VYPR

CVEs

38,009 total · page 580 of 761

  • CVE-2020-7961CriKEVMar 20, 2020
    risk 0.87cvss 9.8epss 1.00

    Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary code via JSON web services (JSONWS).

  • CVE-2019-12498CriMar 20, 2020
    risk 0.64cvss 9.8epss 0.02

    The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection mechanism.

  • CVE-2019-19148CriMar 20, 2020
    risk 0.64cvss 9.8epss 0.08

    Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tellabs has addressed this issue in the SR30.1 and SR31.1 release on February 18, 2020.

  • CVE-2018-20334CriMar 20, 2020
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get shell.

  • CVE-2019-16072CriMar 20, 2020
    risk 0.69cvss 9.8epss 0.26

    An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.

  • CVE-2019-16064CriMar 19, 2020
    risk 0.63cvss 9.6epss 0.01

    NETSAS Enigma NMS 65.0.0 and prior suffers from a directory traversal vulnerability that can allow an authenticated user to access files and directories stored outside of the web root folder. By exploiting this vulnerability, it is possible for an attacker to list…

  • CVE-2019-12127CriMar 19, 2020
    risk 0.64cvss 9.8epss 0.01

    In ONAP OOM through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected.

  • CVE-2019-12126CriMar 19, 2020
    risk 0.64cvss 9.8epss 0.01

    In ONAP DCAE through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected.

  • CVE-2019-12125CriMar 19, 2020
    risk 0.64cvss 9.8epss 0.01

    In ONAP Logging through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected.

  • CVE-2019-16382CriMar 19, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Ivanti Workspace Control 10.3.110.0. One is able to bypass Ivanti's FileGuard folder protection by renaming the WMTemp work folder used by PowerGrid. A malicious PowerGrid XML file can then be created, after which the folder is renamed back to its…

  • CVE-2019-12130CriMar 19, 2020
    risk 0.64cvss 9.8epss 0.02

    In ONAP CLI through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected.

  • CVE-2019-12129CriMar 19, 2020
    risk 0.64cvss 9.8epss 0.02

    In ONAP MSB through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected.

  • CVE-2019-12128CriMar 19, 2020
    risk 0.64cvss 9.8epss 0.02

    In ONAP SO through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective ONAP services without any authentication. All ONAP Operations Manager (OOM) setups are affected.

  • CVE-2020-9423CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.05

    LogicalDoc before 8.3.3 could allow an attacker to upload arbitrary files, leading to command execution or retrieval of data from the database. LogicalDoc provides a functionality to add documents. Those documents could then be used for multiple tasks, such as version control,…

  • CVE-2020-10674CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.01

    PerlSpeak through 2.01 allows attackers to execute arbitrary OS commands, as demonstrated by use of system and 2-argument open.

  • CVE-2019-19676CriMar 18, 2020
    risk 0.63cvss 9.6epss 0.01

    A CSV injection in arxes-tolina 3.0.0 allows malicious users to gain remote control of other computers. By entering formula code in the following columns: Kundennummer, Firma, Street, PLZ, Ort, Zahlziel, and Bemerkung, an attacker can create a user with a name that contains…

  • CVE-2019-12132CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ONAP SDNC before Dublin. By executing sla/dgUpload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected.

  • CVE-2019-12131CriMar 18, 2020
    risk 0.59cvss 9.1epss 0.01

    An issue was detected in ONAP APPC through Dublin and SDC through Dublin. By setting a USER_ID parameter in an HTTP header, an attacker may impersonate an arbitrary existing user without any authentication. All APPC and SDC setups are affected.

  • CVE-2019-12124CriMar 18, 2020
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in ONAP APPC before Dublin. By using an exposed unprotected Jolokia interface, an unauthenticated attacker can read or overwrite an arbitrary file. All APPC setups are affected.

  • CVE-2019-12120CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in ONAP VNFSDK through Dublin. By accessing port 8000 of demo-vnfsdk-vnfsdk, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

  • CVE-2019-12119CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in ONAP SDC through Dublin. By accessing port 7000 of demo-sdc-sdc-wfd-fe pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are…

  • CVE-2019-12118CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in ONAP SDC through Dublin. By accessing port 7001 of demo-sdc-sdc-wfd-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are…

  • CVE-2019-12117CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in ONAP SDC through Dublin. By accessing port 4001 of demo-sdc-sdc-onboarding-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are…

  • CVE-2019-12116CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in ONAP SDC through Dublin. By accessing port 6000 of demo-sdc-sdc-fe pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

  • CVE-2019-12115CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in ONAP SDC through Dublin. By accessing port 4000 of demo-sdc-sdc-be pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are affected.

  • CVE-2019-12114CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in ONAP HOLMES before Dublin. By accessing port 9202 of dep-holmes-engine-mgmt pod, an unauthenticated attacker (who already has access to pod-to-pod communication) may execute arbitrary code inside that pod. All ONAP Operations Manager (OOM) setups are…

  • CVE-2019-12112CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ONAP SDNC before Dublin. By executing sla/upload with a crafted filename parameter, an unauthenticated attacker can execute an arbitrary command. All SDC setups that include admportal are affected.

  • CVE-2020-3922CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.01

    LisoMail, by ArmorX, allows SQL Injections, attackers can access the database without authentication via a URL parameter manipulation.

  • CVE-2020-8600CriMar 18, 2020
    risk 0.64cvss 9.8epss 0.04

    Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could allow an attacker to manipulate a key file to bypass authentication.

  • CVE-2020-8599CriKEVMar 18, 2020
    risk 0.77cvss 9.8epss 0.12

    Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.

  • CVE-2020-8598CriMar 18, 2020
    risk 0.65cvss 9.8epss 0.13

    Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges. Authentication is not…

  • CVE-2020-10121CriMar 17, 2020
    risk 0.64cvss 9.8epss 0.02

    cPanel before 84.0.20 allows a demo account to achieve code execution via PassengerApps APIs (SEC-546).

  • CVE-2020-10119CriMar 17, 2020
    risk 0.64cvss 9.8epss 0.02

    cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).

  • CVE-2020-10118CriMar 17, 2020
    risk 0.59cvss 9.1epss 0.01

    cPanel before 84.0.20 allows a demo account to modify files via Branding API calls (SEC-543).

  • CVE-2020-10117CriMar 17, 2020
    risk 0.59cvss 9.1epss 0.01

    cPanel before 84.0.20 mishandles enforcement of demo checks in the Market UAPI namespace (SEC-542).

  • CVE-2019-20498CriMar 17, 2020
    risk 0.64cvss 9.8epss 0.02

    cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).

  • CVE-2020-10380CriMar 17, 2020
    risk 0.64cvss 9.8epss 0.01

    RMySQL through 0.10.19 allows SQL Injection.

  • CVE-2020-9347CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.08

    Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be…

  • CVE-2020-8786CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 4 of 4).

  • CVE-2020-8785CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 3 of 4).

  • CVE-2020-8784CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 2 of 4).

  • CVE-2020-8783CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.01

    SuiteCRM 7.10.x versions prior to 7.10.23 and 7.11.x versions prior to 7.11.11 allow SQL Injection (issue 1 of 4).

  • CVE-2019-19212CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.04

    Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).

  • CVE-2020-5847CriKEVMar 16, 2020
    risk 0.86cvss 9.8epss 0.96

    Unraid through 6.8.0 allows Remote Code Execution.

  • CVE-2020-6990CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.04

    Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help protect the account password is hard coded into the…

  • CVE-2020-10243CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Joomla! before 3.9.16. The lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Featured Articles frontend menutype.

  • CVE-2020-10230CriMar 16, 2020
    risk 0.68cvss 9.8epss 0.16

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/admin/loader_ajax.php term parameter.

  • CVE-2019-19208CriMar 16, 2020
    risk 0.68cvss 9.8epss 0.19

    Codiad Web IDE through 2.8.4 allows PHP Code injection.

  • CVE-2019-14887CriMar 16, 2020
    risk 0.59cvss 9.1epss 0.01

    A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version of TLS, potentially breaking…

  • CVE-2020-5547CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.02

    Resource Management Errors vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows remote attackers to stop the network functions or execute malware via a specially crafted packet.