VYPR

CVEs

101,977 total · page 1516 of 2,040

  • CVE-2020-0772HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when Windows Error Reporting improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE…

  • CVE-2020-0771HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when the Windows CSC Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows CSC Service Elevation of Privilege Vulnerability'. This CVE ID…

  • CVE-2020-0770HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows ActiveX Installer Service Elevation of Privilege…

  • CVE-2020-0769HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when the Windows CSC Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows CSC Service Elevation of Privilege Vulnerability'. This CVE ID…

  • CVE-2020-0768HigMar 12, 2020
    risk 0.49cvss 7.5epss 0.09

    A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft browsers, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827,…

  • CVE-2020-0763HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when Windows Defender Security Center handles certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Defender Security Center Elevation of Privilege Vulnerability'.…

  • CVE-2020-0762HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists when Windows Defender Security Center handles certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Defender Security Center Elevation of Privilege Vulnerability'.…

  • CVE-2020-0758HigMar 12, 2020
    risk 0.49cvss 7.5epss 0.02

    An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0815.

  • CVE-2020-0684HigMar 12, 2020
    risk 0.58cvss 8.8epss 0.09

    A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution…

  • CVE-2020-0645HigMar 12, 2020
    risk 0.49cvss 7.5epss 0.04

    A tampering vulnerability exists when Microsoft IIS Server improperly handles malformed request headers, aka 'Microsoft IIS Server Tampering Vulnerability'.

  • CVE-2020-9464HigMar 12, 2020
    risk 0.49cvss 7.5epss 0.01

    A Denial-of-Service vulnerability exists in BECKHOFF Ethernet TCP/IP Bus Coupler BK9000. After an attack has occurred, the device's functionality can be restored by rebooting.

  • CVE-2020-9436HigMar 12, 2020
    risk 0.57cvss 8.8epss 0.03

    PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices allow authenticated…

  • CVE-2020-9435HigMar 12, 2020
    risk 0.49cvss 7.5epss 0.01

    PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices contain a hardcoded…

  • CVE-2020-8435HigMar 12, 2020
    risk 0.53cvss 8.1epss 0.02

    An issue was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress. There is SQL injection via the rm_analytics_show_form rm_form_id parameter.

  • CVE-2020-10478HigMar 12, 2020
    risk 0.57cvss 8.8epss 0.01

    CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settings, potentially gaining code execution or causing a denial of service, via a crafted request.

  • CVE-2020-10390HigMar 12, 2020
    risk 0.47cvss 7.2epss 0.04

    OS Command Injection in export.php (vulnerable function called from include/functions-article.php) in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by saving the code to be executed as the wkhtmltopdf path via admin/save-settings.php.

  • CVE-2020-10389HigMar 12, 2020
    risk 0.47cvss 7.2epss 0.05

    admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code into any POST parameter when saving global settings.

  • CVE-2020-10386HigMar 12, 2020
    risk 0.51cvss 7.2epss 0.12

    admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php file in the admin/js/ directory.

  • CVE-2020-7254HigMar 12, 2020
    risk 0.50cvss 7.7epss 0.00

    Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.8.2 allows local users to execute arbitrary code via improper access controls on the sudo command.

  • CVE-2019-5181HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can cause a stack buffer…

  • CVE-2019-5180HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache file. The destination…

  • CVE-2019-5179HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache file.

  • CVE-2019-5178HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache file. The destination…

  • CVE-2019-5171HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send specially crafted packet at 0x1ea48 to the extracted hostname value from the xml file that is used as an…

  • CVE-2019-5170HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An…

  • CVE-2019-5169HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An…

  • CVE-2020-7943HigMar 11, 2020
    risk 0.49cvss 7.5epss 0.08

    Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as…

  • CVE-2019-5175HigMar 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An…

  • CVE-2019-5174HigMar 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can…

  • CVE-2019-5173HigMar 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An…

  • CVE-2019-5172HigMar 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache file. At 0x1e840 the extracted ntp value…

  • CVE-2019-10808HigMar 11, 2020
    risk 0.50cvss 8.8epss 0.02

    utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.

  • CVE-2020-5958HigMar 11, 2020
    risk 0.51cvss 7.8epss 0.00

    NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which an attacker with local system access can plant a malicious DLL file, which may lead to code execution, denial of service, or information disclosure.

  • CVE-2019-5168HigMar 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). An attacker can send a specially crafted XML cache file At 0x1e8a8 the extracted domainname value from the xml file is used as an…

  • CVE-2019-5167HigMar 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). At 0x1e3f0 the extracted dns value from the xml file is used as an argument to /etc/config-tools/edit_dns_server %s dns-server-nr=%d…

  • CVE-2019-5166HigMar 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can cause a stack buffer overflow, resulting in…

  • CVE-2019-5159HigMar 11, 2020
    risk 0.51cvss 7.8epss 0.02

    An exploitable improper input validation vulnerability exists in the firmware update functionality of WAGO e!COCKPIT automation software v1.6.0.7. A specially crafted firmware update file can allow an attacker to write arbitrary files to arbitrary locations on WAGO controllers…

  • CVE-2019-5158HigMar 11, 2020
    risk 0.51cvss 7.8epss 0.01

    An exploitable firmware downgrade vulnerability exists in the firmware update package functionality of the WAGO e!COCKPIT automation software v1.6.1.5. A specially crafted firmware update file can allow an attacker to install an older firmware version while the user thinks a…

  • CVE-2019-5157HigMar 11, 2020
    risk 0.47cvss 7.2epss 0.04

    An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject OS commands into the TimeoutUnconfirmed parameter value contained in the Firmware…

  • CVE-2019-5156HigMar 11, 2020
    risk 0.47cvss 7.2epss 0.04

    An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject operating system commands into the TimeoutPrepared parameter value contained in the firmware…

  • CVE-2019-5155HigMar 11, 2020
    risk 0.47cvss 7.2epss 0.05

    An exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC200. An attacker can inject operating system commands into any of the parameter values contained in the firmware update command. This affects WAGO PFC200 Firmware version…

  • CVE-2019-5149HigMar 11, 2020
    risk 0.49cvss 7.5epss 0.02

    The WBM web application on firmwares prior to 03.02.02 and 03.01.07 on the WAGO PFC100 and PFC2000, respectively, runs on a lighttpd web server and makes use of the FastCGI module, which is intended to provide high performance for all Internet applications without the penalties…

  • CVE-2019-5134HigMar 11, 2020
    risk 0.49cvss 7.5epss 0.02

    An exploitable regular expression without anchors vulnerability exists in the Web-Based Management (WBM) authentication functionality of WAGO PFC200 versions 03.00.39(12) and 03.01.07(13), and WAGO PFC100 version 03.00.39(12). A specially crafted authentication request can…

  • CVE-2019-5107HigMar 11, 2020
    risk 0.49cvss 7.5epss 0.01

    A cleartext transmission vulnerability exists in the network communication functionality of WAGO e!Cockpit version 1.5.1.1. An attacker with access to network traffic can easily intercept, interpret, and manipulate data coming from, or destined for e!Cockpit. This includes…

  • CVE-2020-9408HigMar 11, 2020
    risk 0.57cvss 8.8epss 0.01

    The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker with write permissions to the Spotfire Library, but not "Script Author" group…

  • CVE-2020-1981HigMar 11, 2020
    risk 0.46cvss 7.0epss 0.00

    A predictable temporary filename vulnerability in PAN-OS allows local privilege escalation. This issue allows a local attacker who bypassed the restricted shell to execute commands as a low privileged user and gain root access on the PAN-OS hardware or virtual appliance. This…

  • CVE-2020-1980HigMar 11, 2020
    risk 0.51cvss 7.8epss 0.01

    A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. This issue affects only PAN-OS 8.1 versions earlier than PAN-OS 8.1.13. This issue does not affect PAN-OS 7.1, PAN-OS 9.0, or later…

  • CVE-2020-1979HigMar 11, 2020
    risk 0.53cvss 8.1epss 0.01

    A format string vulnerability in the PAN-OS log daemon (logd) on Panorama allows a network based attacker with knowledge of registered firewall devices and access to Panorama management interfaces to execute arbitrary code, bypassing the restricted shell and escalating…

  • CVE-2013-1753HigMar 11, 2020
    risk 0.49cvss 7.5epss 0.04

    The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.

  • CVE-2019-9104HigMar 11, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains parameters that represent passwords in cleartext.