VYPR

CVEs

38,012 total · page 564 of 761

  • CVE-2020-14172CriJul 3, 2020
    risk 0.64cvss 9.8epss 0.03

    This issue exists to document that a security improvement in the way that Jira Server and Data Center use velocity templates has been implemented. The way in which velocity templates were used in Atlassian Jira Server and Data Center in affected versions allowed remote attackers…

  • CVE-2020-14092CriJul 2, 2020
    risk 0.71cvss 9.8epss 0.95

    The CodePeople Payment Form for PayPal Pro plugin before 1.1.65 for WordPress allows SQL Injection.

  • CVE-2020-3297CriJul 2, 2020
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in session management for the web-based interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to defeat authentication protections and gain unauthorized access to the management interface. The attacker could…

  • CVE-2020-15490CriJul 1, 2020
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple buffer overflow vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges. (The set of affected scripts is similar to CVE-2020-12266.)

  • CVE-2020-15489CriJul 1, 2020
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges.

  • CVE-2019-15311CriJul 1, 2020
    risk 0.64cvss 9.8epss 0.08

    An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is Zolo Halo LAN remote code execution. The Zolo Halo Bluetooth speaker had a GoAhead web server listening on the port 80. The /httpapi.asp endpoint of the GoAhead web server was also vulnerable to…

  • CVE-2019-15310CriJul 1, 2020
    risk 0.64cvss 9.8epss 0.08

    An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Linkplay's AWS estate, including S3 buckets containing device…

  • CVE-2020-14057CriJul 1, 2020
    risk 0.64cvss 9.8epss 0.03

    Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments.

  • CVE-2020-14056CriJul 1, 2020
    risk 0.64cvss 9.8epss 0.01

    Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with arbitrary third-party services.

  • CVE-2020-13619CriJul 1, 2020
    risk 0.64cvss 9.8epss 0.03

    php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.

  • CVE-2020-2500CriJul 1, 2020
    risk 0.64cvss 9.8epss 0.01

    This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulnerability, and already fixed the issue in…

  • CVE-2020-5902CriKEVJul 1, 2020
    risk 0.93cvss 9.8epss 1.00

    In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in undisclosed pages.

  • CVE-2020-5901CriJul 1, 2020
    risk 0.63cvss 9.6epss 0.01

    In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. If the victim user is logged in as admin this could result in a complete compromise of the system.

  • CVE-2020-13382CriJul 1, 2020
    risk 0.66cvss 9.1epss 0.53

    openSIS through 7.4 has Incorrect Access Control.

  • CVE-2020-13381CriJul 1, 2020
    risk 0.71cvss 9.8epss 0.59

    openSIS through 7.4 allows SQL Injection.

  • CVE-2020-13380CriJul 1, 2020
    risk 0.64cvss 9.8epss 0.02

    openSIS before 7.4 allows SQL Injection.

  • CVE-2020-15475CriJul 1, 2020
    risk 0.64cvss 9.8epss 0.01

    In nDPI through 3.2, ndpi_reset_packet_line_info in lib/ndpi_main.c omits certain reinitialization, leading to a use-after-free.

  • CVE-2020-15474CriJul 1, 2020
    risk 0.64cvss 9.8epss 0.01

    In nDPI through 3.2, there is a stack overflow in extractRDNSequence in lib/protocols/tls.c.

  • CVE-2020-15473CriJul 1, 2020
    risk 0.59cvss 9.1epss 0.01

    In nDPI through 3.2, the OpenVPN dissector is vulnerable to a heap-based buffer over-read in ndpi_search_openvpn in lib/protocols/openvpn.c.

  • CVE-2020-15472CriJul 1, 2020
    risk 0.59cvss 9.1epss 0.01

    In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short.

  • CVE-2020-15471CriJul 1, 2020
    risk 0.59cvss 9.1epss 0.01

    In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpi_parse_packet_line_info in lib/ndpi_main.c.

  • CVE-2020-15468CriJul 1, 2020
    risk 0.67cvss 9.8epss 0.03

    Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.

  • CVE-2020-15049CriJun 30, 2020
    risk 0.65cvss 9.9epss 0.06

    An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache. The client sends an HTTP request with a Content-Length header containing "+\ "-" or an uncommon…

  • CVE-2020-15415CriKEVJun 30, 2020
    risk 0.82cvss 9.8epss 0.84

    On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.

  • CVE-2020-15411CriJun 30, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP 2.4.128. app/Controller/AttributesController.php has insufficient ACL checks in the attachment downloader.

  • CVE-2019-20893CriJun 30, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Activision Infinity Ward Call of Duty Modern Warfare 2 through 2019-12-11. PartyHost_HandleJoinPartyRequest has a buffer overflow vulnerability and can be exploited by using a crafted joinParty packet. This can be utilized to conduct arbitrary code…

  • CVE-2017-18922CriJun 30, 2020
    risk 0.64cvss 9.8epss 0.02

    It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

  • CVE-2020-15069CriKEVJun 29, 2020
    risk 0.77cvss 9.8epss 0.11

    Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.

  • CVE-2018-6446CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in Brocade Network Advisor Version Before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using an undocumented user credentials and install additional JEE applications.

  • CVE-2020-15362CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.03

    wifiscanner.js in thingsSDK WiFi Scanner 1.0.1 allows Code Injection because it can be used with options to overwrite the default executable/binary path and its arguments. An attacker can abuse this functionality to execute arbitrary code.

  • CVE-2020-14072CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in MK-AUTH 19.01. It allows command execution as root via shell metacharacters to /auth admin scripts.

  • CVE-2020-14070CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in MK-AUTH 19.01. There is authentication bypass in the web login functionality because guessable credentials to admin/executar_login.php result in admin access.

  • CVE-2020-14068CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MK-AUTH 19.01. The web login functionality allows an attacker to bypass authentication and gain client privileges via SQL injection in central/executar_login.php.

  • CVE-2020-15324CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a world-readable axess/opt/axXMPPHandler/config/xmpp_config.py file that stores hardcoded credentials.

  • CVE-2020-15323CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the cloud1234 password for the a1@chopin account default credentials.

  • CVE-2020-15322CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the wbboEZ4BN3ssxAfM hardcoded password for the debian-sys-maint account.

  • CVE-2020-15321CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axzyxel password for the livedbuser account.

  • CVE-2020-15320CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the axiros password for the root account.

  • CVE-2020-2021CriKEVJun 29, 2020
    risk 0.83cvss 10.0epss 0.04

    When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based attacker to access…

  • CVE-2020-12047CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.02

    The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-default wireless configuration enables an FTP service with hard-coded credentials.

  • CVE-2020-12045CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.02

    The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), operates a Telnet service on Port 1023 with hard-coded credentials.

  • CVE-2020-12043CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.02

    The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the WBM remains operational until the WBM is rebooted.

  • CVE-2020-12041CriJun 29, 2020
    risk 0.61cvss 9.4epss 0.01

    The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM that permits temporary configuration changes to network settings of the WBM, and allows the WBM to be rebooted. Temporary…

  • CVE-2020-12040CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.01

    Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the application layer uses an unauthenticated clear-text communication channel to send and receive system status and operational data. This could allow…

  • CVE-2020-12032CriJun 29, 2020
    risk 0.59cvss 9.1epss 0.01

    Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in an unencrypted database. This could allow an attacker with network access to view or modify sensitive data including PHI.

  • CVE-2020-12016CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.02

    Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5, Baxter ExactaMix EM 2400 Versions 1.10, 1.11, 1.13, 1.14 and ExactaMix EM1200 Versions 1.1, 1.2, 1.4 and 1.5 have hard-coded…

  • CVE-2020-15363CriJun 28, 2020
    risk 0.67cvss 9.8epss 0.06

    The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.

  • CVE-2020-9632CriJun 26, 2020
    risk 0.64cvss 9.8epss 0.07

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-9631CriJun 26, 2020
    risk 0.64cvss 9.8epss 0.07

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-9630CriJun 26, 2020
    risk 0.64cvss 9.8epss 0.04

    Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a business logic error vulnerability. Successful exploitation could lead to privilege escalation.