VYPR

CVEs

102,253 total · page 1691 of 2,046

  • CVE-2018-16201HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.01

    Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier uses hard-coded credentials, which may allow an attacker on the same network segment to login to the administrators settings screen and change the configuration or execute…

  • CVE-2018-16200HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.01

    Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier allows an attacker on the same network segment to execute arbitrary OS commands.

  • CVE-2018-16198HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.00

    Toshiba Home gateway HEM-GW16A 1.2.9 and earlier, Toshiba Home gateway HEM-GW26A 1.2.9 and earlier may allow an attacker on the same network segment to access a non-documented developer screen to perform operations on the affected device.

  • CVE-2018-16196HigJan 9, 2019
    risk 0.49cvss 7.5epss 0.03

    Multiple Yokogawa products that contain Vnet/IP Open Communication Driver (CENTUM CS 3000(R3.05.00 - R3.09.50), CENTUM CS 3000 Entry Class(R3.05.00 - R3.09.50), CENTUM VP(R4.01.00 - R6.03.10), CENTUM VP Entry Class(R4.01.00 - R6.03.10), Exaopc(R3.10.00 - R3.75.00), PRM(R2.06.00…

  • CVE-2018-16195HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.01

    Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows an attacker on the same network segment to execute arbitrary OS commands via SOAP interface of UPnP.

  • CVE-2018-16194HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated attackers to execute arbitrary OS commands via unspecified vectors.

  • CVE-2018-16186HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.01

    RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.1 to V2.2 attached (D5520, D6500, D6510, D7500, D8400), and the display versions with RICOH Interactive Whiteboard…

  • CVE-2018-16185HigJan 9, 2019
    risk 0.51cvss 7.8epss 0.01

    RICOH Interactive Whiteboard D2200 V1.1 to V2.2, D5500 V1.1 to V2.2, D5510 V1.1 to V2.2, the display versions with RICOH Interactive Whiteboard Controller Type1 V1.1 to V2.2 attached (D5520, D6500, D6510, D7500, D8400), and the display versions with RICOH Interactive Whiteboard…

  • CVE-2018-16183HigJan 9, 2019
    risk 0.51cvss 7.8epss 0.01

    An unquoted search path vulnerability in some pre-installed applications on Panasonic PC run on Windows 7 (32bit), Windows 7 (64bit), Windows 8 (64bit), Windows 8.1 (64bit), Windows 10 (64bit) delivered in or later than October 2009 allow local users to gain privileges via a…

  • CVE-2018-16182HigJan 9, 2019
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in the installer of MARKET SPEED Ver.16.4 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-16178HigJan 9, 2019
    risk 0.49cvss 7.5epss 0.01

    Cybozu Garoon 3.0.0 to 4.10.0 allows remote attackers to bypass access restriction to view information available only for a sign-on user via Single sign-on function.

  • CVE-2018-16177HigJan 9, 2019
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path vulnerability in The installer of Windows 10 Fall Creators Update Modify module for Security Measures tool allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-16176HigJan 9, 2019
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in Installer of Mapping Tool 2.0.1.6 and 2.0.1.7 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-16175HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2018-16171HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.02

    Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors.

  • CVE-2018-16170HigJan 9, 2019
    risk 0.53cvss 8.1epss 0.02

    Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors.

  • CVE-2018-16169HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.01

    Cybozu Remote Service 3.0.0 to 3.1.0 allows remote authenticated attackers to upload and execute Java code file on the server via unspecified vectors.

  • CVE-2018-16166HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.02

    LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.

  • CVE-2018-1000425HigJan 9, 2019
    risk 0.51cvss 7.8epss 0.00

    An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java that allows attackers with local file system access to obtain the credentials used to connect to SonarQube.

  • CVE-2018-1000424HigJan 9, 2019
    risk 0.51cvss 7.8epss 0.00

    An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attackers with local file system access to obtain old credentials configured for the plugin before it…

  • CVE-2018-1000423HigJan 9, 2019
    risk 0.44cvss 7.8epss 0.00

    An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd…

  • CVE-2018-1000418HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.01

    An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to send test notifications to an attacker-specified HipChat server with attacker-specified credentials IDs obtained…

  • CVE-2018-1000417HigJan 9, 2019
    risk 0.46cvss 8.1epss 0.01

    A cross-site request forgery vulnerability exists in Jenkins Email Extension Template Plugin 1.0 and earlier in ExtEmailTemplateManagement.java that allows creating or removing templates.

  • CVE-2018-1000414HigJan 9, 2019
    risk 0.46cvss 8.1epss 0.01

    A cross-site request forgery vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in ConfigFilesManagement.java, FolderConfigFileAction.java that allows creating and editing configuration file definitions.

  • CVE-2018-1000412HigJan 9, 2019
    risk 0.50cvss 8.8epss 0.01

    An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read access to have Jenkins connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method,…

  • CVE-2018-1000410HigJan 9, 2019
    risk 0.44cvss 7.8epss 0.00

    An information exposure vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier, and the Stapler framework used by these releases, in core/src/main/java/org/kohsuke/stapler/RequestImpl.java, core/src/main/java/hudson/model/Descriptor.java that allows attackers…

  • CVE-2018-0704HigJan 9, 2019
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files via Keitai Screen.

  • CVE-2018-0703HigJan 9, 2019
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files via HTTP requests.

  • CVE-2018-0702HigJan 9, 2019
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in Cybozu Mailwise 5.0.0 to 5.4.5 allows remote attackers to delete arbitrary files via unspecified vectors.

  • CVE-2018-0689HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.02

    HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N firmware versions released prior to 2018 March 13, EP-10VA firmware versions released prior to 2017 September 4, EP-30VA firmware versions…

  • CVE-2018-0676HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.01

    BN-SDWBP3 firmware version 1.0.9 and earlier allows an attacker on the same network segment to bypass authentication to access to the management screen and execute an arbitrary command via unspecified vectors.

  • CVE-2018-0667HigJan 9, 2019
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in Installer of INplc SDK Express 3.08 and earlier and Installer of INplc SDK Pro+ 3.08 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2018-0641HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.02

    Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via tools_system.cgi date parameter, time parameter, and offset parameter.

  • CVE-2018-0640HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.02

    Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via netWizard.cgi date parameter, time parameter, and offset parameter.

  • CVE-2018-0639HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via tools_firmware.cgi date parameter, time parameter, and offset parameter.

  • CVE-2018-0638HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via import.cgi encKey parameter.

  • CVE-2018-0637HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via export.cgi encKey parameter.

  • CVE-2018-0636HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter of a certain URL, different URL from CVE-2018-0634.

  • CVE-2018-0635HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via filename parameter.

  • CVE-2018-0634HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter or bootmode parameter of a certain URL.

  • CVE-2018-0633HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.02

    Buffer overflow in Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary code via submit-url parameter.

  • CVE-2018-0632HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.02

    Buffer overflow in Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary code via HTTP request and response.

  • CVE-2018-0631HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.

  • CVE-2018-0630HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd parameter.

  • CVE-2018-0629HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.

  • CVE-2018-0628HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.

  • CVE-2018-0627HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.

  • CVE-2018-0626HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd in formWsc parameter.

  • CVE-2018-0625HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via formSysCmd parameter.

  • CVE-2018-6174HigJan 9, 2019
    risk 0.57cvss 8.8epss 0.03

    Integer overflows in Swiftshader in Google Chrome prior to 68.0.3440.75 potentially allowed a remote attacker to execute arbitrary code via a crafted HTML page.