VYPR

CVEs

101,999 total · page 1736 of 2,040

  • CVE-2018-14966HigAug 6, 2018
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=user&do=add page allows CSRF.

  • CVE-2018-14965HigAug 6, 2018
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in EMLsoft 5.4.5. The eml/upload/eml/?action=address&do=add page allows CSRF.

  • CVE-2018-14963HigAug 6, 2018
    risk 0.57cvss 8.8epss 0.01

    zzcms 8.3 has CSRF via the admin/adminadd.php?action=add URI.

  • CVE-2018-14960HigAug 6, 2018
    risk 0.57cvss 8.8epss 0.01

    Xiao5uCompany 1.7 has CSRF via admin/Admin.asp.

  • CVE-2018-14959HigAug 5, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in WeaselCMS v0.3.5. CSRF can create new pages via an index.php?b=pages&a=new URI.

  • CVE-2018-14958HigAug 5, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in WeaselCMS v0.3.5. CSRF can update the website settings (such as the theme, title, and description) via index.php.

  • CVE-2018-14948HigAug 5, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue has been found in dilawar sound through 2017-11-27. The end of openWavFile in wav-file.cc has Mismatched Memory Management Routines (operator new [] versus operator delete).

  • CVE-2018-14947HigAug 5, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue has been found in PDF2JSON 0.69. XmlFontAccu::CSStyle in XmlFonts.cc has Mismatched Memory Management Routines (operator new [] versus operator delete).

  • CVE-2018-14946HigAug 5, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue has been found in PDF2JSON 0.69. The HtmlString class in ImgOutputDev.cc has Mismatched Memory Management Routines (malloc versus operator delete).

  • CVE-2018-14945HigAug 5, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue has been found in jpeg_encoder through 2015-11-27. It is a heap-based buffer overflow in the function readFromBMP in jpeg_encoder.cpp.

  • CVE-2018-14944HigAug 5, 2018
    risk 0.51cvss 7.8epss 0.01

    An issue has been found in jpeg_encoder through 2015-11-27. It is a SEGV in the function readFromBMP in jpeg_encoder.cpp. The signal is caused by an out-of-bounds write.

  • CVE-2018-14942HigAug 5, 2018
    risk 0.57cvss 8.8epss 0.02

    Harmonic NSG 9000 devices allow remote authenticated users to conduct directory traversal attacks, as demonstrated by "POST /PY/EMULATION_GET_FILE" or "POST /PY/EMULATION_EXPORT" with FileName=../../../passwd in the POST data.

  • CVE-2018-14940HigAug 5, 2018
    risk 0.49cvss 7.5epss 0.01

    PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and width parameters in an api.php?op=checkcode request.

  • CVE-2018-14593HigAug 4, 2018
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30. An attacker who is logged into OTRS as an agent may escalate their privileges by accessing a specially crafted URL.

  • CVE-2018-12483HigAug 4, 2018
    risk 0.57cvss 8.8epss 0.03

    OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the ipdiscover_analyser rzo GET parameter is concatenated to a string used in an exec() call in the PHP code. Authentication is needed in order to…

  • CVE-2018-12482HigAug 4, 2018
    risk 0.57cvss 8.8epss 0.01

    OCS Inventory 2.4.1 contains multiple SQL injections in the search engine. Authentication is needed in order to exploit the issues.

  • CVE-2018-14928HigAug 3, 2018
    risk 0.49cvss 7.5epss 0.02

    /contingency/servlet/ServletFileDownload executes as root and provides unauthenticated access to files via the file parameter.

  • CVE-2018-14926HigAug 3, 2018
    risk 0.57cvss 8.8epss 0.01

    Matera Banco 1.0.0 allows CSRF, as demonstrated by a /contingency/web/messageSend/messageSendHandler.jsp request.

  • CVE-2018-14923HigAug 3, 2018
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in uniview EZPlayer 1.0.6 could allow an attacker to execute arbitrary code on a targeted system via video playback.

  • CVE-2018-5490HigAug 3, 2018
    risk 0.57cvss 8.8epss 0.01

    Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "read-only" access from authenticated SMBv2 and SMBv3 clients. This behavior has been resolved in the GA release. Customers running…

  • CVE-2018-14912HigAug 3, 2018
    risk 0.59cvss 7.5epss 0.93

    cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.

  • CVE-2018-14911HigAug 3, 2018
    risk 0.47cvss 7.2epss 0.01

    A file upload vulnerability exists in ukcms v1.1.7 and earlier. The vulnerability is due to the system not strictly filtering the file upload type. An attacker can exploit the vulnerability to upload a script Trojan to admin.php/admin/configset/index/group/upload.html to gain…

  • CVE-2018-14910HigAug 3, 2018
    risk 0.57cvss 8.8epss 0.01

    SeaCMS v6.61 allows Remote Code execution by placing PHP code in an allowed IP address (aka ip) to /admin/admin_ip.php (aka /adm1n/admin_ip.php). The code is executed by visiting adm1n/admin_ip.php or data/admin/ip.php. This can also be exploited through CSRF.

  • CVE-2018-7748HigAug 3, 2018
    risk 0.57cvss 8.8epss 0.03

    report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Injection in the sysparm_media parameter.

  • CVE-2018-14908HigAug 3, 2018
    risk 0.57cvss 8.8epss 0.01

    Samsung Syncthru Web Service V4.05.61 is vulnerable to CSRF on every request, as demonstrated by sws.application/printinformation/printReportSetupView.sws for a "Print emails sent" action.

  • CVE-2018-14715HigAug 3, 2018
    risk 0.49cvss 7.5epss 0.01

    The endCoinFlip function and throwSlammer function of the smart contract implementations for Cryptogs, an Ethereum game, generate random numbers with an old block's hash. Therefore, attackers can predict the random number and always win the game.

  • CVE-2018-14576HigAug 3, 2018
    risk 0.49cvss 7.5epss 0.02

    The mintTokens function of a smart contract implementation for SunContract, an Ethereum token, has an integer overflow via the _amount variable.

  • CVE-2017-15358HigAug 3, 2018
    risk 0.49cvss 7.0epss 0.01

    Race condition in the Charles Proxy Settings suid binary in Charles Proxy before 4.2.1 allows local users to gain privileges via vectors involving the --self-repair option.

  • CVE-2018-14774HigAug 3, 2018
    risk 0.40cvss 7.2epss 0.01

    An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the X-Forwarded-Host headers are implicitly set as trusted…

  • CVE-2018-1524HigAug 3, 2018
    risk 0.57cvss 8.8epss 0.02

    IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.

  • CVE-2017-8316HigAug 3, 2018
    risk 0.49cvss 7.5epss 0.02

    IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.

  • CVE-2018-14884HigAug 3, 2018
    risk 0.42cvss 7.5epss 0.03

    An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a segmentation fault because http_header_value in ext/standard/http_fopen_wrapper.c can be a NULL value that is mishandled in an…

  • CVE-2018-14883HigAug 3, 2018
    risk 0.42cvss 7.5epss 0.09

    An issue was discovered in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. An Integer Overflow leads to a heap-based buffer over-read in exif_thumbnail_extract of exif.c.

  • CVE-2018-14872HigAug 3, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Rincewind 0.1. A reinstall vulnerability exists because the parameter p of index.php and another file named commonPages.php allows an attacker to reinstall the product, with all data reset.

  • CVE-2018-14858HigAug 2, 2018
    risk 0.49cvss 7.5epss 0.01

    An SSRF vulnerability was discovered in idreamsoft iCMS before V7.0.11 because the remote function in app/spider/spider_tools.class.php does not block private and reserved IP addresses such as 10.0.0.0/8. NOTE: this vulnerability exists because of an incomplete fix for…

  • CVE-2018-3834HigAug 2, 2018
    risk 0.48cvss 7.4epss 0.01

    An exploitable permanent denial of service vulnerability exists in Insteon Hub running firmware version 1013. The firmware upgrade functionality, triggered via PubNub, retrieves signed firmware binaries using plain HTTP requests. The device doesn't check the kind of firmware…

  • CVE-2018-1154HigAug 2, 2018
    risk 0.57cvss 8.8epss 0.01

    In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username aliases via brute force, ultimately facilitating unauthorized access. Server response output has been unified to correct this…

  • CVE-2017-16349HigAug 2, 2018
    risk 0.53cvss 8.1epss 0.01

    An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML external entity to be referenced, resulting in information disclosure and potential denial of service. An attacker can issue…

  • CVE-2018-10922HigAug 2, 2018
    risk 0.49cvss 7.5epss 0.01

    An input validation flaw exists in ttembed. With a crafted input file, an attacker may be able to trigger a denial of service condition due to ttembed trusting attacker controlled values.

  • CVE-2017-9118HigAug 2, 2018
    risk 0.49cvss 7.5epss 0.03

    PHP 7.1.5 has an Out of bounds access in php_pcre_replace_impl via a crafted preg_replace call.

  • CVE-2018-1336HigAug 2, 2018
    risk 0.43cvss 7.5epss 0.21

    An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.

  • CVE-2018-3939HigAug 1, 2018
    risk 0.57cvss 8.8epss 0.02

    An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 9.1.0.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs…

  • CVE-2018-3924HigAug 1, 2018
    risk 0.61cvss 8.8epss 0.44

    An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker…

  • CVE-2018-0413HigAug 1, 2018
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to…

  • CVE-2018-3847HigAug 1, 2018
    risk 0.57cvss 8.8epss 0.03

    Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3.42. Specially crafted images parsed via the library, can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT…

  • CVE-2018-8034HigAug 1, 2018
    risk 0.43cvss 7.5epss 0.21

    The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.

  • CVE-2018-1595HigAug 1, 2018
    risk 0.57cvss 8.8epss 0.02

    IBM Spectrum Symphony and Platform Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to execute arbitrary commands due to improper handling of user supplied input. IBM X-Force ID: 143622.

  • CVE-2018-10897HigAug 1, 2018
    risk 0.00cvss 8.1epss 0.06

    A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the destination directory on the targeted…

  • CVE-2018-10896HigAug 1, 2018
    risk 0.46cvss 7.1epss 0.00

    The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances created by cloning a golden master or template system, sharing ssh host keys,…

  • CVE-2016-8654HigAug 1, 2018
    risk 0.44cvss 7.8epss 0.02

    A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.