VYPR

CVEs

38,018 total · page 558 of 761

  • CVE-2020-24715CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.01

    The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, native Python code is used that lacks a comparison of the hostname to commonName and subjectAltName.

  • CVE-2020-24714CriAug 27, 2020
    risk 0.57cvss 9.8epss 0.01

    The Scalyr Agent before 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, the openssl binary is called without the -verify_hostname option.

  • CVE-2020-24203CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.04

    Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.0 allows remote unauthenticated attackers to gain remote code execution.

  • CVE-2020-24202CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.03

    File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote attackers to conduct code execution.

  • CVE-2020-23979CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.02

    13enforme CMS 1.0 has SQL Injection via the 'content.php' id parameter.

  • CVE-2020-23978CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.02

    SQL injection can occur in Soluzione Globale Ecommerce CMS v1 via the parameter " offerta.php"

  • CVE-2020-23976CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.02

    Webexcels Ecommerce CMS 2.x, 2017, 2018, 2019, 2020 has SQL Injection via the 'content.php' id parameter.

  • CVE-2020-23973CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.02

    KandNconcepts Club CMS 1.1 and 1.2 has SQL Injection via the 'team.php,player.php,club.php' id parameter.

  • CVE-2020-23980CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.02

    DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.

  • CVE-2019-4694CriAug 26, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171832.

  • CVE-2020-3446CriAug 26, 2020
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in Cisco Virtual Wide Area Application Services (vWAAS) with Cisco Enterprise NFV Infrastructure Software (NFVIS)-bundled images for Cisco ENCS 5400-W Series and CSP 5000-W Series appliances could allow an unauthenticated, remote attacker to log into the NFVIS…

  • CVE-2020-24007CriAug 26, 2020
    risk 0.64cvss 9.8epss 0.02

    Umanni RH 1.0 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.

  • CVE-2020-14498CriAug 26, 2020
    risk 0.63cvss 9.6epss 0.04

    HMS Industrial Networks AB eCatcher all versions prior to 6.5.5 is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2019-18847CriAug 26, 2020
    risk 0.64cvss 9.8epss 0.02

    Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.

  • CVE-2020-24653CriAug 26, 2020
    risk 0.57cvss 9.8epss 0.01

    secure-store in Expo through 2.16.1 on iOS provides the insecure kSecAttrAccessibleAlwaysThisDeviceOnly policy when WHEN_UNLOCKED_THIS_DEVICE_ONLY is used.

  • CVE-2020-15639CriAug 25, 2020
    risk 0.65cvss 9.8epss 0.12

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Authentication is not required to exploit this vulnerability. The specific flaw exists within the decryptFile method of the…

  • CVE-2020-16245CriAug 25, 2020
    risk 0.64cvss 9.8epss 0.08

    Advantech iView, Versions 5.7 and prior. The affected product is vulnerable to path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.

  • CVE-2020-14524CriAug 25, 2020
    risk 0.64cvss 9.8epss 0.03

    Softing Industrial Automation all versions prior to the latest build of version 4.47.0, The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2020-14510CriAug 25, 2020
    risk 0.64cvss 9.8epss 0.02

    GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for telnet, allowing an unprivileged attacker to execute commands as root.

  • CVE-2020-14500CriAug 25, 2020
    risk 0.65cvss 10.0epss 0.02

    Secomea GateManager all versions prior to 9.2c, An attacker can send a negative value and overwrite arbitrary data.

  • CVE-2020-6637CriAug 24, 2020
    risk 0.65cvss 9.8epss 0.20

    openSIS Community Edition version 7.3 is vulnerable to SQL injection via the USERNAME parameter of index.php.

  • CVE-2020-24186CriAug 24, 2020
    risk 0.76cvss 10.0epss 0.95

    A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.

  • CVE-2020-8234CriAug 21, 2020
    risk 0.64cvss 9.8epss 0.03

    A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be guessed, enabling the attacker to obtain high privileges and get a root shell by a Command injection.

  • CVE-2020-24590CriAug 21, 2020
    risk 0.59cvss 9.1epss 0.01

    The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.

  • CVE-2020-24589CriAug 21, 2020
    risk 0.61cvss 9.1epss 0.26

    The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.

  • CVE-2019-11857CriAug 21, 2020
    risk 0.59cvss 9.1epss 0.02

    Lack of input sanitization in AceManager of ALEOS before 4.12.0, 4.9.5 and 4.4.9 allows disclosure of sensitive system information.

  • CVE-2020-24055CriAug 21, 2020
    risk 0.64cvss 9.8epss 0.02

    Verint 5620PTZ Verint_FW_0_42 and Verint 4320 V4320_FW_0_23, and V4320_FW_0_31 units feature an autodiscovery service implemented in the binary executable '/usr/sbin/DM' that listens on port TCP 6666. The service is vulnerable to a stack buffer overflow. It is worth noting that…

  • CVE-2020-24054CriAug 21, 2020
    risk 0.64cvss 9.8epss 0.03

    The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that can spawn a given process repeatedly at a certain time interval as 'root'. One of the limitations of this feature is that it only takes a path to a binary…

  • CVE-2020-24052CriAug 21, 2020
    risk 0.59cvss 9.1epss 0.02

    Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbitrary files via a crafted Document Type Definition (DTD) in an XML request.

  • CVE-2020-24051CriAug 21, 2020
    risk 0.64cvss 9.8epss 0.02

    The Moog EXO Series EXVF5C-2 and EXVP7C2-3 units support the ONVIF interoperability IP-based physical security protocol, which requires authentication for some of its operations. It was found that the authentication check for those ONVIF operations can be bypassed. An attacker…

  • CVE-2020-16279CriAug 20, 2020
    risk 0.64cvss 9.8epss 0.02

    The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplied input being passed to the command line without sanitization.

  • CVE-2020-23935CriAug 20, 2020
    risk 0.68cvss 9.8epss 0.16

    Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".

  • CVE-2020-23936CriAug 20, 2020
    risk 0.64cvss 9.8epss 0.01

    PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".

  • CVE-2020-10283CriAug 20, 2020
    risk 0.64cvss 9.8epss 0.01

    The Micro Air Vehicle Link (MAVLink) protocol presents authentication mechanisms on its version 2.0 however according to its documentation, in order to maintain backwards compatibility, GCS and autopilot negotiate the version via the AUTOPILOT_VERSION message. Since this…

  • CVE-2020-17456CriAug 20, 2020
    risk 0.73cvss 9.8epss 0.74

    SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.

  • CVE-2020-15636CriAug 20, 2020
    risk 0.64cvss 9.8epss 0.09

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R6400, R6700, R7000, R7850, R7900, R8000, RS400, and XR300 routers with firmware 1.0.4.84_10.0.58. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2020-15149CriAug 20, 2020
    risk 0.65cvss 9.9epss 0.02

    NodeBB before version 1.14.3 has a bug introduced in version 1.12.2 in the validation logic that makes it possible to change the password of any user on a running NodeBB forum by sending a specially crafted socket.io call to the server. This could lead to a privilege escalation…

  • CVE-2020-15146CriAug 20, 2020
    risk 0.56cvss 9.6epss 0.02

    In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized properly. This allows the attacker to access any public service by manipulating that…

  • CVE-2020-24032CriAug 18, 2020
    risk 0.64cvss 9.8epss 0.05

    tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone.

  • CVE-2020-15865CriAug 18, 2020
    risk 0.64cvss 9.8epss 0.05

    A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-64 in the report XML file so that they will be compiled and executed on the server that processes this file. This can be used to fully…

  • CVE-2020-14936CriAug 18, 2020
    risk 0.64cvss 9.8epss 0.01

    Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP agent. Functions parsing the OIDs in SNMP requests lack sufficient allocated target-buffer capacity verification when writing parsed OID values. The function snmp_oid_decode_oid() may overwrite memory…

  • CVE-2020-14935CriAug 18, 2020
    risk 0.64cvss 9.8epss 0.03

    Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP bulk get request response encoding function. The function parsing the received SNMP request does not verify the input message's requested variables against the capacity of the internal SNMP engine…

  • CVE-2020-14934CriAug 18, 2020
    risk 0.64cvss 9.8epss 0.02

    Buffer overflows were discovered in Contiki-NG 4.4 through 4.5, in the SNMP agent. The function parsing the received SNMP request does not verify the input message's requested variables against the capacity of the internal SNMP engine buffer. If the number of variables in the…

  • CVE-2019-6258CriAug 18, 2020
    risk 0.64cvss 9.8epss 0.03

    D-Link DIR-822 Rev.Bx devices with firmware v.202KRb06 and older allow a buffer overflow via long MacAddress data in a /HNAP1/SetClientInfo HNAP protocol message, which is mishandled in /usr/sbin/udhcpd during reading of the /var/servd/LAN-1-udhcpd.conf file.

  • CVE-2020-14937CriAug 18, 2020
    risk 0.59cvss 9.1epss 0.01

    Memory access out of buffer boundaries issues was discovered in Contiki-NG 4.4 through 4.5, in the SNMP BER encoder/decoder. The length of provided input/output buffers is insufficiently verified during the encoding and decoding of data. This may lead to out-of-bounds buffer…

  • CVE-2020-7708CriAug 18, 2020
    risk 0.57cvss 9.8epss 0.03

    The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions.

  • CVE-2020-7707CriAug 18, 2020
    risk 0.57cvss 9.8epss 0.03

    The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.

  • CVE-2020-7706CriAug 18, 2020
    risk 0.57cvss 9.8epss 0.03

    The package connie-lang before 0.1.1 are vulnerable to Prototype Pollution in the configuration language library used by connie.

  • CVE-2020-15152CriAug 17, 2020
    risk 0.52cvss 9.1epss 0.02

    ftp-srv is an npm package which is a modern and extensible FTP server designed to be simple yet configurable. In ftp-srv before versions 2.19.6, 3.1.2, and 4.3.4 are vulnerable to Server-Side Request Forgery. The PORT command allows arbitrary IPs which can be used to cause the…

  • CVE-2020-1467CriAug 17, 2020
    risk 0.65cvss 10.0epss 0.04

    An elevation of privilege vulnerability exists when Windows improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability, an attacker would first have to log…