VYPR

CVEs

101,977 total · page 1513 of 2,040

  • CVE-2020-10239HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in Joomla! before 3.9.16. Incorrect Access Control in the SQL fieldtype of com_fields allows access for non-superadmin users.

  • CVE-2020-10238HigMar 16, 2020
    risk 0.49cvss 7.5epss 0.06

    An issue was discovered in Joomla! before 3.9.16. Various actions in com_templates lack the required ACL checks, leading to various potential attack vectors.

  • CVE-2019-19942HigMar 16, 2020
    risk 0.49cvss 7.5epss 0.02

    Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10.18, and Centro Business 2.0 before 8.02.04 allows a remote attacker to perform DNS spoofing against the web interface via crafted hostnames in DHCP requests.

  • CVE-2019-19940HigMar 16, 2020
    risk 0.47cvss 7.2epss 0.05

    Incorrect input sanitation in text-oriented user interfaces (telnet, ssh) in Swisscom Centro Grande before 6.16.12 allows remote authenticated users to execute arbitrary commands via command injection.

  • CVE-2019-19135HigMar 16, 2020
    risk 0.41cvss 7.4epss 0.01

    In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoundation.NetStandard.Opc.Ua before 1.4.359.31, which allows man in the middle attackers to reuse encrypted user credentials sent over the network.

  • CVE-2020-10557HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in AContent through 1.4. It allows the user to run commands on the server with a low-privileged account. The upload section in the file manager page contains an arbitrary file upload vulnerability via upload.php. The extension .php7 bypasses file upload…

  • CVE-2019-19209HigMar 16, 2020
    risk 0.49cvss 7.5epss 0.02

    Dolibarr ERP/CRM before 10.0.3 allows SQL Injection.

  • CVE-2018-13063HigMar 16, 2020
    risk 0.49cvss 7.5epss 0.01

    Easy!Appointments 1.3.0 has a Missing Authorization issue allowing retrieval of hashed passwords and salts.

  • CVE-2019-10091HigMar 16, 2020
    risk 0.41cvss 7.4epss 0.01

    When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verification of the entries in the certificate SAN during the SSL handshake. This could compromise intra-cluster communication using a man-in-the-middle attack.

  • CVE-2020-5546HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.01

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows an attacker on the same network segment to stop…

  • CVE-2019-17654HigMar 15, 2020
    risk 0.57cvss 8.8epss 0.00

    An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6 and below may allow an unauthenticated attacker to perform a Cross-Site WebSocket Hijacking (CSWSH) attack.

  • CVE-2020-9290HigMar 15, 2020
    risk 0.51cvss 7.8epss 0.01

    An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineInstaller.exe resides to execute arbitrary code on the…

  • CVE-2020-9287HigMar 15, 2020
    risk 0.51cvss 7.8epss 0.01

    An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in which FortiClientEMSOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library…

  • CVE-2019-9474HigMar 15, 2020
    risk 0.49cvss 7.5epss 0.01

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID:…

  • CVE-2019-9473HigMar 15, 2020
    risk 0.49cvss 7.5epss 0.01

    In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-10 Android ID:…

  • CVE-2019-2216HigMar 15, 2020
    risk 0.47cvss 7.3epss 0.00

    In overlay notifications, there is a possible hidden notification due to improper input validation. This could lead to a local escalation of privilege because the user is not notified of an overlaying app, with User execution privileges needed. User interaction is needed for…

  • CVE-2019-2089HigMar 15, 2020
    risk 0.51cvss 7.8epss 0.00

    In app uninstallation, there is a possible set of permissions that may not be removed from a shared app ID. This could lead to a local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions:…

  • CVE-2020-10591HigMar 15, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Walmart Labs Concord before 1.44.0. CORS Access-Control-Allow-Origin headers have a potentially unsafe dependency on Origin headers, and are not configurable. This allows remote attackers to discover host information, nodes, API metadata, and…

  • CVE-2020-10589HigMar 15, 2020
    risk 0.51cvss 7.8epss 0.00

    v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/config.json is owned by a low-privileged user but contains commands that are executed as root, after v2rayL.service is restarted via Sudo.

  • CVE-2020-10588HigMar 15, 2020
    risk 0.51cvss 7.8epss 0.00

    v2rayL 2.1.3 allows local users to achieve root access because /etc/v2rayL/add.sh and /etc/v2rayL/remove.sh are owned by a low-privileged user but execute as root via Sudo.

  • CVE-2020-8141HigMar 15, 2020
    risk 0.57cvss 8.8epss 0.02

    The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Object.prototype.

  • CVE-2020-10587HigMar 14, 2020
    risk 0.51cvss 7.8epss 0.00

    antiX and MX Linux allow local users to achieve root access via "persist-config --command /bin/sh" because of the Sudo configuration.

  • CVE-2020-10578HigMar 14, 2020
    risk 0.49cvss 7.5epss 0.01

    An arbitrary file read vulnerability exists in system/controller/backend/template.php in QCMS v3.0.1.

  • CVE-2020-10573HigMar 14, 2020
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in Janus through 0.9.1. janus_audiobridge.c has a double mutex unlock when listing private rooms in AudioBridge.

  • CVE-2020-10568HigMar 14, 2020
    risk 0.57cvss 8.8epss 0.02

    The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.2 for WordPress has CSRF due to a loose comparison. This leads to remote code execution in includes/class-wp-installer.php via a series of requests that leverage unintended comparisons of integers to strings.

  • CVE-2020-10566HigMar 14, 2020
    risk 0.51cvss 7.8epss 0.00

    grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, mishandles font loading by a guest through a grub2.cfg file, leading to a buffer overflow.

  • CVE-2020-10565HigMar 14, 2020
    risk 0.51cvss 7.8epss 0.00

    grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, does not validate the address provided as part of a memrw command (read_* or write_*) by a guest through a grub2.cfg file. This allows an untrusted guest to perform arbitrary read or write operations in the…

  • CVE-2020-5240HigMar 13, 2020
    risk 0.42cvss 7.6epss 0.01

    In wagtail-2fa before 1.4.1, any user with access to the CMS can view and delete other users 2FA devices by going to the correct path. The user does not require special permissions in order to do so. By deleting the other users device they can disable the target users 2FA…

  • CVE-2020-5257HigMar 13, 2020
    risk 0.43cvss 7.7epss 0.01

    In Administrate (rubygem) before version 0.13.0, when sorting by attributes on a dashboard, the direction parameter was not validated before being interpolated into the SQL query. This could present a SQL injection if the attacker were able to modify the `direction` parameter…

  • CVE-2020-10562HigMar 13, 2020
    risk 0.00cvss 7.2epss 0.01

    An issue was discovered in DEVOME GRR before 3.4.1c. admin_edit_room.php mishandles file uploads.

  • CVE-2019-19611HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Halvotec RaQuest 10.23.10801.0. One of the exposed web services allows an anonymous user to access the list of connected users as well as the session cookie for each user. Fixed in Release 10.24.11206.1

  • CVE-2019-14309HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer firmware. This would allow to an attacker to access and read information stored on the shared FTP folders.

  • CVE-2019-14303HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    Ricoh SP C250DN 1.05 devices allow denial of service (issue 1 of 3). Some Ricoh printers were affected by a wrong LPD service implementation that lead to a denial of service vulnerability.

  • CVE-2019-13196HigMar 13, 2020
    risk 0.57cvss 8.8epss 0.02

    Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the arg4 and arg9 parameters of several functionalities of the web application that would allow an authenticated attacker to perform a Denial of Service…

  • CVE-2019-13195HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.03

    The web application of some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was vulnerable to path traversal, allowing an unauthenticated user to retrieve arbitrary files, or check if files or folders existed within the file system.

  • CVE-2019-13194HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.02

    Some Brother printers (such as the HL-L8360CDW v1.20) were affected by different information disclosure vulnerabilities that provided sensitive information to an unauthenticated user who visits a specific URL.

  • CVE-2019-13193HigMar 13, 2020
    risk 0.57cvss 8.8epss 0.03

    Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a stack buffer overflow vulnerability as the web server did not parse the cookie value properly. This would allow an attacker to execute arbitrary code on the device.

  • CVE-2019-13166HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    Some Xerox printers (such as the Phaser 3320 V53.006.16.000) did not implement account lockout. Local account credentials may be extracted from the device via brute force guessing attacks.

  • CVE-2020-10073HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page.

  • CVE-2019-13395HigMar 13, 2020
    risk 0.57cvss 8.8epss 0.00

    The Voo branded NETGEAR CG3700b custom firmware V2.02.03 allows CSRF against all /goform/ URIs. An attacker can modify all settings including WEP/WPA/WPA2 keys, restore the router to factory settings, or even upload an entire malicious configuration file.

  • CVE-2019-13393HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    The Voo branded NETGEAR CG3700b custom firmware V2.02.03 uses the same default 8 character passphrase for the administrative console and the WPA2 pre-shared key. Either an attack against HTTP Basic Authentication or an attack against WPA2 could be used to determine this…

  • CVE-2019-13206HigMar 13, 2020
    risk 0.57cvss 8.8epss 0.02

    Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in multiple parameters of the Document Boxes functionality of the web application that would allow an authenticated attacker to perform a Denial of Service…

  • CVE-2019-13205HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    All configuration parameters of certain Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were accessible by unauthenticated users. This information was only presented in the menus when authenticated, and the pages that loaded this information were also protected.…

  • CVE-2019-13203HigMar 13, 2020
    risk 0.57cvss 8.8epss 0.02

    Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by an integer overflow vulnerability in the arg3 parameter of several functionalities of the web application that would allow an authenticated attacker to perform a Denial of Service attack,…

  • CVE-2020-10089HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,

  • CVE-2020-10088HigMar 13, 2020
    risk 0.53cvss 8.1epss 0.01

    GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.

  • CVE-2020-10087HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.01

    GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.

  • CVE-2020-8571HigMar 13, 2020
    risk 0.49cvss 7.5epss 0.02

    StorageGRID (formerly StorageGRID Webscale) versions 10.0.0 through 11.3 prior to 11.2.0.8 and 11.3.0.4 are susceptible to a vulnerability which allows an unauthenticated remote attacker to cause a Denial of Service (DoS).

  • CVE-2019-19756HigMar 13, 2020
    risk 0.51cvss 7.9epss 0.00

    An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of managed systems, being written to a log file in clear text. This only affects LXCA version 2.6.0 when performing a Windows driver…

  • CVE-2020-10540HigMar 13, 2020
    risk 0.57cvss 8.8epss 0.00

    Untis WebUntis before 2020.9.6 allows CSRF for certain combinations of rights and modules.