VYPR

CVEs

101,977 total · page 1522 of 2,040

  • CVE-2019-18238HigFeb 26, 2020
    risk 0.49cvss 7.5epss 0.00

    In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is stored in configuration files without encryption, which may allow an attacker to access an administrative account.

  • CVE-2019-17274HigFeb 26, 2020
    risk 0.51cvss 7.8epss 0.01

    NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access.

  • CVE-2020-3175HigFeb 26, 2020
    risk 0.56cvss 8.6epss 0.02

    A vulnerability in the resource handling system of Cisco NX-OS Software for Cisco MDS 9000 Series Multilayer Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper resource…

  • CVE-2020-3173HigFeb 26, 2020
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the local management (local-mgmt) CLI of Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) on an affected device. The vulnerability is due to insufficient input…

  • CVE-2020-3172HigFeb 26, 2020
    risk 0.57cvss 8.8epss 0.02

    A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code as root or cause a denial of service (DoS) condition on an affected device. The vulnerability…

  • CVE-2020-3171HigFeb 26, 2020
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the local management (local-mgmt) CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device. The vulnerability is due to…

  • CVE-2020-3168HigFeb 26, 2020
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in the Secure Login Enhancements capability of Cisco Nexus 1000V Switch for VMware vSphere could allow an unauthenticated, remote attacker to cause an affected Nexus 1000V Virtual Supervisor Module (VSM) to become inaccessible to users through the CLI. The…

  • CVE-2020-3167HigFeb 26, 2020
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An attacker could…

  • CVE-2020-3165HigFeb 26, 2020
    risk 0.53cvss 8.2epss 0.01

    A vulnerability in the implementation of Border Gateway Protocol (BGP) Message Digest 5 (MD5) authentication in Cisco NX-OS Software could allow an unauthenticated, remote attacker to bypass MD5 authentication and establish a BGP connection with the device. The vulnerability…

  • CVE-2020-9274HigFeb 26, 2020
    risk 0.00cvss 7.5epss 0.06

    An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and…

  • CVE-2019-19989HigFeb 26, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several PHP pages, and other type of files, are reachable by any user without checking for user identity and authorization.

  • CVE-2019-19988HigFeb 26, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. A user with valid credentials is able to create and write XML files on the filesystem via /common/vam_editXml.php in the web interface. The vulnerable PHP page checks none of these: the parameter…

  • CVE-2019-19986HigFeb 26, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. An attacker without authentication is able to execute arbitrary SQL SELECT statements by injecting the HTTP (POST or GET) parameter persoid into /tools/VamPersonPhoto.php. The SQL Injection type…

  • CVE-2019-4000HigFeb 25, 2020
    risk 0.51cvss 7.8epss 0.01

    Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privileges.

  • CVE-2015-5201HigFeb 25, 2020
    risk 0.49cvss 7.5epss 0.01

    VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and…

  • CVE-2020-9394HigFeb 25, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows CSRF.

  • CVE-2020-8810HigFeb 25, 2020
    risk 0.53cvss 8.1epss 0.02

    An issue was discovered in Gurux GXDLMS Director through 8.5.1905.1301. When downloading OBIS codes, it does not verify that the downloaded files are actual OBIS codes and doesn't check for path traversal. This allows the attacker exploiting CVE-2020-8809 to send executable…

  • CVE-2020-8809HigFeb 25, 2020
    risk 0.53cvss 8.1epss 0.01

    Gurux GXDLMS Director prior to 8.5.1905.1301 downloads updates to add-ins and OBIS code over an unencrypted HTTP connection. A man-in-the-middle attacker can prompt the user to download updates by modifying the contents of gurux.fi/obis/files.xml and…

  • CVE-2019-3999HigFeb 25, 2020
    risk 0.54cvss 7.8epss 0.09

    Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.

  • CVE-2020-9017HigFeb 25, 2020
    risk 0.52cvss 8.0epss 0.01

    LiteCart through 2.2.1 allows CSV injection via a customer's profile.

  • CVE-2020-9383HigFeb 25, 2020
    risk 0.00cvss 7.1epss 0.01

    An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2.

  • CVE-2019-5165HigFeb 25, 2020
    risk 0.47cvss 7.2epss 0.02

    An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware version 1.13. A specially configured device hostname can cause the device to interpret select remote traffic as local traffic, resulting in a bypass of web…

  • CVE-2019-5162HigFeb 25, 2020
    risk 0.57cvss 8.8epss 0.03

    An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause the overwrite of an existing user account password, resulting in remote shell…

  • CVE-2019-5153HigFeb 25, 2020
    risk 0.58cvss 8.8epss 0.05

    An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted user name entry can cause an overflow of an error message buffer, resulting in remote code execution. An…

  • CVE-2019-5148HigFeb 25, 2020
    risk 0.49cvss 7.5epss 0.03

    An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware version 1.13. A specially crafted packet can cause an integer underflow, triggering a large memcpy that will access unmapped or out-of-bounds memory. An attacker…

  • CVE-2019-5143HigFeb 25, 2020
    risk 0.58cvss 8.8epss 0.05

    An exploitable format string vulnerability exists in the iw_console conio_writestr functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted time server entry can cause an overflow of the time server buffer, resulting in remote code execution. An attacker…

  • CVE-2019-5142HigFeb 25, 2020
    risk 0.47cvss 7.2epss 0.07

    An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the…

  • CVE-2019-5141HigFeb 25, 2020
    risk 0.58cvss 8.8epss 0.05

    An exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted iw_serverip parameter can cause user input to be reflected in a subsequent iw_system call, resulting in remote control over the…

  • CVE-2019-5140HigFeb 25, 2020
    risk 0.57cvss 8.8epss 0.03

    An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted diagnostic script file name can cause user input to be reflected in a subsequent iwsystem call, resulting in remote control over the…

  • CVE-2019-5139HigFeb 25, 2020
    risk 0.46cvss 7.1epss 0.00

    An exploitable use of hard-coded credentials vulnerability exists in multiple iw_* utilities of the Moxa AWK-3131A firmware version 1.13. The device operating system contains an undocumented encryption password, allowing for the creation of custom diagnostic scripts.

  • CVE-2019-5137HigFeb 25, 2020
    risk 0.49cvss 7.5epss 0.02

    The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic across the network from or to the Moxa AWK-3131A firmware version 1.13.

  • CVE-2019-5136HigFeb 25, 2020
    risk 0.57cvss 8.8epss 0.02

    An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted menu selection string can cause an escape from the restricted console, resulting in system access as the root user. An…

  • CVE-2019-4557HigFeb 25, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 166206.

  • CVE-2020-8819HigFeb 25, 2020
    risk 0.03cvss 8.1epss 0.05

    An issue was discovered in the CardGate Payments plugin through 3.1.15 for WooCommerce. Lack of origin authentication in the IPN callback processing function in cardgate/cardgate.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret key, etc.)…

  • CVE-2020-8818HigFeb 25, 2020
    risk 0.53cvss 8.1epss 0.04

    An issue was discovered in the CardGate Payments plugin through 2.0.30 for Magento 2. Lack of origin authentication in the IPN callback processing function in Controller/Payment/Callback.php allows an attacker to remotely replace critical plugin settings (merchant ID, secret…

  • CVE-2020-9385HigFeb 25, 2020
    risk 0.49cvss 7.5epss 0.02

    A NULL Pointer Dereference exists in libzint in Zint 2.7.1 because multiple + characters are mishandled in add_on in upcean.c, when called from eanx in upcean.c during EAN barcode generation.

  • CVE-2020-9381HigFeb 24, 2020
    risk 0.00cvss 7.5epss 0.02

    controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI. This can be exploited in conjunction with CVE-2019-15954.

  • CVE-2020-1937HigFeb 24, 2020
    risk 0.50cvss 8.8epss 0.03

    Kylin has some restful apis which will concatenate SQLs with the user input string, a user is likely to be able to run malicious database queries.

  • CVE-2020-9369HigFeb 24, 2020
    risk 0.49cvss 7.5epss 0.03

    Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters.

  • CVE-2020-5245HigFeb 24, 2020
    risk 0.45cvss 7.9epss 0.03

    Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature. The issue has been…

  • CVE-2020-5244HigFeb 24, 2020
    risk 0.45cvss 8.0epss 0.02

    In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Authentication is not needed. This has been patched in version 5.1.2.

  • CVE-2019-10799HigFeb 24, 2020
    risk 0.46cvss 8.2epss 0.02

    compile-sass prior to 1.0.5 allows execution of arbritary commands. The function "setupCleanupOnExit(cssPath)" within "dist/index.js" is executed as part of the "rm" command without any sanitization.

  • CVE-2012-0785HigFeb 24, 2020
    risk 0.49cvss 7.5epss 0.03

    Hash collision attack vulnerability in Jenkins before 1.447, Jenkins LTS before 1.424.2, and Jenkins Enterprise by CloudBees 1.424.x before 1.424.2.1 and 1.400.x before 1.400.0.11 could allow remote attackers to cause a considerable CPU load, aka "the Hash DoS attack."

  • CVE-2020-9365HigFeb 24, 2020
    risk 0.01cvss 7.5epss 0.07

    An issue was discovered in Pure-FTPd 1.0.49. An out-of-bounds (OOB) read has been detected in the pure_strcmp function in utils.c.

  • CVE-2020-9363HigFeb 24, 2020
    risk 0.51cvss 7.8epss 0.01

    The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway. NOTE: the vendor feels that this does not apply to…

  • CVE-2020-9362HigFeb 24, 2020
    risk 0.51cvss 7.8epss 0.02

    The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted GPFLAG in a ZIP archive. This affects Total Security, Home Security, Total Security Multi-Device, Internet Security, Total Security for Mac, AntiVirus Pro, AntiVirus for Server, and…

  • CVE-2020-8131HigFeb 24, 2020
    risk 0.00cvss 7.5epss 0.05

    Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.

  • CVE-2020-5187HigFeb 24, 2020
    risk 0.57cvss 8.8epss 0.02

    DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).

  • CVE-2019-20480HigFeb 24, 2020
    risk 0.57cvss 8.8epss 0.00

    In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious mail is allowed to make arbitrary changes in the "admin panel" because there is no CSRF protection.

  • CVE-2015-9542HigFeb 24, 2020
    risk 0.42cvss 7.5epss 0.04

    add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and…