VYPR

CVEs

102,253 total · page 1706 of 2,046

  • CVE-2018-18859HigNov 20, 2018
    risk 0.54cvss 7.8epss 0.02

    Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel…

  • CVE-2018-18858HigNov 20, 2018
    risk 0.54cvss 7.8epss 0.02

    Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel…

  • CVE-2018-18857HigNov 20, 2018
    risk 0.54cvss 7.8epss 0.02

    Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel…

  • CVE-2018-18856HigNov 20, 2018
    risk 0.54cvss 7.8epss 0.02

    Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel…

  • CVE-2018-18773HigNov 20, 2018
    risk 0.60cvss 8.8epss 0.03

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.

  • CVE-2018-18772HigNov 20, 2018
    risk 0.60cvss 8.8epss 0.03

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.

  • CVE-2018-18564HigNov 20, 2018
    risk 0.48cvss 7.4epss 0.01

    An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number below 14000) and 04.x before 04.03.00 (Serial Number above 14000), CoaguChek Pro II before 04.03.00, and cobas h 232 before 04.00.04 (Serial number above KQ0400000 or KS0400000).…

  • CVE-2018-18562HigNov 20, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04 and CoaguChek / cobas h232 Handheld Base Unit before 03.01.04. Weak access credentials may enable attackers in the adjacent network to gain unauthorized service access via a service…

  • CVE-2018-18561HigNov 20, 2018
    risk 0.52cvss 8.0epss 0.01

    An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04 and CoaguChek / cobas h232 Handheld Base Unit before 03.01.04. Insecure permissions in a service interface may allow authenticated attackers in the adjacent network to execute…

  • CVE-2018-18440HigNov 20, 2018
    risk 0.51cvss 7.8epss 0.01

    DENX U-Boot through 2018.09-rc1 has a locally exploitable buffer overflow via a crafted kernel image because filesystem loading is mishandled.

  • CVE-2018-1779HigNov 20, 2018
    risk 0.49cvss 7.5epss 0.02

    IBM API Connect 2018.1 through 2018.3.7 could allow an unauthenticated attacker to cause a denial of service due to not setting limits on JSON payload size. IBM X-Force ID: 148802.

  • CVE-2018-17906HigNov 19, 2018
    risk 0.57cvss 8.8epss 0.01

    Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions. Default credentials and no authentication within third party software may allow an attacker to compromise a component of the system.

  • CVE-2018-18519HigNov 19, 2018
    risk 0.51cvss 7.8epss 0.01

    BestXsoftware Best Free Keylogger before 6.0.0 allows local users to gain privileges via a Trojan horse "%PROGRAMFILES%\BFK 5.2.9\syscrb.exe" file because of insecure permissions for the BUILTIN\Users group.

  • CVE-2018-19358HigNov 18, 2018
    risk 0.51cvss 7.8epss 0.01

    GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms…

  • CVE-2018-19349HigNov 17, 2018
    risk 0.47cvss 7.2epss 0.01

    In SeaCMS v6.64, there is SQL injection via the admin_makehtml.php topic parameter because of mishandling in include/mkhtml.func.php.

  • CVE-2018-19348HigNov 17, 2018
    risk 0.46cvss 7.1epss 0.02

    The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Data from Faulting Address controls…

  • CVE-2018-19347HigNov 17, 2018
    risk 0.46cvss 7.1epss 0.02

    The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Data from Faulting Address controls…

  • CVE-2018-19346HigNov 17, 2018
    risk 0.46cvss 7.1epss 0.02

    The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Data from Faulting Address controls…

  • CVE-2018-19345HigNov 17, 2018
    risk 0.46cvss 7.1epss 0.02

    The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation near NULL…

  • CVE-2018-19344HigNov 17, 2018
    risk 0.46cvss 7.1epss 0.02

    The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Data from Faulting Address may be used…

  • CVE-2018-19343HigNov 17, 2018
    risk 0.46cvss 7.1epss 0.02

    The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read), obtain sensitive information, or possibly have unspecified other impact via a U3D sample because of a…

  • CVE-2018-19342HigNov 17, 2018
    risk 0.46cvss 7.1epss 0.02

    The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation starting at…

  • CVE-2018-19341HigNov 17, 2018
    risk 0.46cvss 7.1epss 0.02

    The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation near NULL…

  • CVE-2018-19332HigNov 17, 2018
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type=member&action=add URI.

  • CVE-2018-19331HigNov 17, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in S-CMS v1.5. There is a SQL injection vulnerability in search.php via the keyword parameter.

  • CVE-2018-19327HigNov 17, 2018
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF.

  • CVE-2018-19326HigNov 17, 2018
    risk 0.50cvss 7.5epss 0.10

    Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd.

  • CVE-2018-19274HigNov 17, 2018
    risk 0.47cvss 7.2epss 0.05

    Passing an absolute path to a file_exists check in phpBB before 3.2.4 allows Remote Code Execution through Object Injection by employing Phar deserialization when an attacker has access to the Admin Control Panel with founder permissions.

  • CVE-2018-15769HigNov 16, 2018
    risk 0.49cvss 7.5epss 0.03

    RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x series) and versions prior to 4.1.6.2 (in 4.1.x series) contain a key management error issue. A malicious TLS server could potentially cause a Denial Of Service (DoS) on TLS clients during the handshake when a very…

  • CVE-2018-18955HigNov 16, 2018
    risk 0.04cvss 7.0epss 0.08

    In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass…

  • CVE-2018-19318HigNov 16, 2018
    risk 0.57cvss 8.8epss 0.00

    SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=manager&a=update to change the username and password of the super administrator account.

  • CVE-2018-19312HigNov 16, 2018
    risk 0.00cvss 8.8epss 0.02

    Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php?p=20408 URI.

  • CVE-2018-18799HigNov 16, 2018
    risk 0.60cvss 8.8epss 0.02

    School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.

  • CVE-2018-18797HigNov 16, 2018
    risk 0.60cvss 8.8epss 0.02

    School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.

  • CVE-2018-18794HigNov 16, 2018
    risk 0.60cvss 8.8epss 0.02

    School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.

  • CVE-2018-18759HigNov 16, 2018
    risk 0.52cvss 7.5epss 0.09

    Modbus Slave 7.0.0 in modbus tools has a Buffer Overflow.

  • CVE-2018-18756HigNov 16, 2018
    risk 0.49cvss 7.5epss 0.02

    Local Server 1.0.9 has a Buffer Overflow via crafted data on Port 4008.

  • CVE-2018-16396HigNov 16, 2018
    risk 0.53cvss 8.1epss 0.08

    An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.

  • CVE-2018-7362HigNov 16, 2018
    risk 0.49cvss 7.5epss 0.01

    All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper access control vulnerability, which may allows an unauthorized user to perform unauthorized operations on the router.

  • CVE-2018-9086HigNov 16, 2018
    risk 0.47cvss 7.2epss 0.02

    In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users.

  • CVE-2018-19296HigNov 16, 2018
    risk 0.57cvss 8.8epss 0.02

    PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.

  • CVE-2018-16621HigNov 15, 2018
    risk 0.47cvss 7.2epss 0.02

    Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.

  • CVE-2018-16620HigNov 15, 2018
    risk 0.49cvss 7.5epss 0.01

    Sonatype Nexus Repository Manager before 3.14 has Incorrect Access Control.

  • CVE-2018-16162HigNov 15, 2018
    risk 0.57cvss 8.8epss 0.01

    OpenDolphin 2.7.0 and earlier allows authenticated attackers to obtain other users credentials such as a user ID and/or its password via unspecified vectors.

  • CVE-2018-16161HigNov 15, 2018
    risk 0.57cvss 8.8epss 0.01

    OpenDolphin 2.7.0 and earlier allows authenticated users to gain administrative privileges and perform unintended operations.

  • CVE-2018-16160HigNov 15, 2018
    risk 0.51cvss 7.8epss 0.00

    SecureCore Standard Edition Version 2.x allows an attacker to bypass the product 's authentication to log in to a Windows PC.

  • CVE-2018-12543HigNov 15, 2018
    risk 0.52cvss 7.5epss 0.36

    In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g. $test/test, then an assert is triggered that should otherwise not be reachable and Mosquitto will exit.

  • CVE-2018-0701HigNov 15, 2018
    risk 0.57cvss 8.8epss 0.01

    BlueStacks App Player (BlueStacks App Player for Windows 3.0.0 to 4.31.55, BlueStacks App Player for macOS 2.0.0 and later) allows an attacker on the same network segment to bypass access restriction to gain unauthorized access.

  • CVE-2018-0700HigNov 15, 2018
    risk 0.49cvss 7.5epss 0.01

    YukiWiki 2.1.3 and earlier does not process a particular request properly that may allow consumption of large amounts of CPU and memory resources and may result in causing a denial of service condition.

  • CVE-2018-0693HigNov 15, 2018
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in FileZen V3.0.0 to V4.2.1 allows remote attackers to upload an arbitrary file in the specific directory in FileZen via unspecified vectors.