VYPR

CVEs

38,008 total · page 587 of 761

  • CVE-2014-5087CriFeb 7, 2020
    risk 0.67cvss 9.8epss 0.07

    A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code.

  • CVE-2019-15606CriFeb 7, 2020
    risk 0.65cvss 9.8epss 0.20

    Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

  • CVE-2019-15605CriFeb 7, 2020
    risk 0.68cvss 9.8epss 0.57

    HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed

  • CVE-2014-9530CriFeb 7, 2020
    risk 0.64cvss 9.8epss 0.01

    A vulnerability exists in nw.js before 0.11.3 when calling nw methods from normal frames, which has an unspecified impact.

  • CVE-2013-4335CriFeb 7, 2020
    risk 0.57cvss 9.8epss 0.02

    opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vulnerabilities

  • CVE-2019-17268CriFeb 7, 2020
    risk 0.64cvss 9.8epss 0.02

    The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected.

  • CVE-2013-4334CriFeb 7, 2020
    risk 0.57cvss 9.8epss 0.01

    opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities

  • CVE-2019-14063CriFeb 7, 2020
    risk 0.59cvss 9.1epss 0.01

    Out of bound access due to Invalid inputs to dapm mux settings which results into kernel failure in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and…

  • CVE-2019-14057CriFeb 7, 2020
    risk 0.59cvss 9.1epss 0.01

    Buffer Over read of codec private data while parsing an mkv file due to lack of check of buffer size before read in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon…

  • CVE-2019-10590CriFeb 7, 2020
    risk 0.64cvss 9.8epss 0.01

    Out of bound access while parsing dts atom, which is non-standard as it does not have valid number of tracks in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2020-8656CriFeb 7, 2020
    risk 0.73cvss 9.8epss 0.85

    An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform various tasks such as authentication bypass via the username field to getApiKey in include/api_functions.php.

  • CVE-2020-8645CriFeb 7, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Simplejobscript.com SJS through 1.66. There is an unauthenticated SQL injection via the job applications search function. The vulnerable parameter is job_id. The function is getJobApplicationsByJobId(). The file is _lib/class.JobApplication.php.

  • CVE-2020-6760CriFeb 6, 2020
    risk 0.64cvss 9.8epss 0.02

    Schmid ZI 620 V400 VPN 090 routers allow an attacker to execute OS commands as root via shell metacharacters to an entry on the SSH subcommand menu, as demonstrated by ping.

  • CVE-2020-8657CriKEVFeb 6, 2020
    risk 0.86cvss 9.8epss 0.92

    An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API version 2.4.2) by default for all installations, hence allowing an attacker to calculate/guess the admin access token.

  • CVE-2012-6306CriFeb 6, 2020
    risk 0.64cvss 9.8epss 0.01

    A vulnerability exists in HCView (aka Hardcoreview) 1.4 due to a write access violation with a GIF file.

  • CVE-2020-8772CriFeb 6, 2020
    risk 0.74cvss 9.8epss 0.88

    The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in init.php. Any attacker who knows the username of an administrator can log in.

  • CVE-2020-8771CriFeb 6, 2020
    risk 0.67cvss 9.8epss 0.46

    The Time Capsule plugin before 1.21.16 for WordPress has an authentication bypass. Any request containing IWP_JSON_PREFIX causes the client to be logged in as the first account on the list of administrator accounts.

  • CVE-2020-8636CriFeb 6, 2020
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .

  • CVE-2019-10789CriFeb 6, 2020
    risk 0.64cvss 9.8epss 0.05

    All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.

  • CVE-2013-4521CriFeb 6, 2020
    risk 0.57cvss 9.8epss 0.04

    RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may…

  • CVE-2015-2909CriFeb 6, 2020
    risk 0.64cvss 9.8epss 0.03

    Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote attackers to obtain access by leveraging situations in which this warning was not…

  • CVE-2011-1517CriFeb 5, 2020
    risk 0.64cvss 9.8epss 0.04

    SAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafted packet, an attacker could exploit this vulnerability to cause the application to crash.

  • CVE-2020-8644CriKEVFeb 5, 2020
    risk 0.79cvss 9.8epss 0.87

    PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.

  • CVE-2011-1151CriFeb 5, 2020
    risk 0.59cvss 9.1epss 0.02

    Joomla! 1.6.0 is vulnerable to SQL Injection via the filter_order and filer_order_Dir parameters.

  • CVE-2013-2681CriFeb 5, 2020
    risk 0.68cvss 9.8epss 0.10

    Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.

  • CVE-2019-20447CriFeb 5, 2020
    risk 0.64cvss 9.8epss 0.02

    Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint.

  • CVE-2015-5628CriFeb 5, 2020
    risk 0.64cvss 9.8epss 0.07

    Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and…

  • CVE-2015-5627CriFeb 5, 2020
    risk 0.64cvss 9.8epss 0.04

    Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and…

  • CVE-2015-5626CriFeb 5, 2020
    risk 0.64cvss 9.8epss 0.04

    Stack-based buffer overflow in Yokogawa CENTUM CS 1000 R3.08.70 and earlier, CENTUM CS 3000 R3.09.50 and earlier, CENTUM CS 3000 Entry R3.09.50 and earlier, CENTUM VP R5.04.20 and earlier, CENTUM VP Entry R5.04.20 and earlier, ProSafe-RS R3.02.10 and earlier, Exaopc R3.72.00 and…

  • CVE-2010-4815CriFeb 5, 2020
    risk 0.64cvss 9.8epss 0.02

    Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution.

  • CVE-2020-6754CriFeb 5, 2020
    risk 0.71cvss 9.8epss 0.95

    dotCMS before 5.2.4 is vulnerable to directory traversal, leading to incorrect access control. It allows an attacker to read or execute files under $TOMCAT_HOME/webapps/ROOT/assets (which should be a protected directory). Additionally, attackers can upload temporary files (e.g.,…

  • CVE-2020-6969CriFeb 5, 2020
    risk 0.64cvss 9.8epss 0.02

    It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access the C-More Touch Panels EA9 series: firmware versions prior to 6.53 and manipulate system configurations.

  • CVE-2020-6174CriFeb 5, 2020
    risk 0.57cvss 9.8epss 0.01

    TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.

  • CVE-2020-8114CriFeb 5, 2020
    risk 0.64cvss 9.8epss 0.01

    GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

  • CVE-2019-10788CriFeb 4, 2020
    risk 0.57cvss 9.8epss 0.02

    im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible to inject arbitrary commands as part of the metadata options which is given to the "exec" function.

  • CVE-2019-10787CriFeb 4, 2020
    risk 0.57cvss 9.8epss 0.04

    im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument used within index.js, can be controlled by user without any sanitization.

  • CVE-2019-10786CriFeb 4, 2020
    risk 0.64cvss 9.8epss 0.02

    network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument.

  • CVE-2020-8125CriFeb 4, 2020
    risk 0.57cvss 9.8epss 0.04

    Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using klona.

  • CVE-2020-6058CriFeb 4, 2020
    risk 0.59cvss 9.1epss 0.02

    An exploitable out-of-bounds read vulnerability exists in the way MiniSNMPD version 1.4 parses incoming SNMP packets. A specially crafted SNMP request can trigger an out-of-bounds memory read, which can result in the disclosure of sensitive information and denial of service. To…

  • CVE-2015-3613CriFeb 4, 2020
    risk 0.64cvss 9.8epss 0.02

    A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page

  • CVE-2019-10784CriFeb 4, 2020
    risk 0.63cvss 9.6epss 0.04

    phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from the application. One such area, "database.php" does not verify the source of an HTTP request. This can be leveraged by a remote attacker to trick a logged-in…

  • CVE-2019-4675CriFeb 4, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 171511.

  • CVE-2013-7055CriFeb 4, 2020
    risk 0.67cvss 9.8epss 0.07

    D-Link DIR-100 4.03B07 has PPTP and poe information disclosure

  • CVE-2013-7052CriFeb 4, 2020
    risk 0.69cvss 9.8epss 0.25

    D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script

  • CVE-2012-5686CriFeb 4, 2020
    risk 0.67cvss 9.8epss 0.05

    ZPanel 10.0.1 has insufficient entropy for its password reset process.

  • CVE-2012-5618CriFeb 4, 2020
    risk 0.57cvss 9.8epss 0.01

    Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.

  • CVE-2020-3938CriFeb 4, 2020
    risk 0.64cvss 9.8epss 0.01

    SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Request Forgery, allowing attackers to launch inquiries into network architecture or system files of the server via forged inquests.

  • CVE-2020-8597CriFeb 3, 2020
    risk 0.65cvss 9.8epss 0.20

    eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.

  • CVE-2020-8592CriFeb 3, 2020
    risk 0.64cvss 9.8epss 0.01

    eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password feature).

  • CVE-2020-8591CriFeb 3, 2020
    risk 0.64cvss 9.8epss 0.01

    eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.