forgery.

  • CVE-2015-8535HigMar 27, 2020
    risk 0.51cvss 7.8epss 0.01

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A directory traversal vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that could allow a user to execute arbitrary…

  • CVE-2015-8534HigMar 27, 2020
    risk 0.51cvss 7.8epss 0.00

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that could allow a user to execute…

  • CVE-2015-7336HigMar 27, 2020
    risk 0.49cvss 7.5epss 0.01

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow the signature check of an update to be bypassed.

  • CVE-2015-7335HigMar 27, 2020
    risk 0.46cvss 7.0epss 0.00

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A race condition was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow a user to execute arbitrary code with elevated privileges.

  • CVE-2015-7334HigMar 27, 2020
    risk 0.51cvss 7.8epss 0.00

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type COMMAND type could…

  • CVE-2015-7333HigMar 27, 2020
    risk 0.51cvss 7.8epss 0.00

    MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type INF and…

  • CVE-2020-10607HigMar 27, 2020
    risk 0.57cvss 8.8epss 0.02

    In Advantech WebAccess, Versions 8.4.2 and prior. A stack-based buffer overflow vulnerability caused by a lack of proper validation of the length of user-supplied data may allow remote code execution.

  • CVE-2020-1773HigMar 27, 2020
    risk 0.48cvss 7.3epss 0.01

    An attacker with the ability to generate session IDs or password reset tokens, either by being able to authenticate or by exploiting OSA-2020-09, may be able to predict other users session IDs, password reset tokens and automatically generated passwords. This issue affects…

  • CVE-2020-10510HigMar 27, 2020
    risk 0.53cvss 8.1epss 0.01

    Sunnet eHRD, a human training and development management system, contains a vulnerability of Broken Access Control. After login, attackers can use a specific URL, access unauthorized functionality and data.

  • CVE-2020-10508HigMar 27, 2020
    risk 0.49cvss 7.5epss 0.01

    Sunnet eHRD, a human training and development management system, improperly stores system files. Attackers can use a specific URL and capture confidential information.

  • CVE-2020-3921HigMar 27, 2020
    risk 0.56cvss 8.6epss 0.01

    UltraLog Express device management software stores user’s information in cleartext. Any user can obtain accounts information through a specific page.

  • CVE-2020-3920HigMar 27, 2020
    risk 0.53cvss 8.1epss 0.01

    UltraLog Express device management interface does not properly perform access authentication in some specific pages/functions. Any user can access the privileged page to manage accounts through specific system directory.

  • CVE-2020-9521HigMar 26, 2020
    risk 0.57cvss 8.8epss 0.01

    An SQL injection vulnerability was discovered in Micro Focus Service Manager Automation (SMA), affecting versions 2019.08, 2019.05, 2019.02, 2018.08, 2018.05, 2018.02. The vulnerability could allow for the improper neutralization of special elements in SQL commands and may lead…

  • CVE-2020-9066HigMar 26, 2020
    risk 0.51cvss 7.8epss 0.01

    Huawei smartphones OxfordP-AN10B with versions earlier than 10.0.1.169(C00E166R4P1) have an improper authentication vulnerability. The Application doesn't perform proper authentication when user performs certain operations. An attacker can trick user into installing a malicious…

  • CVE-2020-7944HigMar 26, 2020
    risk 0.50cvss 7.7epss 0.01

    In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive parameters can result in the Sensitive parameters ending up in the impact analysis report.

  • CVE-2020-1800HigMar 26, 2020
    risk 0.51cvss 7.8epss 0.01

    HUAWEI smartphones P30 with versions earlier than 10.0.0.185(C00E85R1P11) have an improper access control vulnerability. The software incorrectly restricts access to a function interface from an unauthorized actor, the attacker tricks the user into installing a crafted…

  • CVE-2019-5105HigMar 26, 2020
    risk 0.49cvss 7.5epss 0.02

    An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solutions CODESYS GatewayService. A specially crafted packet can cause a large memcpy, resulting in an access violation and termination of the process. An attacker…

  • CVE-2020-4276HigMar 26, 2020
    risk 0.49cvss 7.5epss 0.03

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 traditional is vulnerable to a privilege escalation vulnerability when using token-based authentication in an admin request over the SOAP connector. X-Force ID: 175984.

  • CVE-2020-7260HigMar 26, 2020
    risk 0.47cvss 7.3epss 0.00

    DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary code via execution from a compromised folder.

  • CVE-2020-5129HigMar 26, 2020
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the SonicWall SMA1000 HTTP Extraweb server allows an unauthenticated remote attacker to cause HTTP server crash which leads to Denial of Service. This vulnerability affected SMA1000 Version 12.1.0-06411 and earlier.

  • CVE-2020-1764HigMar 26, 2020
    risk 0.49cvss 8.6epss 0.03

    A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining…

  • CVE-2020-10969HigMar 26, 2020
    risk 0.50cvss 8.8epss 0.03

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.

  • CVE-2020-10968HigMar 26, 2020
    risk 0.50cvss 8.8epss 0.04

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).

  • CVE-2020-10965HigMar 25, 2020
    risk 0.53cvss 8.1epss 0.01

    Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetadminpassword of the default admin account. This vulnerability only exists when the default admin account is not disabled. It is fixed in 20.01.1 and 19.11.2.

  • CVE-2020-6811HigMar 25, 2020
    risk 0.57cvss 8.8epss 0.03

    The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and…

  • CVE-2020-6809HigMar 25, 2020
    risk 0.49cvss 7.5epss 0.01

    When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to read local files. This vulnerability affects Firefox < 74.

  • CVE-2020-6807HigMar 25, 2020
    risk 0.57cvss 8.8epss 0.01

    When a device was changed while a stream was about to be destroyed, the stream-reinit task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox <…

  • CVE-2020-6806HigMar 25, 2020
    risk 0.57cvss 8.8epss 0.03

    By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox…

  • CVE-2020-6805HigMar 25, 2020
    risk 0.57cvss 8.8epss 0.01

    When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

  • CVE-2020-10963HigMar 25, 2020
    risk 0.51cvss 7.2epss 0.15

    FrozenNode Laravel-Administrator through 5.0.12 allows unrestricted file upload (and consequently Remote Code Execution) via admin/tips_image/image/file_upload image upload with PHP content within a GIF image that has the .php extension. NOTE: this product is discontinued.

  • CVE-2020-3790HigMar 25, 2020
    risk 0.57cvss 8.8epss 0.04

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3780HigMar 25, 2020
    risk 0.58cvss 8.8epss 0.05

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a buffer errors vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3779HigMar 25, 2020
    risk 0.58cvss 8.8epss 0.04

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3777HigMar 25, 2020
    risk 0.49cvss 7.5epss 0.03

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2020-3776HigMar 25, 2020
    risk 0.58cvss 8.8epss 0.05

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a buffer errors vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3774HigMar 25, 2020
    risk 0.58cvss 8.8epss 0.05

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a buffer errors vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3773HigMar 25, 2020
    risk 0.58cvss 8.8epss 0.04

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3772HigMar 25, 2020
    risk 0.58cvss 8.8epss 0.05

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a buffer errors vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3770HigMar 25, 2020
    risk 0.58cvss 8.8epss 0.05

    Adobe Photoshop CC 2019 versions 20.0.8 and earlier, and Photoshop 2020 versions 21.1 and earlier have a buffer errors vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-10884HigMar 25, 2020
    risk 0.62cvss 8.8epss 0.25

    This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service,…