VYPR

CVEs

38,008 total · page 586 of 761

  • CVE-2020-3750CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.05

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

  • CVE-2020-3749CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.05

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

  • CVE-2020-3746CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.05

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

  • CVE-2020-3745CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.05

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

  • CVE-2020-3743CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.05

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

  • CVE-2020-3742CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.06

    Adobe Acrobat and Reader versions, 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .

  • CVE-2020-3740CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.05

    Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-8962CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.02

    A stack-based buffer overflow was found on the D-Link DIR-842 REVC with firmware v3.13B09 HOTFIX due to the use of strcpy for LOGINPASSWORD when handling a POST request to the /MTFWU endpoint.

  • CVE-2020-8953CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.01

    OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass (except when a user is enrolled in two-factor authentication).

  • CVE-2020-8964CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.04

    TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to bypass authentication by placing t3axs=TiMEtOOlsj7G3xMm52wB in a t3.cgi…

  • CVE-2020-8963CriFeb 13, 2020
    risk 0.64cvss 9.8epss 0.03

    TimeTools SC7105 1.0.007, SC9205 1.0.007, SC9705 1.0.007, SR7110 1.0.007, SR9210 1.0.007, SR9750 1.0.007, SR9850 1.0.007, T100 1.0.003, T300 1.0.003, and T550 1.0.003 devices allow remote attackers to execute arbitrary OS commands via shell metacharacters in the t3.cgi srmodel…

  • CVE-2020-7209CriFeb 13, 2020
    risk 0.75cvss 9.8epss 0.99

    LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.

  • CVE-2020-8955CriFeb 12, 2020
    risk 0.64cvss 9.8epss 0.04

    irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malformed IRC message 324 (channel mode).

  • CVE-2011-4908CriFeb 12, 2020
    risk 0.71cvss 9.8epss 0.56

    TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.

  • CVE-2011-4906CriFeb 12, 2020
    risk 0.67cvss 9.8epss 0.10

    Tiny browser in TinyMCE 3.0 editor in Joomla! before 1.5.13 allows file upload and arbitrary PHP code execution.

  • CVE-2013-3725CriFeb 12, 2020
    risk 0.64cvss 9.8epss 0.02

    Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.

  • CVE-2013-6236CriFeb 12, 2020
    risk 0.68cvss 9.8epss 0.10

    IZON IP 2.0.2: hard-coded password vulnerability

  • CVE-2015-5617CriFeb 12, 2020
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in pub/m_pending_news/delete_pending_news.jsp in Enorth Webpublisher CMS allows remote attackers to execute arbitrary SQL commands via the cbNewsId parameter.

  • CVE-2013-7381CriFeb 12, 2020
    risk 0.57cvss 9.8epss 0.03

    libnotify before 1.0.4 for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in a call to libnotify.notify.

  • CVE-2013-2010CriFeb 12, 2020
    risk 0.73cvss 9.8epss 0.74

    WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability

  • CVE-2013-7378CriFeb 12, 2020
    risk 0.57cvss 9.8epss 0.03

    scripts/email.coffee in the Hubot Scripts module before 2.4.4 for Node.js allows remote attackers to execute arbitrary commands.

  • CVE-2014-9390CriFeb 12, 2020
    risk 0.66cvss 9.8epss 0.76

    Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all…

  • CVE-2014-2595CriFeb 12, 2020
    risk 0.68cvss 9.8epss 0.17

    Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.

  • CVE-2014-0234CriFeb 12, 2020
    risk 0.57cvss 9.8epss 0.04

    The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before…

  • CVE-2012-1124CriFeb 11, 2020
    risk 0.67cvss 9.8epss 0.04

    SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.

  • CVE-2014-9753CriFeb 11, 2020
    risk 0.57cvss 9.8epss 0.03

    confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login parameter.

  • CVE-2013-3684CriFeb 11, 2020
    risk 0.68cvss 9.8epss 0.19

    NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload

  • CVE-2013-2057CriFeb 11, 2020
    risk 0.64cvss 9.8epss 0.02

    YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability

  • CVE-2013-1607CriFeb 11, 2020
    risk 0.64cvss 9.8epss 0.03

    Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability

  • CVE-2013-1359CriFeb 11, 2020
    risk 0.74cvss 9.8epss 0.89

    An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, 5.1, and 6.0 via the skipSessionCheck parameter to the UMA…

  • CVE-2013-0803CriFeb 11, 2020
    risk 0.73cvss 9.8epss 0.75

    A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code.

  • CVE-2014-2052CriFeb 11, 2020
    risk 0.64cvss 9.8epss 0.02

    Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

  • CVE-2013-1360CriFeb 11, 2020
    risk 0.69cvss 9.8epss 0.23

    An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and ViewPoint 4.1, 5.0, and 6.0 via a crafted request to the SGMS interface, which…

  • CVE-2020-3934CriFeb 11, 2020
    risk 0.64cvss 9.8epss 0.01

    TAIWAN SECOM CO., LTD., a Door Access Control and Personnel Attendance Management system, contains a vulnerability of Pre-auth SQL Injection, allowing attackers to inject a specific SQL command.

  • CVE-2019-14514CriFeb 11, 2020
    risk 0.64cvss 9.8epss 0.07

    An issue was discovered in Microvirt MEmu all versions prior to 7.0.2. A guest Android operating system inside the MEmu emulator contains a /system/bin/systemd binary that is run with root privileges on startup (this is unrelated to Red Hat's systemd init program, and is a…

  • CVE-2013-5945CriFeb 11, 2020
    risk 0.67cvss 9.8epss 0.10

    Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to…

  • CVE-2013-4267CriFeb 11, 2020
    risk 0.57cvss 9.8epss 0.04

    Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Power FS module (plugins/action.powerfs/class.PowerFSController.php), a (2) file name to the getTrustSizeOnFileSystem function in the…

  • CVE-2020-8840CriFeb 10, 2020
    risk 0.59cvss 9.8epss 0.27

    FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.

  • CVE-2019-17137CriFeb 10, 2020
    risk 0.61cvss 9.4epss 0.03

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR AC1200 R6220 Firmware version 1.1.0.86 Smart WiFi Router. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2019-20451CriFeb 10, 2020
    risk 0.64cvss 9.8epss 0.08

    The HTTP API in Prismview System 9 11.10.17.00 and Prismview Player 11 13.09.1100 allows remote code execution by uploading RebootSystem.lnk and requesting /REBOOTSYSTEM or /RESTARTVNC. (Authentication is required but an XML file containing credentials can be downloaded.)

  • CVE-2012-6611CriFeb 10, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and can be successfully used without setting this password.

  • CVE-2019-20062CriFeb 10, 2020
    risk 0.64cvss 9.8epss 0.02

    MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).

  • CVE-2015-5741CriFeb 8, 2020
    risk 0.57cvss 9.8epss 0.03

    The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fields.

  • CVE-2014-8739CriFeb 8, 2020
    risk 0.74cvss 9.8epss 0.92

    Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote…

  • CVE-2011-3642CriFeb 8, 2020
    risk 0.66cvss 9.6epss 0.09

    Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an…

  • CVE-2020-6770CriFeb 7, 2020
    risk 0.65cvss 10.0epss 0.04

    Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.0.329 and 7.5 and older. This…

  • CVE-2020-8796CriFeb 7, 2020
    risk 0.64cvss 9.8epss 0.03

    Biscom Secure File Transfer (SFT) before 5.1.1071 and 6.0.1xxx before 6.0.1005 allows Remote Code Execution on the server.

  • CVE-2020-6769CriFeb 7, 2020
    risk 0.65cvss 10.0epss 0.02

    Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set arbitrary configuration data of the Video Streaming Gateway. A successful attack can impact the confidentiality and availability…

  • CVE-2013-3091CriFeb 7, 2020
    risk 0.64cvss 9.8epss 0.04

    An Authentication Bypass vulnerability in Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication using "Javascript debugging."

  • CVE-2014-5091CriFeb 7, 2020
    risk 0.68cvss 9.8epss 0.15

    A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code.