VYPR

CVEs

101,977 total · page 1534 of 2,040

  • CVE-2020-3719HigJan 29, 2020
    risk 0.49cvss 7.5epss 0.03

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have an sql injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2020-3714HigJan 29, 2020
    risk 0.51cvss 7.8epss 0.04

    Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3713HigJan 29, 2020
    risk 0.51cvss 7.8epss 0.04

    Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3712HigJan 29, 2020
    risk 0.51cvss 7.8epss 0.03

    Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3711HigJan 29, 2020
    risk 0.51cvss 7.8epss 0.03

    Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3710HigJan 29, 2020
    risk 0.51cvss 7.8epss 0.04

    Adobe Illustrator CC versions 24.0 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2013-2574HigJan 29, 2020
    risk 0.54cvss 7.5epss 0.30

    An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /log/ directories, which could let a malicious user obtain sensitive information.

  • CVE-2013-2572HigJan 29, 2020
    risk 0.53cvss 7.5epss 0.16

    A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicious user obtain unauthorized access to CGI files.

  • CVE-2019-18634HigJan 29, 2020
    risk 0.48cvss 7.8epss 0.19

    In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however, it is NOT the default for upstream and many other packages,…

  • CVE-2013-2569HigJan 29, 2020
    risk 0.54cvss 7.5epss 0.31

    A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could let a malicious user obtain unauthorized access to the live video stream.

  • CVE-2020-8416HigJan 29, 2020
    risk 0.04cvss 7.5epss 0.14

    IKTeam BearFTP before 0.2.0 allows remote attackers to achieve denial of service via a large volume of connections to the PASV mode port.

  • CVE-2013-2567HigJan 29, 2020
    risk 0.53cvss 7.5epss 0.15

    An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.conf, which lets a remote malicious user obtain sensitive information.

  • CVE-2020-2108HigJan 29, 2020
    risk 0.49cvss 7.6epss 0.01

    Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Job/Configure permissions.

  • CVE-2020-2099HigJan 29, 2020
    risk 0.49cvss 8.6epss 0.01

    Jenkins 2.213 and earlier, LTS 2.204.1 and earlier improperly reuses encryption key parameters in the Inbound TCP Agent Protocol/3, allowing unauthorized attackers with knowledge of agent names to obtain the connection secrets for those agents, which can be used to connect to…

  • CVE-2019-7656HigJan 29, 2020
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any unprivileged Linux user to escalate privileges to root. The installer sets too relaxed permissions on /usr/local/WowzaStreamingEngine/bin/* core program files. By injecting a payload into…

  • CVE-2020-7965HigJan 29, 2020
    risk 0.50cvss 8.8epss 0.00

    flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request body is valid JSON, it will accept it even if the content type is application/x-www-form-urlencoded. This allows for JSON POST…

  • CVE-2012-4383HigJan 29, 2020
    risk 0.50cvss 8.8epss 0.01

    contao prior to 2.11.4 has a sql injection vulnerability

  • CVE-2020-8428HigJan 29, 2020
    risk 0.00cvss 7.1epss 0.01

    fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a denial of service (OOPS) or possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9. One attack vector may be an open system call for a…

  • CVE-2020-8424HigJan 28, 2020
    risk 0.60cvss 8.8epss 0.02

    Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php.

  • CVE-2013-1602HigJan 28, 2020
    risk 0.53cvss 7.5epss 0.15

    An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01, DCS-1100L 1.04, DCS-1130L 1.04, DCS-1100 1.03/1.04_US, DCS-1130 1.03/1.04_US , DCS-2102 1.05_RU/1.06/1.06_FR/1.05_TESCO, DCS-2121…

  • CVE-2020-8420HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.

  • CVE-2020-8419HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Joomla! before 3.9.15. Missing token checks in the batch actions of various components cause CSRF vulnerabilities.

  • CVE-2020-8417HigJan 28, 2020
    risk 0.58cvss 8.8epss 0.12

    The Code Snippets plugin before 2.14.0 for WordPress allows CSRF because of the lack of a Referer check on the import menu.

  • CVE-2013-3212HigJan 28, 2020
    risk 0.56cvss 8.1epss 0.08

    vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.

  • CVE-2013-3093HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.01

    ASUS RT-N56U devices allow CSRF.

  • CVE-2013-3074HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.02

    NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device crash).

  • CVE-2015-5483HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.02

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add users, (2) delete posts, or (3) modify PHP files via unspecified vectors, or…

  • CVE-2019-4707HigJan 28, 2020
    risk 0.46cvss 7.1epss 0.01

    IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 172018.

  • CVE-2019-4639HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.01

    IBM Security Secret Server 10.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 170045.

  • CVE-2019-4620HigJan 28, 2020
    risk 0.51cvss 7.8epss 0.00

    IBM MQ Appliance 8.0 and 9.0 LTS could allow a local attacker to bypass security restrictions caused by improper validation of environment variables. IBM X-Force ID: 168863.

  • CVE-2015-8012HigJan 28, 2020
    risk 0.42cvss 7.5epss 0.03

    lldpd before 0.8.0 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via a malformed packet.

  • CVE-2020-8112HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.04

    opj_t1_clbl_decode_processor in openjp2/t1.c in OpenJPEG 2.3.1 through 2020-01-28 has a heap-based buffer overflow in the qmfbid==1 case, a different issue than CVE-2020-6851.

  • CVE-2020-1940HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.05

    The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive information disclosure vulnerability. The code mandates the changed password to be passed as an additional attribute to the credentials…

  • CVE-2013-4863HigJan 28, 2020
    risk 0.61cvss 8.8epss 0.12

    The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLua action in a request to upnp/control/hag on port 49451 or (2) remote authenticated users to execute arbitrary Lua code via a…

  • CVE-2013-4862HigJan 28, 2020
    risk 0.56cvss 8.1epss 0.04

    MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via the squashfs parameter to upgrade_step2.sh or (2) obtain hashed passwords via the cgi-bin/cmh/backup.sh page.

  • CVE-2012-6610HigJan 28, 2020
    risk 0.61cvss 8.8epss 0.11

    Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated by a ; (semicolon) to the ping command feature.

  • CVE-2012-6609HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.

  • CVE-2014-3856HigJan 28, 2020
    risk 0.46cvss 7.0epss 0.00

    The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privileges via a temporary file with a predictable name.

  • CVE-2014-2906HigJan 28, 2020
    risk 0.46cvss 7.0epss 0.00

    The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands via a temporary file with a predictable name.

  • CVE-2013-4583HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.02

    The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.

  • CVE-2014-2581HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.03

    Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the "Additional options" line edit.

  • CVE-2013-1895HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.03

    The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.

  • CVE-2020-7799HigJan 28, 2020
    risk 0.48cvss 7.2epss 0.20

    An issue was discovered in FusionAuth before 1.11.0. An authenticated user, allowed to edit e-mail templates (Home -> Settings -> Email Templates) or themes (Home -> Settings -> Themes), can execute commands on the underlying operating system by abusing…

  • CVE-2020-5523HigJan 28, 2020
    risk 0.48cvss 7.4epss 0.01

    Android App 'MyPallete' and some of the Android banking applications based on 'MyPallete' do not verify X.509 certificates from servers, and also do not properly validate certificates with host-mismatch, which allows man-in-the-middle attackers to spoof servers and obtain…

  • CVE-2020-7998HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default, there is no password set for the FTP or Web UI service.

  • CVE-2019-5472HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.02

    An authorization issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 that prevented owners and maintainer to delete epic comments.

  • CVE-2019-5470HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.02

    An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboard which could result in disclosure of vulnerability feedback information.

  • CVE-2019-5468HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.02

    An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account.

  • CVE-2019-5462HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.03

    A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.

  • CVE-2019-15590HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.01

    An access control issue exists in < 12.3.5, < 12.2.8, and < 12.1.14 for GitLab Community Edition (CE) and Enterprise Edition (EE) where private merge requests and issues would be disclosed with the Group Search feature provided by Elasticsearch integration