VYPR

CVEs

101,977 total · page 1530 of 2,040

  • CVE-2020-6381HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6380HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.01

    Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.130 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted Chrome Extension.

  • CVE-2020-6379HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.01

    Use after free in V8 in Google Chrome prior to 79.0.3945.130 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6378HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.01

    Use after free in speech in Google Chrome prior to 79.0.3945.130 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2014-8347HigFeb 11, 2020
    risk 0.54cvss 7.8epss 0.01

    An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04, which could let a malicious user obtain elevated privileges.

  • CVE-2018-14553HigFeb 11, 2020
    risk 0.42cvss 7.5epss 0.03

    gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).

  • CVE-2020-8596HigFeb 11, 2020
    risk 0.49cvss 7.5epss 0.02

    participants-database.php in the Participants Database plugin 1.9.5.5 and previous versions for WordPress has a time-based SQL injection vulnerability via the ascdesc, list_filter_count, or sortBy parameters. It is possible to exfiltrate data and potentially execute code (if…

  • CVE-2020-7217HigFeb 11, 2020
    risk 0.49cvss 7.5epss 0.02

    An ni_dhcp4_fsm_process_dhcp4_packet memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets with a different client-id.

  • CVE-2020-5529HigFeb 11, 2020
    risk 0.46cvss 8.1epss 0.05

    HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of…

  • CVE-2020-3935HigFeb 11, 2020
    risk 0.49cvss 7.5epss 0.01

    TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, stores users’ information by cleartext in the cookie, which divulges password to attackers.

  • CVE-2020-8841HigFeb 10, 2020
    risk 0.00cvss 8.8epss 0.01

    An issue was discovered in TestLink 1.9.19. The relation_type parameter of the lib/requirements/reqSearch.php endpoint is vulnerable to authenticated SQL Injection.

  • CVE-2019-13322HigFeb 10, 2020
    risk 0.57cvss 8.8epss 0.03

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific…

  • CVE-2019-13321HigFeb 10, 2020
    risk 0.52cvss 8.0epss 0.01

    This vulnerability allows network adjacent attackers to execute arbitrary code on affected installations of Xiaomi Browser Prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must connect to a malicious access point. The specific flaw…

  • CVE-2019-19664HigFeb 10, 2020
    risk 0.46cvss 7.1epss 0.00

    A CSRF vulnerability exists in the Web Settings of Web File Manager in Rumpus FTP 8.2.9.1. Exploitation of this vulnerability can result in manipulation of Server Web settings at RAPR/WebSettingsGeneralSet.html.

  • CVE-2013-2109HigFeb 10, 2020
    risk 0.57cvss 8.8epss 0.02

    WordPress plugin wp-cleanfix has Remote Code Execution

  • CVE-2019-19659HigFeb 10, 2020
    risk 0.57cvss 8.8epss 0.00

    A CSRF vulnerability exists in the Web File Manager's Edit Accounts functionality of Rumpus FTP Server 8.2.9.1. By exploiting it, an attacker can take over a user account by changing the password, update users' details, and escalate privileges via RAPR/DefineUsersSet.html.

  • CVE-2014-5086HigFeb 10, 2020
    risk 0.61cvss 8.8epss 0.10

    A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5086 pertains to instances of fwrite in Sphider Pro and Sphider Plus…

  • CVE-2014-5085HigFeb 10, 2020
    risk 0.61cvss 8.8epss 0.06

    A Command Execution vulnerability exists in Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5085 pertains to instances of fwrite in Sphider Plus, but do not exist in either Sphider…

  • CVE-2014-5084HigFeb 10, 2020
    risk 0.61cvss 8.8epss 0.08

    A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious user execute arbitrary code. CVE-2014-5084 pertains to instances of fwrite in Sphider Pro only, but do not exist in either Sphider or…

  • CVE-2014-5083HigFeb 10, 2020
    risk 0.61cvss 8.8epss 0.06

    A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5083 pertains to instances of fwrite in Sphider.

  • CVE-2019-20061HigFeb 10, 2020
    risk 0.49cvss 7.5epss 0.01

    The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other words, the user is not allowed to choose their own initial password.

  • CVE-2019-20060HigFeb 10, 2020
    risk 0.49cvss 7.5epss 0.01

    MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parties may discover password-reset hashes, file-delete links, or other sensitive information.

  • CVE-2019-20059HigFeb 10, 2020
    risk 0.57cvss 8.8epss 0.01

    payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the…

  • CVE-2017-18641HigFeb 10, 2020
    risk 0.53cvss 8.1epss 0.01

    In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.

  • CVE-2012-4512HigFeb 8, 2020
    risk 0.61cvss 8.8epss 0.12

    The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."

  • CVE-2015-3423HigFeb 8, 2020
    risk 0.57cvss 8.8epss 0.02

    Multiple SQL injection vulnerabilities in NetCracker Resource Management System before 8.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) ctrl, (2) h____%2427, (3) h____%2439, (4) param0, (5) param1, (6) param2, (7) param3, (8) param4, (9)…

  • CVE-2015-2062HigFeb 8, 2020
    risk 0.47cvss 7.2epss 0.02

    Multiple SQL injection vulnerabilities in the Huge-IT Slider (slider-image) plugin before 2.7.0 for WordPress allow remote administrators to execute arbitrary SQL commands via the removeslide parameter in a popup_posts or edit_cat action in the sliders_huge_it_slider page to…

  • CVE-2012-4381HigFeb 8, 2020
    risk 0.53cvss 8.1epss 0.04

    MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict…

  • CVE-2014-7863HigFeb 8, 2020
    risk 0.58cvss 7.5epss 0.83

    The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users…

  • CVE-2014-2225HigFeb 8, 2020
    risk 0.60cvss 8.8epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in Ubiquiti Networks UniFi Controller before 3.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new admin user via a request to api/add/admin; (2) have unspecified…

  • CVE-2019-11483HigFeb 8, 2020
    risk 0.46cvss 7.0epss 0.00

    Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user.

  • CVE-2019-17136HigFeb 8, 2020
    risk 0.51cvss 7.8epss 0.05

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2019-17135HigFeb 8, 2020
    risk 0.51cvss 7.8epss 0.05

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2019-13334HigFeb 8, 2020
    risk 0.51cvss 7.8epss 0.07

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2019-13333HigFeb 8, 2020
    risk 0.51cvss 7.8epss 0.07

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw…

  • CVE-2020-8808HigFeb 7, 2020
    risk 0.51cvss 7.8epss 0.01

    The CorsairLLAccess64.sys and CorsairLLAccess32.sys drivers in CORSAIR iCUE before 3.25.60 allow local non-privileged users (including low-integrity level processes) to read and write to arbitrary physical memory locations, and consequently gain NT AUTHORITY\SYSTEM privileges,…

  • CVE-2019-19356HigKEVFeb 7, 2020
    risk 0.63cvss 7.5epss 0.28

    Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands…

  • CVE-2020-6768HigFeb 7, 2020
    risk 0.56cvss 8.6epss 0.02

    A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5…

  • CVE-2020-1708HigFeb 7, 2020
    risk 0.46cvss 7.0epss 0.00

    It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running…

  • CVE-2011-1085HigFeb 7, 2020
    risk 0.57cvss 8.8epss 0.00

    CSRF vulnerability in Smoothwall Express 3.

  • CVE-2014-5468HigFeb 7, 2020
    risk 0.64cvss 8.8epss 0.53

    A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG file, which could let a remote malicious user obtain sensitive information or execute arbitrary code.

  • CVE-2014-5288HigFeb 7, 2020
    risk 0.60cvss 8.8epss 0.02

    A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.

  • CVE-2019-18988HigKEVFeb 7, 2020
    risk 0.61cvss 7.0epss 0.05

    TeamViewer Desktop through 14.7.1965 allows a bypass of remote-login access control because the same key is used for different customers' installations. It used a shared AES key for all installations since at least as far back as v7.0.43148, and used it for at least…

  • CVE-2014-7224HigFeb 7, 2020
    risk 0.57cvss 8.8epss 0.02

    A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityTraversal objects, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-8126HigFeb 7, 2020
    risk 0.51cvss 7.8epss 0.01

    A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resulting in local commands execution, allowing an operator user (Privilege-1) to escalate privileges and became administrator (Privilege-15).

  • CVE-2019-16155HigFeb 7, 2020
    risk 0.46cvss 7.1epss 0.00

    A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to overwrite system files as root with arbitrary content through system backup file via specially crafted "BackupConfig" type IPC client requests to the fctsched…

  • CVE-2019-15604HigFeb 7, 2020
    risk 0.50cvss 7.5epss 0.20

    Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate

  • CVE-2013-3629HigFeb 7, 2020
    risk 0.64cvss 8.8epss 0.43

    ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution

  • CVE-2013-3628HigFeb 7, 2020
    risk 0.66cvss 8.8epss 0.67

    Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability

  • CVE-2013-3591HigFeb 7, 2020
    risk 0.64cvss 8.8epss 0.43

    vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability