VYPR

CVEs

38,008 total · page 584 of 761

  • CVE-2020-9374CriFeb 24, 2020
    risk 0.70cvss 9.8epss 0.43

    On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends specific shell metacharacters to the panel's traceroute feature.

  • CVE-2019-12511CriFeb 24, 2020
    risk 0.64cvss 9.8epss 0.02

    In NETGEAR Nighthawk X10-R9000 prior to 1.0.4.26, an attacker may execute arbitrary system commands as root by sending a specially-crafted MAC address to the "NETGEAR Genie" SOAP endpoint at AdvancedQoS:GetCurrentBandwidthByMAC. Although this requires QoS being enabled, advanced…

  • CVE-2019-12510CriFeb 24, 2020
    risk 0.59cvss 9.1epss 0.01

    In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGEAR Genie" SOAP API ("/soap/server_sa") by supplying a malicious X-Forwarded-For header of the device's LAN IP address (192.168.1.1) in every request. As a…

  • CVE-2018-14705CriFeb 24, 2020
    risk 0.64cvss 9.8epss 0.02

    In Drobo 5N2 4.0.5, all optional applications lack any form of authentication/authorization validation. As a result, any user capable of accessing the device over the network may interact with and control these applications. This not only poses a severe risk to the availability…

  • CVE-2019-10796CriFeb 24, 2020
    risk 0.64cvss 9.8epss 0.03

    rpi through 0.0.3 allows execution of arbritary commands. The variable pinNumbver in function GPIO within src/lib/gpio.js is used as part of the arguement of exec function without any sanitization.

  • CVE-2020-9366CriFeb 24, 2020
    risk 0.64cvss 9.8epss 0.03

    A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Specially crafted output, or a special program, could corrupt memory and crash Screen or possibly have unspecified other impact.

  • CVE-2020-4222CriFeb 24, 2020
    risk 0.65cvss 9.8epss 0.15

    IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175091.

  • CVE-2020-4213CriFeb 24, 2020
    risk 0.65cvss 9.8epss 0.15

    IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175024.

  • CVE-2020-4212CriFeb 24, 2020
    risk 0.65cvss 9.8epss 0.15

    IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175023.

  • CVE-2020-4211CriFeb 24, 2020
    risk 0.69cvss 9.8epss 0.71

    IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175022.

  • CVE-2020-4210CriFeb 24, 2020
    risk 0.65cvss 9.8epss 0.15

    IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force ID: 175020.

  • CVE-2019-20481CriFeb 24, 2020
    risk 0.64cvss 9.8epss 0.01

    In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old password. This can be exploited in conjunction with CVE-2019-20480.

  • CVE-2019-18183CriFeb 24, 2020
    risk 0.64cvss 9.8epss 0.04

    pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable the non-default delta feature and retrieve an…

  • CVE-2019-18182CriFeb 24, 2020
    risk 0.64cvss 9.8epss 0.04

    pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable a non-default XferCommand and retrieve an…

  • CVE-2020-9355CriFeb 23, 2020
    risk 0.64cvss 9.8epss 0.02

    danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled.

  • CVE-2020-9352CriFeb 23, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST request to /tools/developerConsoleOperations.jsp with a valid payload in the _transaction parameter. NOTE: the documentation states…

  • CVE-2020-9039CriFeb 22, 2020
    risk 0.64cvss 9.8epss 0.04

    Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint exposed by the projector process is an…

  • CVE-2012-0828CriFeb 21, 2020
    risk 0.64cvss 9.8epss 0.04

    Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 line from server containing characters outside of the Basic…

  • CVE-2020-6841CriFeb 21, 2020
    risk 0.64cvss 9.8epss 0.03

    D-Link DCH-M225 1.05b01 and earlier devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the spotifyConnect.php userName parameter.

  • CVE-2016-4606CriFeb 21, 2020
    risk 0.64cvss 9.8epss 0.03

    Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized actions. This may aid in other…

  • CVE-2020-9015CriFeb 20, 2020
    risk 0.68cvss 9.8epss 0.16

    Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly other products) allow attackers to bypass intended TACACS+ shell restrictions via a | character. NOTE: the vendor reports that this is a configuration issue…

  • CVE-2020-8990CriFeb 20, 2020
    risk 0.59cvss 9.1epss 0.01

    Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation.

  • CVE-2020-3765CriFeb 20, 2020
    risk 0.64cvss 9.8epss 0.06

    Adobe After Effects versions 16.1.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2014-4650CriFeb 20, 2020
    risk 0.69cvss 9.8epss 0.25

    The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character…

  • CVE-2014-4657CriFeb 20, 2020
    risk 0.57cvss 9.8epss 0.04

    The safe_eval function in Ansible before 1.5.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions.

  • CVE-2014-3484CriFeb 20, 2020
    risk 0.64cvss 9.8epss 0.02

    Multiple stack-based buffer overflows in the __dn_expand function in network/dn_expand.c in musl libc 1.1x before 1.1.2 and 0.9.13 through 1.0.3 allow remote attackers to (1) have unspecified impact via an invalid name length in a DNS response or (2) cause a denial of service…

  • CVE-2014-4678CriFeb 20, 2020
    risk 0.57cvss 9.8epss 0.05

    The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4657.

  • CVE-2013-2018CriFeb 20, 2020
    risk 0.64cvss 9.8epss 0.02

    Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2020-6970CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.03

    A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially crafted script could execute code on the OpenEnterprise…

  • CVE-2020-3943CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.02

    vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to…

  • CVE-2020-3158CriFeb 19, 2020
    risk 0.59cvss 9.1epss 0.03

    A vulnerability in the High Availability (HA) service of Cisco Smart Software Manager On-Prem could allow an unauthenticated, remote attacker to access a sensitive part of the system with a high-privileged account. The vulnerability is due to a system account that has a default…

  • CVE-2014-9614CriFeb 19, 2020
    risk 0.69cvss 9.8epss 0.69

    The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/.

  • CVE-2014-9613CriFeb 19, 2020
    risk 0.67cvss 9.8epss 0.04

    Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to webadmin/auth/verification.php or (2) dpid parameter to webadmin/deny/index.php.

  • CVE-2014-9612CriFeb 19, 2020
    risk 0.67cvss 9.8epss 0.05

    SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to execute arbitrary SQL commands via the server parameter.

  • CVE-2020-6061CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.05

    An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this…

  • CVE-2020-8441CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.05

    JYaml through 1.3 allows remote code execution during deserialization of a malicious payload through the load() function. NOTE: this is a discontinued product.

  • CVE-2019-4640CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code which could result in an attacker executing malicious code. IBM X-Force ID: 170046.

  • CVE-2014-2727CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.02

    The STARTTLS implementation in MailMarshal before 7.2 allows plaintext command injection.

  • CVE-2014-2228CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.03

    The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages.

  • CVE-2016-1000005CriFeb 19, 2020
    risk 0.57cvss 9.8epss 0.01

    mcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to type confusion if other types of data were passed in. This issue affects HHVM versions prior to 3.9.5, all versions between 3.10.0 and 3.12.3 (inclusive), and all versions between…

  • CVE-2016-1000004CriFeb 19, 2020
    risk 0.57cvss 9.8epss 0.01

    Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_dom. This issue affects HHVM versions prior to 3.9.5, all versions between 3.10.0 and 3.12.3 (inclusive), and all versions between 3.13.0 and 3.14.1 (inclusive).

  • CVE-2014-3622CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.03

    Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.

  • CVE-2019-20478CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.07

    In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an untrusted argument. In other words, this issue affects developers who are unaware of the need to use methods such as safe_load in these use cases.

  • CVE-2019-20477CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.05

    PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.

  • CVE-2020-7796CriKEVFeb 18, 2020
    risk 0.75cvss 9.8epss 0.84

    Zimbra Collaboration Suite (ZCS) before 8.8.15 Patch 7 allows SSRF when WebEx zimlet is installed and zimlet JSP is enabled.

  • CVE-2015-7567CriFeb 18, 2020
    risk 0.60cvss 9.8epss 0.04

    SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passwordreset&token" parameter.

  • CVE-2019-10791CriFeb 18, 2020
    risk 0.57cvss 9.8epss 0.02

    promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and options functions can be controlled by users without any sanitization.

  • CVE-2014-3879CriFeb 18, 2020
    risk 0.64cvss 9.8epss 0.03

    OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a policy that does not exist, which causes the loaded policy chain to no be discarded and allows context-dependent attackers to bypass authentication via a login…

  • CVE-2013-6295CriFeb 18, 2020
    risk 0.57cvss 9.8epss 0.02

    PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module

  • CVE-2013-3323CriFeb 18, 2020
    risk 0.64cvss 9.8epss 0.03

    A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.