VYPR

CVEs

38,012 total · page 563 of 761

  • CVE-2020-14507CriJul 15, 2020
    risk 0.64cvss 9.8epss 0.05

    Advantech iView, versions 5.6 and prior, is vulnerable to multiple path traversal vulnerabilities that could allow an attacker to create/download arbitrary files, limit system availability, and remotely execute code.

  • CVE-2020-14505CriJul 15, 2020
    risk 0.64cvss 9.8epss 0.07

    Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to send a HTTP GET or POST request that creates a command…

  • CVE-2020-14497CriJul 15, 2020
    risk 0.64cvss 9.8epss 0.05

    Advantech iView, versions 5.6 and prior, contains multiple SQL injection vulnerabilities that are vulnerable to the use of an attacker-controlled string in the construction of SQL queries. An attacker could extract user credentials, read or modify information, and remotely…

  • CVE-2020-1350CriKEVJul 14, 2020
    risk 0.85cvss 10.0epss 0.97

    A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle requests, aka 'Windows DNS Server Remote Code Execution Vulnerability'.

  • CVE-2020-1043CriJul 14, 2020
    risk 0.59cvss 9.0epss 0.06

    A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from…

  • CVE-2020-1042CriJul 14, 2020
    risk 0.59cvss 9.0epss 0.06

    A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from…

  • CVE-2020-1041CriJul 14, 2020
    risk 0.59cvss 9.0epss 0.06

    A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from…

  • CVE-2020-1040CriKEVJul 14, 2020
    risk 0.71cvss 9.0epss 0.07

    A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from…

  • CVE-2020-1036CriJul 14, 2020
    risk 0.59cvss 9.0epss 0.06

    A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from…

  • CVE-2020-1032CriJul 14, 2020
    risk 0.59cvss 9.0epss 0.06

    A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is unique from…

  • CVE-2020-1025CriJul 14, 2020
    risk 0.64cvss 9.8epss 0.06

    An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit…

  • CVE-2020-9297CriJul 14, 2020
    risk 0.64cvss 9.8epss 0.02

    Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are supported, including Java EL expressions. If an attacker…

  • CVE-2020-11546CriJul 14, 2020
    risk 0.66cvss 9.8epss 0.33

    SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.

  • CVE-2020-7593CriJul 14, 2020
    risk 0.64cvss 9.8epss 0.09

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (V1.81.01 - V1.81.03), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.01), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.02). A buffer overflow vulnerability exists in the Web Server functionality of the device. A…

  • CVE-2020-1948CriJul 14, 2020
    risk 0.65cvss 9.8epss 0.16

    This vulnerability can affect all Dubbo users stay on version 2.7.6 or lower. An attacker can send RPC requests with unrecognized service name or method name along with some malicious parameter payloads. When the malicious parameter is deserialized, it will execute some…

  • CVE-2020-13753CriJul 14, 2020
    risk 0.65cvss 10.0epss 0.03

    The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to…

  • CVE-2020-11956CriJul 14, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is a least privilege violation.

  • CVE-2020-10042CriJul 14, 2020
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). A buffer overflow in various positions of the web application might enable an attacker with access to the web application to execute arbitrary code…

  • CVE-2020-10038CriJul 14, 2020
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SICAM MMU (All versions < V2.05), SICAM SGU (All versions), SICAM T (All versions < V2.18). An attacker with access to the device's web server might be able to execute administrative commands without authentication.

  • CVE-2020-6287CriKEVJul 14, 2020
    risk 0.88cvss 10.0epss 0.95

    SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP Java system, including…

  • CVE-2020-13926CriJul 14, 2020
    risk 0.64cvss 9.8epss 0.02

    Kylin concatenates and executes a Hive SQL in Hive CLI or beeline when building a new segment; some part of the HQL is from system configurations, while the configuration can be overwritten by certain rest api, which makes SQL injection attack is possible. Users of all previous…

  • CVE-2020-13925CriJul 14, 2020
    risk 0.65cvss 9.8epss 0.20

    Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then executes them on the server; while the reported API misses necessary input validation, which causes the hackers to have the possibility to execute OS command…

  • CVE-2020-11951CriJul 14, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is a Backdoor root account.

  • CVE-2020-10988CriJul 13, 2020
    risk 0.64cvss 9.8epss 0.03

    A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated remote attackers to start a telnetd service on the device.

  • CVE-2020-10987CriKEVJul 13, 2020
    risk 0.82cvss 9.8epss 0.80

    The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.

  • CVE-2020-11749CriJul 13, 2020
    risk 0.63cvss 9.0epss 0.16

    Pandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can trigger a Cross Site Scripting (XSS), which can run arbitrary code to allow Remote Code Execution as root or apache2.

  • CVE-2020-15504CriJul 10, 2020
    risk 0.64cvss 9.8epss 0.02

    A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13…

  • CVE-2020-8186CriJul 10, 2020
    risk 0.64cvss 9.8epss 0.03

    A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function.

  • CVE-2019-17638CriJul 9, 2020
    risk 0.55cvss 9.4epss 0.11

    In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer containing the HTTP response headers is released back to the ByteBufferPool twice.…

  • CVE-2020-7458CriJul 9, 2020
    risk 0.64cvss 9.8epss 0.02

    In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELEASE before p1, long values in the user-controlled PATH environment variable cause posix_spawnp to write beyond the end of the heap allocated stack possibly leading to arbitrary code execution.

  • CVE-2020-11849CriJul 8, 2020
    risk 0.64cvss 9.8epss 0.01

    Elevation of privilege and/or unauthorized access vulnerability in Micro Focus Identity Manager. Affecting versions prior to 4.7.3 and 4.8.1 hot fix 1. The vulnerability could allow information exposure that can result in an elevation of privilege or an unauthorized access.

  • CVE-2020-3931CriJul 8, 2020
    risk 0.64cvss 9.8epss 0.02

    Buffer overflow exists in Geovision Door Access Control device family, an unauthenticated remote attacker can execute arbitrary command.

  • CVE-2020-8521CriJul 7, 2020
    risk 0.64cvss 9.8epss 0.01

    SQL injection with start and length parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql

  • CVE-2020-8520CriJul 7, 2020
    risk 0.64cvss 9.8epss 0.01

    SQL injection in order and column parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql

  • CVE-2020-8519CriJul 7, 2020
    risk 0.64cvss 9.8epss 0.01

    SQL injection with the search parameter in Records.php for phpzag live add edit delete data tables records with ajax php mysql

  • CVE-2020-12821CriJul 7, 2020
    risk 0.64cvss 9.8epss 0.02

    Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.

  • CVE-2019-20896CriJul 7, 2020
    risk 0.64cvss 9.8epss 0.01

    WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter.

  • CVE-2020-15350CriJul 7, 2020
    risk 0.64cvss 9.8epss 0.01

    RIOT 2020.04 has a buffer overflow in the base64 decoder. The decoding function base64_decode() uses an output buffer estimation function to compute the required buffer capacity and validate against the provided buffer size. The base64_estimate_decode_size() function calculates…

  • CVE-2020-15367CriJul 7, 2020
    risk 0.64cvss 9.8epss 0.02

    Venki Supravizio BPM 10.1.2 does not limit the number of authentication attempts. An unauthenticated user may exploit this vulnerability to launch a brute-force authentication attack against the Login page.

  • CVE-2020-5599CriJul 7, 2020
    risk 0.64cvss 9.8epss 0.03

    TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability,…

  • CVE-2020-5595CriJul 7, 2020
    risk 0.64cvss 9.8epss 0.02

    TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a buffer overflow vulnerability, which may allow a remote attacker to stop the network functions of…

  • CVE-2020-15506CriJul 7, 2020
    risk 0.64cvss 9.8epss 0.03

    An authentication bypass vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0 that allows remote attackers to bypass authentication mechanisms via unspecified vectors.

  • CVE-2020-15505CriKEVJul 7, 2020
    risk 0.87cvss 9.8epss 1.00

    A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1, 10.4.0.2, 10.4.0.3, 10.5.1.0, 10.5.2.0 and 10.6.0.0; and Sentry versions 9.7.2 and earlier, and 9.8.0; and Monitor and Reporting Database (RDB) version 2.0.0.1…

  • CVE-2020-5368CriJul 6, 2020
    risk 0.64cvss 9.8epss 0.02

    Dell EMC VxRail versions 4.7.410 and 4.7.411 contain an improper authentication vulnerability. A remote unauthenticated attacker may exploit this vulnerability to obtain sensitive information in an encrypted form.

  • CVE-2020-15543CriJul 5, 2020
    risk 0.64cvss 9.8epss 0.02

    SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.

  • CVE-2020-15542CriJul 5, 2020
    risk 0.64cvss 9.8epss 0.02

    SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.

  • CVE-2020-15541CriJul 5, 2020
    risk 0.64cvss 9.8epss 0.07

    SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.

  • CVE-2020-15540CriJul 5, 2020
    risk 0.64cvss 9.8epss 0.02

    We-com OpenData CMS 2.0 allows SQL Injection via the username field on the administrator login page.

  • CVE-2020-15539CriJul 5, 2020
    risk 0.64cvss 9.8epss 0.02

    SQL injection can occur in We-com Municipality portal CMS 2.1.x via the cerca/ keywords field.

  • CVE-2020-10282CriJul 3, 2020
    risk 0.64cvss 9.8epss 0.02

    The Micro Air Vehicle Link (MAVLink) protocol presents no authentication mechanism on its version 1.0 (nor authorization) whichs leads to a variety of attacks including identity spoofing, unauthorized access, PITM attacks and more. According to literature, version 2.0 optionally…