VYPR

CVEs

38,061 total · page 515 of 762

  • CVE-2019-20467CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. The device by default has a TELNET interface available (which is not advertised or functionally used, but is nevertheless available). Two backdoor accounts (root and default) exist that…

  • CVE-2021-35522CriJul 22, 2021
    risk 0.64cvss 9.8epss 0.04

    A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2, Sigma devices before 4.9.4, and MA VP MD devices before 4.9.7 allows remote attackers to achieve code execution, denial of services, and information disclosure via…

  • CVE-2021-32744CriJul 21, 2021
    risk 0.64cvss 9.8epss 0.01

    Collabora Online is a collaborative online office suite. In versions prior to 4.2.17-1 and version 6.4.9-5, unauthenticated attackers are able to gain access to files which are currently opened by other users in the Collabora Online editor. For successful exploitation the…

  • CVE-2021-37155CriJul 21, 2021
    risk 0.64cvss 9.8epss 0.01

    wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request differs from the serial number in the OCSP response.

  • CVE-2021-2447CriJul 21, 2021
    risk 0.64cvss 9.9epss 0.01

    Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle…

  • CVE-2021-2446CriJul 21, 2021
    risk 0.63cvss 9.6epss 0.02

    Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported version that is affected is 5.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle…

  • CVE-2021-2397CriJul 21, 2021
    risk 0.64cvss 9.8epss 0.02

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2021-2394CriJul 21, 2021
    risk 0.70cvss 9.8epss 0.77

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2021-2382CriJul 21, 2021
    risk 0.64cvss 9.8epss 0.02

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2021-2355CriJul 21, 2021
    risk 0.59cvss 9.1epss 0.01

    Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

  • CVE-2021-22772CriJul 21, 2021
    risk 0.64cvss 9.8epss 0.02

    A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T200 ((Modbus) SC2-04MOD-07000100 and earlier), Easergy T200 ((IEC104) SC2-04IEC-07000100 and earlier), and Easergy T200 ((DNP3) SC2-04DNP-07000102 and earlier) that could cause unauthorized…

  • CVE-2021-22730CriJul 21, 2021
    risk 0.64cvss 9.8epss 0.01

    A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that…

  • CVE-2021-22729CriJul 21, 2021
    risk 0.64cvss 9.8epss 0.02

    A CWE-259: Use of Hard-coded Password vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that…

  • CVE-2021-22727CriJul 21, 2021
    risk 0.64cvss 9.8epss 0.01

    A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could…

  • CVE-2021-22707CriJul 21, 2021
    risk 0.69cvss 9.8epss 0.65

    A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that…

  • CVE-2020-21937CriJul 21, 2021
    risk 0.64cvss 9.8epss 0.05

    An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary system commands.

  • CVE-2020-21935CriJul 21, 2021
    risk 0.64cvss 9.8epss 0.04

    A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary code.

  • CVE-2021-2463CriJul 21, 2021
    risk 0.64cvss 9.8epss 0.02

    Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported versions that are affected are 11.0.0, 11.1.0, 11.2.0 and 11.3.0-11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network…

  • CVE-2021-2456CriJul 21, 2021
    risk 0.70cvss 9.8epss 0.81

    Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access…

  • CVE-2020-35427CriJul 20, 2021
    risk 0.64cvss 9.8epss 0.03

    SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.

  • CVE-2020-5349CriJul 19, 2021
    risk 0.64cvss 9.8epss 0.01

    Dell EMC Networking S4100 and S5200 Series Switches manufactured prior to February 2020 contain a hardcoded credential vulnerability. A remote unauthenticated malicious user could exploit this vulnerability and gain administrative privileges.

  • CVE-2020-5322CriJul 19, 2021
    risk 0.59cvss 9.1epss 0.02

    Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a command injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploit the vulnerability to execute arbitrary shell commands on the affected system.

  • CVE-2020-5320CriJul 19, 2021
    risk 0.59cvss 9.0epss 0.01

    Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a SQL injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to…

  • CVE-2021-20110CriJul 19, 2021
    risk 0.64cvss 9.8epss 0.07

    Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on…

  • CVE-2021-35965CriJul 19, 2021
    risk 0.64cvss 9.8epss 0.02

    The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code of the webpage in plain text, thus remote attackers can obtain administrator’s privilege without logging in.

  • CVE-2021-35963CriJul 19, 2021
    risk 0.64cvss 9.8epss 0.02

    The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remote unauthenticated attackers to upload files containing malicious script to execute RCE attacks.

  • CVE-2021-33501CriJul 19, 2021
    risk 0.63cvss 9.6epss 0.08

    Overwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL.

  • CVE-2021-33027CriJul 19, 2021
    risk 0.64cvss 9.8epss 0.01

    Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.

  • CVE-2021-33592CriJul 19, 2021
    risk 0.64cvss 9.8epss 0.02

    NAVER Toolbar before 4.0.30.323 allows remote attackers to execute arbitrary code via a crafted upgrade.xml file. Special characters in filename parameter can be the cause of bypassing code signing check function.

  • CVE-2021-33911CriJul 17, 2021
    risk 0.64cvss 9.8epss 0.05

    Zoho ManageEngine ADManager Plus before 7110 allows remote code execution.

  • CVE-2021-34458CriJul 16, 2021
    risk 0.65cvss 9.9epss 0.03

    Windows Kernel Remote Code Execution Vulnerability

  • CVE-2020-4821CriJul 16, 2021
    risk 0.64cvss 9.8epss 0.02

    IBM InfoSphere Data Replication 11.4 and IBM InfoSphere Change Data Capture for z/OS 10.2.1, under certain configurations, could allow a user to bypass authentication mechanisms using an empty password string. IBM X-Force ID: 189834

  • CVE-2021-35961CriJul 16, 2021
    risk 0.64cvss 9.8epss 0.02

    Dr. ID Door Access Control and Personnel Attendance Management system uses the hard-code admin default credentials that allows remote attackers to access the system through the default password and obtain the highest permission.

  • CVE-2021-21820CriJul 16, 2021
    risk 0.64cvss 9.8epss 0.03

    A hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2021-21804CriJul 16, 2021
    risk 0.64cvss 9.8epss 0.04

    A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HTTP request can lead to arbitrary PHP code execution. An attacker can send a crafted HTTP request to trigger this…

  • CVE-2021-0276CriJul 15, 2021
    risk 0.64cvss 9.8epss 0.02

    A stack-based Buffer Overflow vulnerability in Juniper Networks SBR Carrier with EAP (Extensible Authentication Protocol) authentication configured, allows an attacker sending specific packets causing the radius daemon to crash resulting with a Denial of Service (DoS) or leading…

  • CVE-2020-11633CriJul 15, 2021
    risk 0.64cvss 9.8epss 0.02

    The Zscaler Client Connector for Windows prior to 2.1.2.74 had a stack based buffer overflow when connecting to misconfigured TLS servers. An adversary would potentially have been able to execute arbitrary code with system privileges.

  • CVE-2021-34690CriJul 15, 2021
    risk 0.64cvss 9.8epss 0.01

    iDrive RemotePC before 7.6.48 on Windows allows authentication bypass. A remote and unauthenticated attacker can bypass cloud authentication to connect and control a system via TCP port 5970 and 5980.

  • CVE-2021-25320CriJul 15, 2021
    risk 0.64cvss 9.9epss 0.01

    A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the cloud-credential ID. Rancher in this case would attach the requested credentials without further checks This issue affects: Rancher…

  • CVE-2020-24133CriJul 14, 2021
    risk 0.64cvss 9.8epss 0.03

    A heap buffer overflow vulnerability in the r_asm_swf_disass function of Radare2-extras before commit e74a93c allows attackers to execute arbitrary code or carry out denial of service (DOS) attacks.

  • CVE-2021-35211CriKEVJul 14, 2021
    risk 0.84cvss 9.0epss 0.91

    Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File…

  • CVE-2020-18155CriJul 14, 2021
    risk 0.57cvss 9.8epss 0.01

    SQL Injection vulnerability in Subrion CMS v4.2.1 in the search page if a website uses a PDO connection.

  • CVE-2021-34523CriKEVJul 14, 2021
    risk 0.87cvss 9.0epss 1.00

    Microsoft Exchange Server Elevation of Privilege Vulnerability

  • CVE-2021-34473CriKEVJul 14, 2021
    risk 0.88cvss 9.1epss 1.00

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2020-18144CriJul 14, 2021
    risk 0.64cvss 9.8epss 0.01

    SQL Injection Vulnerability in ECTouch v2 via the integral_min parameter in index.php.

  • CVE-2021-22779CriJul 14, 2021
    risk 0.59cvss 9.1epss 0.01

    Authentication Bypass by Spoofing vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Control Expert V15.0 SP1, EcoStruxure Process Expert (all versions, including all versions of EcoStruxure…

  • CVE-2021-0515CriJul 14, 2021
    risk 0.64cvss 9.8epss 0.01

    In Factory::CreateStrictFunctionMap of factory.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-25953CriJul 14, 2021
    risk 0.64cvss 9.8epss 0.03

    Prototype pollution vulnerability in 'putil-merge' versions1.0.0 through 3.6.6 allows attacker to cause a denial of service and may lead to remote code execution.

  • CVE-2021-21994CriJul 13, 2021
    risk 0.64cvss 9.8epss 0.01

    SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.

  • CVE-2021-31217CriJul 13, 2021
    risk 0.59cvss 9.1epss 0.04

    In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.