VYPR

CVEs

38,011 total · page 568 of 761

  • CVE-2019-20825CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Foxit PhantomPDF before 8.3.11. It has an out-of-bounds write when Internet Explorer is used.

  • CVE-2018-21244CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows arbitrary application execution via an embedded executable file in a PDF portfolio, aka FG-VD-18-029.

  • CVE-2018-21242CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows Remote Code Execution via a GoToE or GoToR action.

  • CVE-2020-13814CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7.1. It has a use-after-free via a document that lacks a dictionary.

  • CVE-2019-20822CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the 3D Plugin Beta for Foxit Reader and PhantomPDF before 9.7.0.29430. It has an out-of-bounds write via incorrect image data.

  • CVE-2020-13805CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It has brute-force attack mishandling because the CAS service lacks a limit on login failures.

  • CVE-2020-13804CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Foxit Reader and PhantomPDF before 9.7.2. It allows information disclosure of a hardcoded username and password in the DocuSign plugin.

  • CVE-2020-4193CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM Security Guardium 11.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 174857.

  • CVE-2020-9292CriJun 4, 2020
    risk 0.64cvss 9.8epss 0.02

    An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path.

  • CVE-2020-10549CriJun 4, 2020
    risk 0.66cvss 9.8epss 0.32

    rConfig 3.9.4 and previous versions has unauthenticated snippets.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

  • CVE-2020-10548CriJun 4, 2020
    risk 0.67cvss 9.8epss 0.37

    rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

  • CVE-2020-10547CriJun 4, 2020
    risk 0.67cvss 9.8epss 0.37

    rConfig 3.9.4 and previous versions has unauthenticated compliancepolicyelements.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

  • CVE-2020-10546CriJun 4, 2020
    risk 0.71cvss 9.8epss 0.87

    rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

  • CVE-2020-6493CriJun 3, 2020
    risk 0.63cvss 9.6epss 0.02

    Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-3258CriJun 3, 2020
    risk 0.64cvss 9.8epss 0.05

    Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, remote attacker or an authenticated, local attacker to execute…

  • CVE-2020-3227CriJun 3, 2020
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the authorization controls for the Cisco IOx application hosting infrastructure in Cisco IOS XE Software could allow an unauthenticated, remote attacker to execute Cisco IOx API commands without proper authorization. The vulnerability is due to incorrect…

  • CVE-2020-3198CriJun 3, 2020
    risk 0.64cvss 9.8epss 0.04

    Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, remote attacker or an authenticated, local attacker to execute…

  • CVE-2020-4177CriJun 3, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM Security Guardium 11.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174732.

  • CVE-2020-13756CriJun 3, 2020
    risk 0.61cvss 9.8epss 0.50

    Sabberworm PHP CSS Parser before 8.3.1 calls eval on uncontrolled data, possibly leading to remote code execution if the function allSelectors() or getSelectorsBySpecificity() is called with input from an attacker.

  • CVE-2020-10516CriJun 3, 2020
    risk 0.64cvss 9.8epss 0.02

    An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization. This vulnerability affected all versions of GitHub…

  • CVE-2020-7115CriJun 3, 2020
    risk 0.72cvss 9.8epss 0.65

    The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution in the underlying operating system. Resolution: Fixed in…

  • CVE-2020-1963CriJun 3, 2020
    risk 0.60cvss 9.1epss 0.05

    Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem.

  • CVE-2020-12017CriJun 2, 2020
    risk 0.64cvss 9.8epss 0.02

    GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerability in the web application could allow multiple unauthenticated attacks that could cause serious impact. The vulnerability may allow an unauthenticated…

  • CVE-2020-3641CriJun 2, 2020
    risk 0.64cvss 9.8epss 0.01

    Integer overflow may occur if atom size is less than atom offset as there is improper validation of atom size in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009,…

  • CVE-2020-3633CriJun 2, 2020
    risk 0.64cvss 9.8epss 0.01

    Array out of bound may occur while playing mp3 file as no check is there on offset if it is greater than the buffer allocated or not in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music,…

  • CVE-2020-3615CriJun 2, 2020
    risk 0.64cvss 9.8epss 0.01

    Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disassoc frames due to improper enum values used to check the frame subtype in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity,…

  • CVE-2014-8945CriJun 1, 2020
    risk 0.64cvss 9.8epss 0.02

    admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.

  • CVE-2014-8941CriJun 1, 2020
    risk 0.64cvss 9.8epss 0.01

    Lexiglot through 2014-11-20 allows SQL injection via an admin.php?page=users&from_id= or admin.php?page=history&limit= URI.

  • CVE-2014-7175CriJun 1, 2020
    risk 0.64cvss 9.8epss 0.01

    FarLinX X25 Gateway through 2014-09-25 allows attackers to write arbitrary data to fsUI.xyz via fsSaveUIPersistence.php.

  • CVE-2014-7173CriJun 1, 2020
    risk 0.64cvss 9.8epss 0.03

    FarLinX X25 Gateway through 2014-09-25 allows command injection via shell metacharacters to sysSaveMonitorData.php, fsx25MonProxy.php, syseditdate.php, iframeupload.php, or sysRestoreX25Cplt.php.

  • CVE-2020-8967CriJun 1, 2020
    risk 0.65cvss 10.0epss 0.01

    There is an improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in php files of GESIO ERP. GESIO ERP all versions prior to 11.2 allows malicious users to retrieve all database information.

  • CVE-2020-11844CriMay 29, 2020
    risk 0.65cvss 10.0epss 0.02

    Incorrect Authorization vulnerability in Micro Focus Container Deployment Foundation component affects products: - Hybrid Cloud Management. Versions 2018.05 to 2019.11. - ArcSight Investigate. versions 2.4.0, 3.0.0 and 3.1.0. - ArcSight Transformation Hub. versions 3.0.0, 3.1.0,…

  • CVE-2020-12493CriMay 29, 2020
    risk 0.65cvss 10.0epss 0.01

    An open port used for debugging in SWARCOs CPU LS4000 Series with versions starting with G4... grants root access to the device without access control via network. A malicious user could use this vulnerability to get access to the device and disturb operations with connected…

  • CVE-2020-13693CriMay 29, 2020
    risk 0.70cvss 9.8epss 0.44

    An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.

  • CVE-2019-6342CriMay 28, 2020
    risk 0.64cvss 9.8epss 0.02

    An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.

  • CVE-2020-8606CriMay 27, 2020
    risk 0.73cvss 9.8epss 0.73

    A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected installations of Trend Micro InterScan Web Security Virtual Appliance.

  • CVE-2020-11059CriMay 27, 2020
    risk 0.55cvss 9.6epss 0.01

    In AEgir greater than or equal to 21.7.0 and less than 21.10.1, aegir publish and aegir build may leak secrets from environment variables in the browser bundle published to npm. This has been fixed in 21.10.1.

  • CVE-2020-6774CriMay 27, 2020
    risk 0.60cvss 9.3epss 0.00

    Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attacker to escape from the Kiosk Mode and access the underlying operating system.

  • CVE-2020-6831CriMay 26, 2020
    risk 0.64cvss 9.8epss 0.06

    A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.

  • CVE-2020-12390CriMay 26, 2020
    risk 0.64cvss 9.8epss 0.02

    Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.

  • CVE-2020-12389CriMay 26, 2020
    risk 0.65cvss 10.0epss 0.02

    The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.

  • CVE-2020-12388CriMay 26, 2020
    risk 0.65cvss 10.0epss 0.03

    The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.

  • CVE-2020-12396CriMay 26, 2020
    risk 0.64cvss 9.8epss 0.02

    Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects…

  • CVE-2020-12395CriMay 26, 2020
    risk 0.64cvss 9.8epss 0.03

    Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This…

  • CVE-2020-8171CriMay 26, 2020
    risk 0.64cvss 9.8epss 0.04

    We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:There are certain end-points containing functionalities that…

  • CVE-2020-13485CriMay 25, 2020
    risk 0.59cvss 9.1epss 0.01

    The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.

  • CVE-2020-13442CriMay 25, 2020
    risk 0.64cvss 9.8epss 0.03

    A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.

  • CVE-2020-5537CriMay 25, 2020
    risk 0.64cvss 9.8epss 0.03

    Cybozu Desktop for Windows 2.0.23 to 2.2.40 allows remote code execution via unspecified vectors.

  • CVE-2020-13433CriMay 24, 2020
    risk 0.64cvss 9.8epss 0.01

    Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.

  • CVE-2020-13417CriMay 22, 2020
    risk 0.64cvss 9.8epss 0.02

    An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.