VYPR

CVEs

38,008 total · page 585 of 761

  • CVE-2020-7450CriFeb 18, 2020
    risk 0.64cvss 9.8epss 0.03

    In FreeBSD 12.1-STABLE before r357213, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0-RELEASE before 12.0-RELEASE-p13, 11.3-STABLE before r357214, and 11.3-RELEASE before 11.3-RELEASE-p6, URL handling in libfetch with URLs containing username and/or password components is vulnerable…

  • CVE-2019-5613CriFeb 18, 2020
    risk 0.64cvss 9.8epss 0.01

    In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec packet processor allows reinjection of an old packet to be accepted by the ipsec endpoint. Depending on the higher-level protocol in use over ipsec, this could allow an action to be repeated.

  • CVE-2014-4967CriFeb 18, 2020
    risk 0.57cvss 9.8epss 0.04

    Multiple argument injection vulnerabilities in Ansible before 1.6.7 allow remote attackers to execute arbitrary code by leveraging access to an Ansible managed host and providing a crafted fact, as demonstrated by a fact with (1) a trailing " src=" clause, (2) a trailing "…

  • CVE-2014-4966CriFeb 18, 2020
    risk 0.57cvss 9.8epss 0.04

    Ansible before 1.6.7 does not prevent inventory data with "{{" and "lookup" substrings, and does not prevent remote data with "{{" substrings, which allows remote attackers to execute arbitrary code via (1) crafted lookup('pipe') calls or (2) crafted Jinja2 data.

  • CVE-2015-6970CriFeb 18, 2020
    risk 0.67cvss 9.8epss 0.05

    The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the idstring parameter to rcp.xml.

  • CVE-2014-4651CriFeb 18, 2020
    risk 0.64cvss 9.8epss 0.02

    It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to access sensitive data, cause a denial of service, or perform other attacks.

  • CVE-2013-4454CriFeb 18, 2020
    risk 0.59cvss 9.1epss 0.04

    WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities

  • CVE-2015-1425CriFeb 18, 2020
    risk 0.64cvss 9.8epss 0.02

    JAKWEB Gecko CMS has Multiple Input Validation Vulnerabilities

  • CVE-2020-8012CriFeb 18, 2020
    risk 0.73cvss 9.8epss 0.77

    CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerability in the robot (controller) component. A remote attacker can execute arbitrary code.

  • CVE-2020-8010CriFeb 18, 2020
    risk 0.71cvss 9.8epss 0.51

    CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vulnerability in the robot (controller) component. A remote attacker can execute commands, read from, or write to the target system.

  • CVE-2014-8089CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.03

    SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte.

  • CVE-2014-7236CriFeb 17, 2020
    risk 0.67cvss 9.1epss 0.56

    Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.

  • CVE-2014-4981CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.06

    LPAR2RRD in 3.5 and earlier allows remote attackers to execute arbitrary commands due to insufficient input sanitization of the web GUI parameters.

  • CVE-2020-8768CriFeb 17, 2020
    risk 0.61cvss 9.4epss 0.02

    An issue was discovered on Phoenix Contact Emalytics Controller ILC 2050 BI before 1.2.3 and BI-L before 1.2.3 devices. There is an insecure mechanism for read and write access to the configuration of the device. The mechanism can be discovered by examining a link on the website…

  • CVE-2015-6922CriFeb 17, 2020
    risk 0.66cvss 9.8epss 0.82

    Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before 9.1.0.9 does not properly require authentication, which allows remote attackers to bypass authentication and (1) add an administrative account via crafted…

  • CVE-2013-3738CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.03

    A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-9006CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.09

    The Popup Builder plugin 2.2.8 through 2.6.7.6 for WordPress is vulnerable to SQL injection (in the sgImportPopups function in sg_popup_ajax.php) via PHP Deserialization on attacker-controlled data with the attachmentUrl POST variable. This allows creation of an arbitrary…

  • CVE-2020-8518CriFeb 17, 2020
    risk 0.72cvss 9.8epss 0.72

    Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.

  • CVE-2020-8427CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.02

    In Unitrends Backup before 10.4.1, an HTTP request parameter was not properly sanitized, allowing for SQL injection that resulted in an authentication bypass.

  • CVE-2020-5531CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.02

    Mitsubishi Electric MELSEC C Controller Module and MELIPC Series MI5000 MELSEC-Q Series C Controller Module(Q24DHCCPU-V, Q24DHCCPU-VG User Ethernet port (CH1, CH2): First 5 digits of serial number 21121 or before), MELSEC iQ-R Series C Controller Module / C Intelligent Function…

  • CVE-2020-9027CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.03

    ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the TRACE field of the resource ping.cmd. The NTP-2 device is also affected.

  • CVE-2020-9026CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.03

    ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the PING field of the resource ping.cmd. The NTP-2 device is also affected.

  • CVE-2020-9024CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.02

    Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have world-writable permissions for the /root/cleardata.pl (executed as root by crond) and /root/loadperl.sh (executed as root at boot time) scripts.

  • CVE-2020-9023CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.01

    Iteris Vantage Velocity Field Unit 2.3.1 and 2.4.2 devices have two users that are not documented and are configured with weak passwords (User bluetooth, password bluetooth; User eclipse, password eclipse). Also, bluetooth is the root password.

  • CVE-2020-9021CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.02

    Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12.5 is vulnerable to injections of operating system commands through timeconfig.py via shell metacharacters in the htmlNtpServer parameter.

  • CVE-2020-9020CriFeb 17, 2020
    risk 0.64cvss 9.8epss 0.03

    Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field.

  • CVE-2020-8129CriFeb 14, 2020
    risk 0.64cvss 9.8epss 0.03

    An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code.

  • CVE-2020-8128CriFeb 14, 2020
    risk 0.64cvss 9.8epss 0.03

    An unintended require and server-side request forgery vulnerabilities in jsreport version 2.5.0 and earlier allow attackers to execute arbitrary code.

  • CVE-2019-4392CriFeb 14, 2020
    risk 0.64cvss 9.8epss 0.01

    HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get unauthorized access to the system.

  • CVE-2013-4211CriFeb 14, 2020
    risk 0.72cvss 9.8epss 0.71

    A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP code

  • CVE-2020-8612CriFeb 14, 2020
    risk 0.59cvss 9.0epss 0.02

    In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.2 before 2019.2.1, a REST API endpoint failed to adequately sanitize malicious input, which could allow an authenticated attacker to execute arbitrary code in a victim's browser, aka XSS.

  • CVE-2019-20046CriFeb 14, 2020
    risk 0.64cvss 9.8epss 0.02

    The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and prior. The affected product does not require adequate authentication, which may allow an attacker to read sensitive information or execute arbitrary code. This is…

  • CVE-2013-7287CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.01

    MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.

  • CVE-2013-7173CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.02

    Belkin n750 routers have a buffer overflow.

  • CVE-2013-7098CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.02

    OpenConnect VPN client with GnuTLS before 5.02 contains a heap overflow if MTU is increased on reconnection.

  • CVE-2013-6362CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.01

    Xerox ColorCube and WorkCenter devices in 2013 had hardcoded FTP and shell user accounts.

  • CVE-2013-1401CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.05

    Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPress allow a remote attacker to add, edit, and delete an answer and delete a poll.

  • CVE-2013-1400CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.03

    Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollResults or userlogs action.

  • CVE-2014-4198CriFeb 13, 2020
    risk 0.59cvss 9.1epss 0.01

    A Two-Factor Authentication Bypass Vulnerability exists in BS-Client Private Client 2.4 and 2.5 via an XML request that neglects the use of ADPswID and AD parameters, which could let a malicious user access privileged function.

  • CVE-2014-4170CriFeb 13, 2020
    risk 0.68cvss 9.8epss 0.14

    A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database information.

  • CVE-2014-3919CriFeb 13, 2020
    risk 0.61cvss 9.3epss 0.01

    A vulnerability exists in Netgear CG3100 devices before 3.9.2421.13.mp3 V0027 via an embed malicious script in an unspecified page, which could let a malicious user obtain sensitive information.

  • CVE-2020-8803CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.03

    SuiteCRM through 7.11.11 allows Directory Traversal to include arbitrary .php files within the webroot via add_to_prospect_list.

  • CVE-2020-8802CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.03

    SuiteCRM through 7.11.11 has Incorrect Access Control via action_saveHTMLField Bean Manipulation.

  • CVE-2020-8614CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on Askey AP4000W TDC_V1.01.003 devices. An attacker can perform Remote Code Execution (RCE) by sending a specially crafted network packer to the bd_svr service listening on TCP port 54188.

  • CVE-2020-3763CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.04

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to arbitrary file system write.

  • CVE-2020-3762CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.03

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to arbitrary file system write.

  • CVE-2020-3760CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.07

    Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3754CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.05

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

  • CVE-2020-3752CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.05

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a buffer error vulnerability. Successful exploitation could lead to arbitrary code execution .

  • CVE-2020-3751CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.05

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .