VYPR

CVEs

38,012 total · page 559 of 761

  • CVE-2020-7702CriAug 17, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of package templ8 are vulnerable to Prototype Pollution via the parse function.

  • CVE-2020-12606CriAug 17, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in DB Soft SGLAC before 20.05.001. The ProcedimientoGenerico method in the SVCManejador.svc webservice of the SGLAC web frontend allows an attacker to run arbitrary SQL commands on the SQL Server. Command execution can be easily achieved by using the…

  • CVE-2020-24361CriAug 16, 2020
    risk 0.64cvss 9.8epss 0.02

    SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.

  • CVE-2020-17474CriAug 14, 2020
    risk 0.64cvss 9.8epss 0.01

    A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary new users, elevate users to administrators, delete users, and download user faces from the database.

  • CVE-2020-15692CriAug 14, 2020
    risk 0.64cvss 9.8epss 0.04

    In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file path that will be opened in the default explorer. An attacker can pass one argument to the underlying open command to execute arbitrary…

  • CVE-2020-15781CriAug 14, 2020
    risk 0.62cvss 9.6epss 0.01

    A vulnerability has been identified in SICAM WEB firmware for SICAM A8000 RTUs (All versions < V05.30). The login screen does not sufficiently sanitize input, which enables an attacker to generate specially crafted log messages. If an unsuspecting victim views the log messages…

  • CVE-2020-10055CriAug 14, 2020
    risk 0.64cvss 9.8epss 0.06

    A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications are delivered with a 3rd party component (BIRT) that contains a remote code execution vulnerability if the Advanced Reporting…

  • CVE-2020-7701CriAug 14, 2020
    risk 0.57cvss 9.8epss 0.02

    madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue.

  • CVE-2020-7700CriAug 14, 2020
    risk 0.64cvss 9.8epss 0.02

    All versions of phpjs are vulnerable to Prototype Pollution via parse_str.

  • CVE-2020-17463CriKEVAug 13, 2020
    risk 0.76cvss 9.8epss 0.90

    FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

  • CVE-2019-16374CriAug 13, 2020
    risk 0.64cvss 9.8epss 0.02

    Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four characters of a username, followed by the * character, to bypass access control.

  • CVE-2020-4589CriAug 13, 2020
    risk 0.64cvss 9.8epss 0.08

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 184585.

  • CVE-2020-16137CriAug 12, 2020
    risk 0.68cvss 9.8epss 0.19

    A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to reset the credentials for the SSH administrative console to arbitrary values. Note: We cannot prove this vulnerability exists. Out of an abundance of caution,…

  • CVE-2020-12107CriAug 12, 2020
    risk 0.64cvss 9.8epss 0.02

    The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full control over this module's Operating System.

  • CVE-2020-12106CriAug 12, 2020
    risk 0.64cvss 9.8epss 0.01

    The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Administrator account or connect the product to a rogue access point.

  • CVE-2020-5415CriAug 12, 2020
    risk 0.65cvss 10.0epss 0.01

    Concourse, versions prior to 6.3.1 and 6.4.1, in installations which use the GitLab auth connector, is vulnerable to identity spoofing by way of configuring a GitLab account with the same full name as another user who is granted access to a Concourse team. GitLab groups do not…

  • CVE-2020-17506CriAug 12, 2020
    risk 0.74cvss 9.8epss 0.94

    Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.

  • CVE-2020-17446CriAug 12, 2020
    risk 0.57cvss 9.8epss 0.02

    asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder.

  • CVE-2020-6294CriAug 12, 2020
    risk 0.59cvss 9.1epss 0.02

    Xvfb of SAP Business Objects Business Intelligence Platform, versions - 4.2, 4.3, platform on Unix does not perform any authentication checks for functionalities that require user identity.

  • CVE-2020-6284CriAug 12, 2020
    risk 0.59cvss 9.0epss 0.02

    SAP NetWeaver (Knowledge Management), versions - 7.30, 7.31, 7.40, 7.50, allows the automatic execution of script content in a stored file due to inadequate filtering with the accessing user's privileges. If the accessing user has administrative privileges, then the execution of…

  • CVE-2020-17496CriKEVAug 12, 2020
    risk 0.86cvss 9.8epss 0.87

    vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759.

  • CVE-2020-6932CriAug 12, 2020
    risk 0.65cvss 10.0epss 0.04

    An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arbitrary executables in the context of the…

  • CVE-2020-0260CriAug 11, 2020
    risk 0.59cvss 9.1epss 0.00

    There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152225183

  • CVE-2020-0253CriAug 11, 2020
    risk 0.64cvss 9.8epss 0.01

    There is a possible memory corruption due to a use after free.Product: AndroidVersions: Android SoCAndroid ID: A-152647365

  • CVE-2020-0252CriAug 11, 2020
    risk 0.64cvss 9.8epss 0.01

    There is a possible memory corruption due to a use after free.Product: AndroidVersions: Android SoCAndroid ID: A-152236803

  • CVE-2020-17466CriAug 11, 2020
    risk 0.64cvss 9.8epss 0.01

    Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redirect responses.

  • CVE-2020-17368CriAug 11, 2020
    risk 0.64cvss 9.8epss 0.04

    Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.

  • CVE-2020-11552CriAug 11, 2020
    risk 0.64cvss 9.8epss 0.07

    An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog. This vulnerability could allow an unauthenticated attacker to escalate privileges on a…

  • CVE-2020-14324CriAug 11, 2020
    risk 0.59cvss 9.1epss 0.03

    A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerability can be exploited by authenticated attacker while setuping conversion host through Infrastructure Migration Solution. This flaw…

  • CVE-2020-14325CriAug 11, 2020
    risk 0.59cvss 9.1epss 0.01

    Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and non-existent role-based access control user, with groups and roles. With a selected group of EvmGroup-super_administrator, an…

  • CVE-2020-17479CriAug 10, 2020
    risk 0.57cvss 9.8epss 0.02

    jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.

  • CVE-2020-9529CriAug 10, 2020
    risk 0.64cvss 9.8epss 0.03

    Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20), as used by many different vendors in millions of Internet of Things devices, suffers from a privilege escalation vulnerability that allows attackers on the local network to reset the device's administrator…

  • CVE-2020-9527CriAug 10, 2020
    risk 0.64cvss 9.8epss 0.03

    Firmware developed by Shenzhen Hichip Vision Technology (V6 through V20, after 2018-08-09 through 2020), as used by many different vendors in millions of Internet of Things devices, suffers from buffer overflow vulnerability that allows unauthenticated remote attackers to…

  • CVE-2020-13292CriAug 10, 2020
    risk 0.62cvss 9.6epss 0.01

    In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.

  • CVE-2020-16169CriAug 7, 2020
    risk 0.64cvss 9.8epss 0.02

    Authentication Bypass Using an Alternate Path or Channel in temi Robox OS prior to120, temi Android app up to 1.3.7931 allows remote attackers to gain elevated privileges on the temi and have it automatically answer the attacker's calls, granting audio, video, and motor control…

  • CVE-2020-16167CriAug 7, 2020
    risk 0.59cvss 9.1epss 0.02

    Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to receive and answer calls intended for another temi user. Answering the call this way grants motor control of the temi in addition to audio/video…

  • CVE-2020-13376CriAug 7, 2020
    risk 0.59cvss 9.0epss 0.04

    SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files and achieve OS command execution via a crafted SecurEnvoyReply cookie.

  • CVE-2020-11984CriAug 7, 2020
    risk 0.71cvss 9.8epss 0.90

    Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE

  • CVE-2020-13793CriAug 6, 2020
    risk 0.64cvss 9.8epss 0.02

    Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key.

  • CVE-2020-12441CriAug 6, 2020
    risk 0.64cvss 9.8epss 0.04

    Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a specially crafted network packet.

  • CVE-2020-7361CriAug 6, 2020
    risk 0.67cvss 9.6epss 0.17

    The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' component. After authenticating to the ZenTao dashboard, attackers may construct and send arbitrary OS commands via the POST parameter 'path', and those commands…

  • CVE-2020-7357CriAug 6, 2020
    risk 0.68cvss 9.6epss 0.32

    Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell commands as the root user through the 'NTP_Server_IP' HTTP POST parameter in system.cgi page. This issue…

  • CVE-2020-7356CriAug 6, 2020
    risk 0.69cvss 10.0epss 0.14

    CAYIN xPost suffers from an unauthenticated SQL Injection vulnerability. Input passed via the GET parameter 'wayfinder_seqid' in wayfinder_meeting_input.jsp is not properly sanitized before being returned to the user or used in SQL queries. This can be exploited to manipulate…

  • CVE-2020-5609CriAug 5, 2020
    risk 0.64cvss 9.8epss 0.02

    Directory traversal vulnerability in CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01 allows a remote…

  • CVE-2020-5608CriAug 5, 2020
    risk 0.64cvss 9.8epss 0.02

    CAMS for HIS CENTUM CS 3000 (includes CENTUM CS 3000 Small) R3.08.10 to R3.09.50, CENTUM VP (includes CENTUM VP Small, Basic) R4.01.00 to R6.07.00, B/M9000CS R5.04.01 to R5.05.01, and B/M9000 VP R6.01.01 to R8.03.01 allows a remote unauthenticated attacker to bypass…

  • CVE-2020-17353CriAug 5, 2020
    risk 0.64cvss 9.8epss 0.02

    scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.

  • CVE-2020-13921CriAug 5, 2020
    risk 0.59cvss 9.8epss 0.33

    **Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.

  • CVE-2020-13151CriAug 5, 2020
    risk 0.74cvss 9.8epss 0.87

    Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. It attempts to restrict code execution by disabling os.execute() calls, but this is insufficient. Anyone with…

  • CVE-2020-4459CriAug 4, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM Security Verify Access 10.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 181395.

  • CVE-2020-5616CriAug 4, 2020
    risk 0.64cvss 9.8epss 0.03

    [Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and…