VYPR

CVEs

101,977 total · page 1542 of 2,040

  • CVE-2014-5138HigJan 14, 2020
    risk 0.49cvss 7.5epss 0.02

    Innovative Interfaces Sierra Library Services Platform 1.2_3 does not properly handle query strings with multiple instances of the same parameter, which allows remote attackers to bypass parameter validation via unspecified vectors, possibly related to the Webpac Pro submodule.

  • CVE-2014-4610HigJan 14, 2020
    risk 0.58cvss 8.8epss 0.04

    Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before 1.2.7, 2.0.x before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.4 allows remote attackers to execute arbitrary code via a crafted Literal Run.

  • CVE-2014-4609HigJan 14, 2020
    risk 0.58cvss 8.8epss 0.06

    Integer overflow in the get_len function in libavutil/lzo.c in Libav before 0.8.13, 9.x before 9.14, and 10.x before 10.2 allows remote attackers to execute arbitrary code via a crafted Literal Run.

  • CVE-2019-12399HigJan 14, 2020
    risk 0.49cvss 7.5epss 0.04

    When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration…

  • CVE-2013-7185HigJan 14, 2020
    risk 0.54cvss 7.8epss 0.03

    PotPlayer 1.5.40688: .avi File Memory Corruption

  • CVE-2013-2773HigJan 14, 2020
    risk 0.51cvss 7.8epss 0.00

    Nitro PDF 8.5.0.26: A specially crafted DLL file can facilitate Arbitrary Code Execution

  • CVE-2020-5196HigJan 14, 2020
    risk 0.53cvss 8.1epss 0.01

    Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create files, display hidden files, list directories, and list files without the permission to zip and download (or unzip and upload) files. There are multiple ways to…

  • CVE-2019-19680HigJan 13, 2020
    risk 0.57cvss 8.8epss 0.01

    A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of PPS through 8.9.22 and 8.14.2 respectively, allows attackers to bypass protection mechanisms (related to extensions, MIME types, virus detection, and journal…

  • CVE-2012-4761HigJan 13, 2020
    risk 0.51cvss 7.8epss 0.00

    A Privilege Escalation vulnerability exists in the unquoted Service Binary in SDPAgent or SDBAgent in Safend Data Protector Agent 3.4.5586.9772, which could let a local malicious user obtain privileges.

  • CVE-2012-4760HigJan 13, 2020
    risk 0.51cvss 7.8epss 0.00

    A Privilege Escalation vulnerability exists in the SDBagent service in Safend Data Protector Agent 3.4.5586.9772, which could let a local malicious user obtain privileges.

  • CVE-2020-6949HigJan 13, 2020
    risk 0.57cvss 8.8epss 0.01

    A privilege escalation issue was discovered in the postUser function in HashBrown CMS through 1.3.3. An editor user can change the password hash of an admin user's account, or otherwise reconfigure that account.

  • CVE-2020-5390HigJan 13, 2020
    risk 0.42cvss 7.5epss 0.01

    PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus…

  • CVE-2019-19728HigJan 13, 2020
    risk 0.49cvss 7.5epss 0.01

    SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.

  • CVE-2019-20209HigJan 13, 2020
    risk 0.49cvss 7.5epss 0.03

    The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.

  • CVE-2019-18894HigJan 13, 2020
    risk 0.51cvss 7.8epss 0.02

    In Avast Premium Security 19.8.2393, attackers can send a specially crafted request to the local web server run by Avast Antivirus on port 27275 to support Bank Mode functionality. A flaw in the processing of a command allows execution of arbitrary OS commands with the…

  • CVE-2014-6059HigJan 13, 2020
    risk 0.47cvss 7.2epss 0.03

    WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability

  • CVE-2014-6039HigJan 13, 2020
    risk 0.57cvss 7.5epss 0.69

    ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.

  • CVE-2014-6038HigJan 13, 2020
    risk 0.58cvss 7.5epss 0.73

    Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000.

  • CVE-2014-5380HigJan 13, 2020
    risk 0.52cvss 7.5epss 0.04

    Grand MA 300 allows retrieval of the access PIN from sniffed data.

  • CVE-2020-6860HigJan 13, 2020
    risk 0.57cvss 8.8epss 0.02

    libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute.

  • CVE-2020-6851HigJan 13, 2020
    risk 0.49cvss 7.5epss 0.05

    OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

  • CVE-2020-6377HigJan 10, 2020
    risk 0.57cvss 8.8epss 0.01

    Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-19475HigJan 10, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticated Users” group can…

  • CVE-2019-13767HigJan 10, 2020
    risk 0.58cvss 8.8epss 0.16

    Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2012-4603HigJan 10, 2020
    risk 0.51cvss 7.8epss 0.07

    Citrix XenApp Online Plug-in for Windows 12.1 and earlier, and Citrix Receiver for Windows 3.2 and earlier could allow remote attackers to execute arbitrary code by convincing a target to open a specially crafted file from an SMB or WebDAV fileserver.

  • CVE-2019-18194HigJan 10, 2020
    risk 0.54cvss 7.8epss 0.02

    TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL from quarantine into the system32 folder.

  • CVE-2019-14306HigJan 10, 2020
    risk 0.49cvss 7.5epss 0.01

    Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 2 of 2).

  • CVE-2019-14304HigJan 10, 2020
    risk 0.57cvss 8.8epss 0.01

    Ricoh SP C250DN 1.06 devices allow CSRF.

  • CVE-2019-14301HigJan 10, 2020
    risk 0.49cvss 7.5epss 0.01

    Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 1 of 2).

  • CVE-2019-19820HigJan 10, 2020
    risk 0.51cvss 7.8epss 0.01

    An invalid pointer vulnerability in IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation, denial-of-service, and code execution via usermode because 0x9C402405 using METHOD_NEITHER results in a read…

  • CVE-2012-4030HigJan 10, 2020
    risk 0.49cvss 7.5epss 0.01

    Chamilo before 1.8.8.6 does not adequately handle user supplied input by the index.php script, which could allow remote attackers to delete arbitrary files.

  • CVE-2012-3824HigJan 10, 2020
    risk 0.49cvss 7.5epss 0.02

    In Arial Campaign Enterprise before 11.0.551, multiple pages are accessible without authentication or authorization.

  • CVE-2012-3823HigJan 10, 2020
    risk 0.49cvss 7.5epss 0.01

    Arial Campaign Enterprise before 11.0.551 stores passwords in clear text and these may be retrieved.

  • CVE-2012-3822HigJan 10, 2020
    risk 0.49cvss 7.5epss 0.02

    Arial Campaign Enterprise before 11.0.551 has unauthorized access to the User-Edit.asp page, which allows remote attackers to enumerate users' credentials.

  • CVE-2019-4508HigJan 10, 2020
    risk 0.51cvss 7.8epss 0.00

    IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local attacker. IBM X-Force ID: 164429.

  • CVE-2014-5092HigJan 10, 2020
    risk 0.61cvss 8.8epss 0.07

    Status2k allows Remote Command Execution in admin/options/editpl.php.

  • CVE-2013-6231HigJan 10, 2020
    risk 0.61cvss 8.8epss 0.10

    SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script

  • CVE-2014-5013HigJan 10, 2020
    risk 0.58cvss 8.8epss 0.05

    DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.

  • CVE-2020-6757HigJan 9, 2020
    risk 0.57cvss 8.8epss 0.01

    contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers to remotely execute code via the name parameter.

  • CVE-2019-20373HigJan 9, 2020
    risk 0.00cvss 7.8epss 0.00

    LTSP LDM through 2.18.06 allows fat-client root access because the LDM_USERNAME variable may have an empty value if the user's shell lacks support for Bourne shell syntax. This is related to a run-x-session script.

  • CVE-2020-5504HigJan 9, 2020
    risk 0.56cvss 8.8epss 0.39

    In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.

  • CVE-2019-20184HigJan 9, 2020
    risk 0.51cvss 7.8epss 0.02

    KeePass 2.4.1 allows CSV injection in the title field of a CSV export.

  • CVE-2019-20183HigJan 9, 2020
    risk 0.47cvss 7.2epss 0.08

    uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension validation is only on the client side. The attacker can modify global.js to allow the .php extension.

  • CVE-2019-20179HigJan 9, 2020
    risk 0.57cvss 8.8epss 0.01

    SOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.

  • CVE-2012-3810HigJan 9, 2020
    risk 0.52cvss 7.5epss 0.05

    Samsung Kies before 2.5.0.12094_27_11 has registry modification.

  • CVE-2012-3809HigJan 9, 2020
    risk 0.52cvss 7.5epss 0.05

    Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.

  • CVE-2012-3808HigJan 9, 2020
    risk 0.52cvss 7.5epss 0.05

    Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.

  • CVE-2012-3806HigJan 9, 2020
    risk 0.49cvss 7.5epss 0.04

    Samsung Kies before 2.5.0.12094_27_11 contains a NULL pointer dereference vulnerability which could allow remote attackers to perform a denial of service.

  • CVE-2012-2950HigJan 9, 2020
    risk 0.53cvss 8.1epss 0.02

    Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote attackers to execute local PHP code and obtain sensitive information.

  • CVE-2012-4434HigJan 9, 2020
    risk 0.57cvss 8.8epss 0.03

    fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arbitrary code.