VYPR

CVEs

101,977 total · page 1540 of 2,040

  • CVE-2020-2669HigJan 15, 2020
    risk 0.53cvss 8.2epss 0.01

    Vulnerability in the Oracle Email Center product of Oracle E-Business Suite (component: Message Display). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to…

  • CVE-2020-2665HigJan 15, 2020
    risk 0.53cvss 8.2epss 0.01

    Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Others). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise…

  • CVE-2020-2662HigJan 15, 2020
    risk 0.53cvss 8.2epss 0.01

    Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Others). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise…

  • CVE-2020-2661HigJan 15, 2020
    risk 0.53cvss 8.2epss 0.01

    Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Others). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise…

  • CVE-2020-2658HigJan 15, 2020
    risk 0.53cvss 8.2epss 0.01

    Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Others). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise…

  • CVE-2020-2653HigJan 15, 2020
    risk 0.53cvss 8.2epss 0.01

    Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to…

  • CVE-2020-2652HigJan 15, 2020
    risk 0.53cvss 8.2epss 0.01

    Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to…

  • CVE-2020-2651HigJan 15, 2020
    risk 0.53cvss 8.2epss 0.01

    Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to…

  • CVE-2020-2605HigJan 15, 2020
    risk 0.46cvss 7.1epss 0.00

    Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise…

  • CVE-2020-2604HigJan 15, 2020
    risk 0.53cvss 8.1epss 0.05

    Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker…

  • CVE-2020-2591HigJan 15, 2020
    risk 0.53cvss 8.2epss 0.01

    Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Application Service). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS…

  • CVE-2020-2582HigJan 15, 2020
    risk 0.53cvss 8.2epss 0.01

    Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to…

  • CVE-2020-2565HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Solaris product of Oracle Systems (component: Consolidation Infrastructure). The supported version that is affected is 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes…

  • CVE-2020-2556HigJan 15, 2020
    risk 0.47cvss 7.3epss 0.00

    Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Core). Supported versions that are affected are 16.2.0.0-16.2.19.0, 17.12.0.0-17.12.16.0, 18.8.0.0-18.8.16.0, 19.12.0.0 and 20.1.0.0. Easily…

  • CVE-2020-2549HigJan 15, 2020
    risk 0.47cvss 7.2epss 0.02

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). The supported version that is affected is 10.3.6.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise…

  • CVE-2020-2543HigJan 15, 2020
    risk 0.48cvss 7.3epss 0.01

    Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2020-2538HigJan 15, 2020
    risk 0.46cvss 7.1epss 0.01

    Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced UI). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…

  • CVE-2020-2537HigJan 15, 2020
    risk 0.46cvss 7.1epss 0.01

    Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2020-2518HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via…

  • CVE-2020-2511HigJan 15, 2020
    risk 0.50cvss 7.7epss 0.01

    Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via OracleNet to…

  • CVE-2020-2510HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.02

    Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via OracleNet to compromise Core RDBMS.…

  • CVE-2019-16469HigJan 15, 2020
    risk 0.50cvss 7.5epss 0.17

    Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2019-16468HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.03

    Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

  • CVE-2015-6497HigJan 15, 2020
    risk 0.58cvss 8.8epss 0.07

    The create function in app/code/core/Mage/Catalog/Model/Product/Api/V2.php in Magento Community Edition (CE) before 1.9.2.1 and Enterprise Edition (EE) before 1.14.2.1, when used with PHP before 5.4.24 or 5.5.8, allows remote authenticated users to execute arbitrary PHP code via…

  • CVE-2015-5230HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.09

    The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via crafted query packets.

  • CVE-2020-2098HigJan 15, 2020
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery vulnerability in Jenkins Sounds Plugin 0.5 and earlier allows attacker to execute arbitrary OS commands as the OS user account running Jenkins.

  • CVE-2020-2097HigJan 15, 2020
    risk 0.50cvss 8.8epss 0.01

    Jenkins Sounds Plugin 0.5 and earlier does not perform permission checks in URLs performing form validation, allowing attackers with Overall/Read access to execute arbitrary OS commands as the OS user account running Jenkins.

  • CVE-2020-2093HigJan 15, 2020
    risk 0.50cvss 8.8epss 0.01

    A cross-site request forgery vulnerability in Jenkins Health Advisor by CloudBees Plugin 3.0 and earlier allows attackers to send an email with fixed content to an attacker-specified recipient.

  • CVE-2020-2092HigJan 15, 2020
    risk 0.50cvss 8.8epss 0.01

    Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with Job/Configure to have Jenkins parse crafted XML documents.

  • CVE-2020-2091HigJan 15, 2020
    risk 0.46cvss 8.1epss 0.01

    A missing permission check in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL within the AWS region using attacker-specified credentials IDs obtained through another method.

  • CVE-2020-2090HigJan 15, 2020
    risk 0.50cvss 8.8epss 0.01

    A cross-site request forgery vulnerability in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers to connect to an attacker-specified URL within the AWS region using attacker-specified credentials IDs obtained through another method.

  • CVE-2019-18412HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.01

    JetBrains IDETalk plugin before version 193.4099.10 allows XXE

  • CVE-2015-5466HigJan 15, 2020
    risk 0.54cvss 7.8epss 0.01

    Silicon Integrated Systems XGI WindowsXP Display Manager (aka XGI VGA Driver Manager and VGA Display Manager) 6.14.10.1090 allows local users to gain privileges via a crafted 0x96002404 IOCTL call.

  • CVE-2015-8549HigJan 15, 2020
    risk 0.39cvss 7.1epss 0.01

    XML external entity (XXE) vulnerability in PyAMF before 0.8.0 allows remote attackers to cause a denial of service or read arbitrary files via a crafted Action Message Format (AMF) payload.

  • CVE-2015-7556HigJan 15, 2020
    risk 0.54cvss 7.8epss 0.01

    DeleGate 9.9.13 allows local users to gain privileges as demonstrated by the dgcpnod setuid program.

  • CVE-2012-1326HigJan 15, 2020
    risk 0.48cvss 7.4epss 0.01

    Cisco IronPort Web Security Appliance up to and including 7.5 does not validate the basic constraints of the certificate authority which could lead to MITM attacks

  • CVE-2012-0070HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.01

    spamdyke prior to 4.2.1: STARTTLS reveals plaintext

  • CVE-2012-1563HigJan 15, 2020
    risk 0.52cvss 7.5epss 0.09

    Joomla! before 2.5.3 allows Admin Account Creation.

  • CVE-2012-1562HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.01

    Joomla! core before 2.5.3 allows unauthorized password change.

  • CVE-2020-1609HigJan 15, 2020
    risk 0.57cvss 8.8epss 0.01

    When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv6 packets who may then arbitrarily execute commands as root on the…

  • CVE-2020-1608HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.01

    Receipt of a specific MPLS or IPv6 packet on the core facing interface of an MX Series device configured for Broadband Edge (BBE) service may trigger a kernel crash (vmcore), causing the device to reboot. The issue is specific to the processing of packets destined to BBE clients…

  • CVE-2020-1607HigJan 15, 2020
    risk 0.49cvss 7.5epss 0.01

    Insufficient Cross-Site Scripting (XSS) protection in J-Web may potentially allow a remote attacker to inject web script or HTML, hijack the target user's J-Web session and perform administrative actions on the Junos device as the targeted user. This issue affects Juniper…

  • CVE-2020-1605HigJan 15, 2020
    risk 0.57cvss 8.8epss 0.01

    When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv4 packets who may then arbitrarily execute commands as root on the…

  • CVE-2020-1603HigJan 15, 2020
    risk 0.56cvss 8.6epss 0.01

    Specific IPv6 packets sent by clients processed by the Routing Engine (RE) are improperly handled. These IPv6 packets are designed to be blocked by the RE from egressing the RE. Instead, the RE allows these specific IPv6 packets to egress the RE, at which point a mbuf memory…

  • CVE-2020-1602HigJan 15, 2020
    risk 0.46cvss 7.1epss 0.01

    When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv4 packets who may remotely take over the code execution of the…

  • CVE-2020-7058HigJan 15, 2020
    risk 0.57cvss 8.8epss 0.02

    data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input Methods -> Unix -> Ping Host. NOTE: the vendor has stated "This is a false alarm.

  • CVE-2020-0653HigJan 14, 2020
    risk 0.52cvss 7.8epss 0.20

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0650, CVE-2020-0651.

  • CVE-2020-0652HigJan 14, 2020
    risk 0.52cvss 7.8epss 0.17

    A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Memory Corruption Vulnerability'.

  • CVE-2020-0651HigJan 14, 2020
    risk 0.52cvss 7.8epss 0.17

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0650, CVE-2020-0653.

  • CVE-2020-0650HigJan 14, 2020
    risk 0.52cvss 7.8epss 0.17

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0651, CVE-2020-0653.