VYPR

CVEs

101,977 total · page 1525 of 2,040

  • CVE-2013-3722HigFeb 17, 2020
    risk 0.42cvss 7.5epss 0.01

    A Denial of Service (infinite loop) exists in OpenSIPS before 1.10 in lookup.c.

  • CVE-2020-1692HigFeb 17, 2020
    risk 0.53cvss 8.1epss 0.01

    Moodle before version 3.7.2 is vulnerable to information exposure of service tokens for users enrolled in the same course.

  • CVE-2020-8795HigFeb 17, 2020
    risk 0.49cvss 7.5epss 0.01

    In GitLab Enterprise Edition (EE) 12.5.0 through 12.7.5, sharing a group with a group could grant project access to unauthorized users.

  • CVE-2020-9005HigFeb 17, 2020
    risk 0.51cvss 7.8epss 0.02

    meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaming server with a crafted map, and inviting a victim to this server. A GetValue call is mishandled.

  • CVE-2020-9034HigFeb 17, 2020
    risk 0.49cvss 7.5epss 0.01

    Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenticated creation, modification, or elimination of users.

  • CVE-2019-20456HigFeb 16, 2020
    risk 0.51cvss 7.8epss 0.01

    Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking.

  • CVE-2020-8997HigFeb 16, 2020
    risk 0.57cvss 8.8epss 0.01

    Older generation Abbott FreeStyle Libre sensors allow remote attackers within close proximity to enable write access to memory via a specific NFC unlock command. NOTE: The vulnerability is not present in the FreeStyle Libre 14-day in the U.S (announced in August 2018) and…

  • CVE-2020-6068HigFeb 14, 2020
    risk 0.57cvss 8.8epss 0.04

    An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll PNG pngread parser of the Accusoft ImageGear 19.5.0 library. A specially crafted PNG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed…

  • CVE-2019-5187HigFeb 14, 2020
    risk 0.57cvss 8.8epss 0.04

    An exploitable out-of-bounds write vulnerability exists in the TIFreadstripdata function of the igcore19d.dll library of Accusoft ImageGear 19.5.0. A specially crafted TIFF file file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to…

  • CVE-2019-13967HigFeb 14, 2020
    risk 0.49cvss 7.5epss 0.01

    iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile operation. The requests use the pages/exec.php?exec_env=production&exec_module=itop-hub-connector&exec_page=ajax.php&operation=compile URI.…

  • CVE-2020-8843HigFeb 14, 2020
    risk 0.48cvss 7.4epss 0.01

    An issue was discovered in Istio 1.3 through 1.3.6. Under certain circumstances, it is possible to bypass a specifically configured Mixer policy. Istio-proxy accepts the x-istio-attributes header at ingress that can be used to affect policy decisions when Mixer policy…

  • CVE-2020-8858HigFeb 14, 2020
    risk 0.58cvss 8.8epss 0.07

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Moxa MGate 5105-MB-EIP firmware version 4.1. Authentication is required to exploit this vulnerability. The specific flaw exists within the DestIP parameter within MainPing.asp. The…

  • CVE-2020-8857HigFeb 14, 2020
    risk 0.51cvss 7.8epss 0.06

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-8856HigFeb 14, 2020
    risk 0.52cvss 7.8epss 0.20

    This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25608. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-8855HigFeb 14, 2020
    risk 0.51cvss 7.8epss 0.06

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.2947. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-8854HigFeb 14, 2020
    risk 0.51cvss 7.8epss 0.06

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-8853HigFeb 14, 2020
    risk 0.51cvss 7.8epss 0.06

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.7.0.29478. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-8851HigFeb 14, 2020
    risk 0.51cvss 7.8epss 0.06

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-8850HigFeb 14, 2020
    risk 0.51cvss 7.8epss 0.06

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-8849HigFeb 14, 2020
    risk 0.51cvss 7.8epss 0.06

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-8848HigFeb 14, 2020
    risk 0.51cvss 7.8epss 0.06

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-8847HigFeb 14, 2020
    risk 0.51cvss 7.8epss 0.06

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.7.0.29455. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-8846HigFeb 14, 2020
    risk 0.52cvss 7.8epss 0.20

    This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-8845HigFeb 14, 2020
    risk 0.52cvss 7.8epss 0.19

    This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-8844HigFeb 14, 2020
    risk 0.53cvss 7.8epss 0.24

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-8611HigFeb 14, 2020
    risk 0.57cvss 8.8epss 0.01

    In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, multiple SQL Injection vulnerabilities have been found in the REST API that could allow an authenticated attacker to gain unauthorized access to MOVEit Transfer's database via the REST API. Depending…

  • CVE-2019-11215HigFeb 14, 2020
    risk 0.53cvss 8.1epss 0.01

    In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.dataloader with a maliciously crafted payload. Many conditions can place the configuration file into a writable state: during…

  • CVE-2019-6193HigFeb 14, 2020
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encrypted password hashes.

  • CVE-2019-20045HigFeb 14, 2020
    risk 0.49cvss 7.5epss 0.01

    The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. Specially crafted malicious packets could cause disconnection of active authentic connections or reboot of device. This is a different issue than…

  • CVE-2019-19879HigFeb 14, 2020
    risk 0.49cvss 7.5epss 0.01

    HashiCorp Sentinel up to 0.10.1 incorrectly parsed negation in certain policy expressions. Fixed in 0.10.2.

  • CVE-2019-20454HigFeb 14, 2020
    risk 0.42cvss 7.5epss 0.02

    An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash…

  • CVE-2013-5687HigFeb 14, 2020
    risk 0.49cvss 7.5epss 0.01

    RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure.

  • CVE-2013-6360HigFeb 13, 2020
    risk 0.49cvss 7.5epss 0.01

    TRENDnet TS-S402 has a backdoor to enable TELNET.

  • CVE-2013-6277HigFeb 13, 2020
    risk 0.49cvss 7.5epss 0.02

    QNAP VioCard 300 has hardcoded RSA private keys.

  • CVE-2013-1634HigFeb 13, 2020
    risk 0.49cvss 7.5epss 0.02

    A denial of service vulnerability exists in some motherboard implementations of Intel e1000e/82574L network controller devices through 2013-02-06 where the device can be brought into a non-processing state when parsing 32 hex, 33 hex, or 34 hex byte values at the 0x47f offset.…

  • CVE-2015-6589HigFeb 13, 2020
    risk 0.54cvss 8.8epss 0.14

    Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.9 allows remote authenticated users to write to and execute arbitrary files due to insufficient…

  • CVE-2015-3309HigFeb 13, 2020
    risk 0.42cvss 7.5epss 0.02

    Directory traversal vulnerability in node/utils/Minify.js in Etherpad 1.1.2 through 1.5.4 allows remote attackers to read arbitrary files with permissions of the user running the service via a .. (dot dot) in the path parameter of HTTP API requests. NOTE: This vulnerability is…

  • CVE-2014-3208HigFeb 13, 2020
    risk 0.49cvss 7.5epss 0.02

    A Denial of Service vulnerability exists in askpop3d 0.7.7 in free (pszQuery),

  • CVE-2012-6091HigFeb 13, 2020
    risk 0.49cvss 7.5epss 0.02

    Zend_XmlRpc Class in Magento before 1.7.0.2 contains an information disclosure vulnerability.

  • CVE-2020-0564HigFeb 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for Intel(R) RWC3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-0563HigFeb 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for Intel(R) MPSS before version 3.8.6 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-0562HigFeb 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for Intel(R) RWC2, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-0561HigFeb 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2012-5623HigFeb 13, 2020
    risk 0.49cvss 7.5epss 0.01

    Squirrelmail 4.0 uses the outdated MD5 hash algorithm for passwords.

  • CVE-2020-0560HigFeb 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper permissions in the installer for the Intel(R) Renesas Electronics(R) USB 3.0 Driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-8801HigFeb 13, 2020
    risk 0.47cvss 7.2epss 0.03

    SuiteCRM through 7.11.11 allows PHAR Deserialization.

  • CVE-2020-8800HigFeb 13, 2020
    risk 0.57cvss 8.8epss 0.03

    SuiteCRM through 7.11.11 allows EmailsControllerActionGetFromFields PHP Object Injection.

  • CVE-2020-3759HigFeb 13, 2020
    risk 0.49cvss 7.5epss 0.04

    Adobe Digital Editions versions 4.5.10 and below have a buffer errors vulnerability. Successful exploitation could lead to information disclosure.

  • CVE-2020-3757HigFeb 13, 2020
    risk 0.58cvss 8.8epss 0.10

    Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3756HigFeb 13, 2020
    risk 0.49cvss 7.5epss 0.02

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a stack exhaustion vulnerability. Successful exploitation could lead to memory leak .