| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2014-5087 | Cri | 0.67 | 9.8 | 0.07 | Feb 7, 2020 | A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code. | ||
| CVE-2019-15606 | Cri | 0.65 | 9.8 | 0.20 | Feb 7, 2020 | Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons | ||
| CVE-2019-15605 | Cri | 0.68 | 9.8 | 0.57 | Feb 7, 2020 | HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed | ||
| CVE-2014-9530 | Cri | 0.64 | 9.8 | 0.01 | Feb 7, 2020 | A vulnerability exists in nw.js before 0.11.3 when calling nw methods from normal frames, which has an unspecified impact. | ||
| CVE-2013-4335 | Cri | 0.57 | 9.8 | 0.02 | Feb 7, 2020 | opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilities | ||
| CVE-2019-17268 | Cri | 0.64 | 9.8 | 0.02 | Feb 7, 2020 | The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected. | ||
| CVE-2013-4334 | Cri | 0.57 | 9.8 | 0.01 | Feb 7, 2020 | opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities | ||
| CVE-2019-14063 | Cri | 0.59 | 9.1 | 0.01 | Feb 7, 2020 | Out of bound access due to Invalid inputs to dapm mux settings which results into kernel failure in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and… | ||
| CVE-2019-14057 | Cri | 0.59 | 9.1 | 0.01 | Feb 7, 2020 | Buffer Over read of codec private data while parsing an mkv file due to lack of check of buffer size before read in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon… | ||
| CVE-2019-10590 | Cri | 0.64 | 9.8 | 0.01 | Feb 7, 2020 | Out of bound access while parsing dts atom, which is non-standard as it does not have valid number of tracks in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &… | ||
| CVE-2020-8656 | Cri | 0.73 | 9.8 | 0.85 | Feb 7, 2020 | An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php. | ||
| CVE-2020-8645 | Cri | 0.64 | 9.8 | 0.02 | Feb 7, 2020 | An issue was discovered in Simplejobscript.com SJS through 1.66. There is an unauthenticated SQL injection via the job applications search function. The vulnerable parameter is job_id. The function is getJobApplicationsByJobId(). The file is _lib/class.JobApplication.php. | ||
| CVE-2020-6760 | Cri | 0.64 | 9.8 | 0.02 | Feb 6, 2020 | Schmid ZI 620 V400 VPN 090 routers allow an attacker to execute OS commands as root via shell metacharacters to an entry on the SSH subcommand menu, as demonstrated by ping. | ||
| CVE-2020-8657 | Cri | 0.86 | 9.8 | 0.92 | KEV | Feb 6, 2020 | An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attacker to calculate/guess the admin access token. | |
| CVE-2012-6306 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2020 | A vulnerability exists in HCView (aka Hardcoreview) 1.4 due to a write access violation with a GIF file. | ||
| CVE-2020-8772 | Cri | 0.74 | 9.8 | 0.88 | Feb 6, 2020 | The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in. | ||
| CVE-2020-8771 | Cri | 0.67 | 9.8 | 0.46 | Feb 6, 2020 | The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts. | ||
| CVE-2020-8636 | Cri | 0.64 | 9.8 | 0.04 | Feb 6, 2020 | An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution . | ||
| CVE-2019-10789 | Cri | 0.64 | 9.8 | 0.05 | Feb 6, 2020 | All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization. | ||
| CVE-2013-4521 | Cri | 0.57 | 9.8 | 0.04 | Feb 6, 2020 | RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may… | ||
| CVE-2015-2909 | Cri | 0.64 | 9.8 | 0.03 | Feb 6, 2020 | Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote attackers to obtain access by leveraging situations in which this warning was not… | ||
| CVE-2011-1517 | Cri | 0.64 | 9.8 | 0.04 | Feb 5, 2020 | SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash. | ||
| CVE-2020-8644 | Cri | 0.79 | 9.8 | 0.87 | KEV | Feb 5, 2020 | PlaySMS before 1.4.3 does not sanitize inputs from a malicious string. | |
| CVE-2011-1151 | Cri | 0.59 | 9.1 | 0.02 | Feb 5, 2020 | Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters. | ||
| CVE-2013-2681 | Cri | 0.68 | 9.8 | 0.10 | Feb 5, 2020 | Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access. | ||
| CVE-2019-20447 | Cri | 0.64 | 9.8 | 0.02 | Feb 5, 2020 | Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint. | ||
| CVE-2015-5628 | Cri | 0.64 | 9.8 | 0.07 | Feb 5, 2020 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and… | ||
| CVE-2015-5627 | Cri | 0.64 | 9.8 | 0.04 | Feb 5, 2020 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and… | ||
| CVE-2015-5626 | Cri | 0.64 | 9.8 | 0.04 | Feb 5, 2020 | Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and… | ||
| CVE-2010-4815 | Cri | 0.64 | 9.8 | 0.02 | Feb 5, 2020 | Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution. | ||
| CVE-2020-6754 | Cri | 0.71 | 9.8 | 0.95 | Feb 5, 2020 | dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g.,… | ||
| CVE-2020-6969 | Cri | 0.64 | 9.8 | 0.02 | Feb 5, 2020 | It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access the C-More Touch Panels EA9 series: firmware versions prior to 6.53 and manipulate system configurations. | ||
| CVE-2020-6174 | Cri | 0.57 | 9.8 | 0.01 | Feb 5, 2020 | TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature. | ||
| CVE-2020-8114 | Cri | 0.64 | 9.8 | 0.01 | Feb 5, 2020 | GitLab EE 8.9 and later through 12.7.2 has Insecure Permission | ||
| CVE-2019-10788 | Cri | 0.57 | 9.8 | 0.02 | Feb 4, 2020 | im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible to inject arbitrary commands as part of the metadata options which is given to the "exec" function. | ||
| CVE-2019-10787 | Cri | 0.57 | 9.8 | 0.04 | Feb 4, 2020 | im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be controlled by user without any sanitization. | ||
| CVE-2019-10786 | Cri | 0.64 | 9.8 | 0.02 | Feb 4, 2020 | network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument. | ||
| CVE-2020-8125 | Cri | 0.57 | 9.8 | 0.04 | Feb 4, 2020 | Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using klona. | ||
| CVE-2020-6058 | Cri | 0.59 | 9.1 | 0.02 | Feb 4, 2020 | An exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out-of-bounds memory read, which can result in the disclosure of sensitive information and denial of service. To… | ||
| CVE-2015-3613 | Cri | 0.64 | 9.8 | 0.02 | Feb 4, 2020 | A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page | ||
| CVE-2019-10784 | Cri | 0.63 | 9.6 | 0.04 | Feb 4, 2020 | phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verify the source of an HTTP request. This can be leveraged by a remote attacker to trick a logged-in… | ||
| CVE-2019-4675 | Cri | 0.64 | 9.8 | 0.01 | Feb 4, 2020 | IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171511. | ||
| CVE-2013-7055 | Cri | 0.67 | 9.8 | 0.07 | Feb 4, 2020 | D-Link DIR-100 4.03B07 has PPTP and poe information disclosure | ||
| CVE-2013-7052 | Cri | 0.69 | 9.8 | 0.25 | Feb 4, 2020 | D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script | ||
| CVE-2012-5686 | Cri | 0.67 | 9.8 | 0.05 | Feb 4, 2020 | ZPanel 10.0.1 has insufficient entropy for its password reset process. | ||
| CVE-2012-5618 | Cri | 0.57 | 9.8 | 0.01 | Feb 4, 2020 | Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens. | ||
| CVE-2020-3938 | Cri | 0.64 | 9.8 | 0.01 | Feb 4, 2020 | SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to launch inquiries into network architecture or system files of the server via forged inquests. | ||
| CVE-2020-8597 | Cri | 0.65 | 9.8 | 0.20 | Feb 3, 2020 | eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions. | ||
| CVE-2020-8592 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2020 | eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password feature). | ||
| CVE-2020-8591 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2020 | eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request. |
- risk 0.67cvss 9.8epss 0.07
A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code.
- risk 0.65cvss 9.8epss 0.20
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons
- risk 0.68cvss 9.8epss 0.57
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed
- risk 0.64cvss 9.8epss 0.01
A vulnerability exists in nw.js before 0.11.3 when calling nw methods from normal frames, which has an unspecified impact.
- risk 0.57cvss 9.8epss 0.02
opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilities
- risk 0.64cvss 9.8epss 0.02
The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected.
- risk 0.57cvss 9.8epss 0.01
opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities
- risk 0.59cvss 9.1epss 0.01
Out of bound access due to Invalid inputs to dapm mux settings which results into kernel failure in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and…
- risk 0.59cvss 9.1epss 0.01
Buffer Over read of codec private data while parsing an mkv file due to lack of check of buffer size before read in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon…
- risk 0.64cvss 9.8epss 0.01
Out of bound access while parsing dts atom, which is non-standard as it does not have valid number of tracks in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…
- risk 0.73cvss 9.8epss 0.85
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in Simplejobscript.com SJS through 1.66. There is an unauthenticated SQL injection via the job applications search function. The vulnerable parameter is job_id. The function is getJobApplicationsByJobId(). The file is _lib/class.JobApplication.php.
- risk 0.64cvss 9.8epss 0.02
Schmid ZI 620 V400 VPN 090 routers allow an attacker to execute OS commands as root via shell metacharacters to an entry on the SSH subcommand menu, as demonstrated by ping.
- risk 0.86cvss 9.8epss 0.92
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attacker to calculate/guess the admin access token.
- risk 0.64cvss 9.8epss 0.01
A vulnerability exists in HCView (aka Hardcoreview) 1.4 due to a write access violation with a GIF file.
- risk 0.74cvss 9.8epss 0.88
The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.
- risk 0.67cvss 9.8epss 0.46
The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts.
- risk 0.64cvss 9.8epss 0.04
An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .
- risk 0.64cvss 9.8epss 0.05
All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.
- risk 0.57cvss 9.8epss 0.04
RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may…
- risk 0.64cvss 9.8epss 0.03
Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote attackers to obtain access by leveraging situations in which this warning was not…
- risk 0.64cvss 9.8epss 0.04
SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash.
- risk 0.79cvss 9.8epss 0.87
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
- risk 0.59cvss 9.1epss 0.02
Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.
- risk 0.68cvss 9.8epss 0.10
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.
- risk 0.64cvss 9.8epss 0.02
Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint.
- risk 0.64cvss 9.8epss 0.07
Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and…
- risk 0.64cvss 9.8epss 0.04
Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and…
- risk 0.64cvss 9.8epss 0.04
Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and…
- risk 0.64cvss 9.8epss 0.02
Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution.
- risk 0.71cvss 9.8epss 0.95
dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g.,…
- risk 0.64cvss 9.8epss 0.02
It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access the C-More Touch Panels EA9 series: firmware versions prior to 6.53 and manipulate system configurations.
- risk 0.57cvss 9.8epss 0.01
TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.
- risk 0.64cvss 9.8epss 0.01
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
- risk 0.57cvss 9.8epss 0.02
im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible to inject arbitrary commands as part of the metadata options which is given to the "exec" function.
- risk 0.57cvss 9.8epss 0.04
im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be controlled by user without any sanitization.
- risk 0.64cvss 9.8epss 0.02
network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument.
- risk 0.57cvss 9.8epss 0.04
Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using klona.
- risk 0.59cvss 9.1epss 0.02
An exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out-of-bounds memory read, which can result in the disclosure of sensitive information and denial of service. To…
- risk 0.64cvss 9.8epss 0.02
A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page
- risk 0.63cvss 9.6epss 0.04
phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verify the source of an HTTP request. This can be leveraged by a remote attacker to trick a logged-in…
- risk 0.64cvss 9.8epss 0.01
IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171511.
- risk 0.67cvss 9.8epss 0.07
D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
- risk 0.69cvss 9.8epss 0.25
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
- risk 0.67cvss 9.8epss 0.05
ZPanel 10.0.1 has insufficient entropy for its password reset process.
- risk 0.57cvss 9.8epss 0.01
Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.
- risk 0.64cvss 9.8epss 0.01
SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to launch inquiries into network architecture or system files of the server via forged inquests.
- risk 0.65cvss 9.8epss 0.20
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
- risk 0.64cvss 9.8epss 0.01
eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password feature).
- risk 0.64cvss 9.8epss 0.01
eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.