VYPR

CVEs

38,008 total · page 588 of 761

  • CVE-2020-8547CriFeb 3, 2020
    risk 0.67cvss 9.8epss 0.06

    phpList 3.5.0 allows type juggling for admin login bypass because == is used instead of === for password hashes, which mishandles hashes that begin with 0e followed by exclusively numerical characters.

  • CVE-2020-8510CriFeb 3, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in phpABook 0.9 Intermediate. On the login page, if one sets a userInfo cookie with the value of admin+1+en (user+perms+lang), one can login as any user without a password.

  • CVE-2020-7471CriFeb 3, 2020
    risk 0.62cvss 9.8epss 0.66

    Django 1.11 before 1.11.28, 2.2 before 2.2.10, and 3.0 before 3.0.3 allows SQL Injection if untrusted data is used as a StringAgg delimiter (e.g., in Django applications that offer downloads of data as a series of rows with a user-specified column delimiter). By passing a…

  • CVE-2020-8508CriFeb 3, 2020
    risk 0.64cvss 9.8epss 0.02

    nsak64.sys in Norman Malware Cleaner 2.08.08 allows users to call arbitrary kernel functions because the passing of function pointers between user and kernel mode is mishandled.

  • CVE-2020-8515CriKEVFeb 1, 2020
    risk 0.87cvss 9.8epss 1.00

    DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has been fixed in…

  • CVE-2014-2025CriJan 31, 2020
    risk 0.64cvss 9.8epss 0.04

    Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an executable extension,…

  • CVE-2014-8322CriJan 31, 2020
    risk 0.62cvss 9.8epss 0.24

    Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.

  • CVE-2014-5039CriJan 31, 2020
    risk 0.62cvss 9.6epss 0.01

    Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-2031CriJan 31, 2020
    risk 0.64cvss 9.8epss 0.05

    Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive information, perform…

  • CVE-2020-8440CriJan 31, 2020
    risk 0.64cvss 9.8epss 0.03

    controllers/page_apply.php in Simplejobscript.com SJS through 1.66 is prone to unauthenticated Remote Code Execution by uploading a PHP script as a resume.

  • CVE-2020-7956CriJan 31, 2020
    risk 0.64cvss 9.8epss 0.01

    HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.

  • CVE-2013-2198CriJan 30, 2020
    risk 0.64cvss 9.8epss 0.02

    The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows attackers to bypass intended restrictions via a crafted username.

  • CVE-2014-3719CriJan 30, 2020
    risk 0.64cvss 9.8epss 0.02

    Multiple SQL injection vulnerabilities in cgi-bin/review_m.cgi in Ex Libris ALEPH 500 (Integrated library management system) 18.1 and 20 allow remote attackers to execute arbitrary SQL commands via the (1) find, (2) lib, or (3) sid parameter.

  • CVE-2013-1350CriJan 30, 2020
    risk 0.59cvss 9.1epss 0.02

    Verax NMS prior to 2.1.0 has multiple security bypass vulnerabilities

  • CVE-2020-8447CriJan 30, 2020
    risk 0.64cvss 9.8epss 0.02

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of syscheck formatted msgs (received from authenticated remote agents and delivered to the analysisd processing queue by…

  • CVE-2020-8445CriJan 30, 2020
    risk 0.64cvss 9.8epss 0.02

    In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many cases, those characters are later logged. Because newlines (\n) are permitted in messages processed…

  • CVE-2020-8444CriJan 30, 2020
    risk 0.64cvss 9.8epss 0.02

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of ossec-alert formatted msgs (received from authenticated remote agents and delivered to the analysisd processing queue by…

  • CVE-2020-8443CriJan 30, 2020
    risk 0.64cvss 9.8epss 0.03

    In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-based buffer overflow during the cleaning of crafted syslog msgs (received from authenticated remote agents and delivered to the analysisd…

  • CVE-2019-10783CriJan 29, 2020
    risk 0.64cvss 9.8epss 0.03

    All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the package uses the exec function to parse user input.

  • CVE-2013-3317CriJan 29, 2020
    risk 0.64cvss 9.8epss 0.05

    Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.

  • CVE-2013-3316CriJan 29, 2020
    risk 0.64cvss 9.8epss 0.05

    Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".

  • CVE-2019-20445CriJan 29, 2020
    risk 0.60cvss 9.1epss 0.13

    HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.

  • CVE-2019-20444CriJan 29, 2020
    risk 0.60cvss 9.1epss 0.09

    HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold."

  • CVE-2020-8432CriJan 29, 2020
    risk 0.64cvss 9.8epss 0.03

    In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what-where condition, allowing an attacker to execute arbitrary code. NOTE: this vulnerablity was introduced when attempting to fix a…

  • CVE-2020-3718CriJan 29, 2020
    risk 0.64cvss 9.8epss 0.08

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2020-3716CriJan 29, 2020
    risk 0.65cvss 9.8epss 0.14

    Magento versions 2.3.3 and earlier, 2.2.10 and earlier, 1.14.4.3 and earlier, and 1.9.4.3 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2013-2573CriJan 29, 2020
    risk 0.70cvss 9.8epss 0.42

    A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, 3171G. and 4171G 1.6.18P12s, which could let a malicious user execute arbitrary code.

  • CVE-2013-3215CriJan 29, 2020
    risk 0.72cvss 9.8epss 0.69

    vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.

  • CVE-2013-2570CriJan 29, 2020
    risk 0.69cvss 9.8epss 0.27

    A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the binary /opt/cgi/view/param, which could let a remove malicious user execute arbitrary code.

  • CVE-2013-2568CriJan 29, 2020
    risk 0.71cvss 9.8epss 0.49

    A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-7247CriKEVJan 29, 2020
    risk 0.87cvss 9.8epss 0.99

    smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented"…

  • CVE-2019-20217CriJan 29, 2020
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because SERVER_ID is mishandled. The value of the urn: service/device is checked with the strstr function,…

  • CVE-2019-20216CriJan 29, 2020
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because REMOTE_PORT is mishandled. The value of the urn: service/device is checked with the strstr function,…

  • CVE-2019-20215CriJan 29, 2020
    risk 0.73cvss 9.8epss 0.75

    D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because HTTP_ST is mishandled. The value of the urn: service/device is checked with the strstr function, which…

  • CVE-2013-3214CriJan 28, 2020
    risk 0.73cvss 9.8epss 0.85

    vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.

  • CVE-2013-3071CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.02

    NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.

  • CVE-2013-2748CriJan 28, 2020
    risk 0.68cvss 9.8epss 0.13

    Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.

  • CVE-2013-1599CriJan 28, 2020
    risk 0.70cvss 9.8epss 0.40

    A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01, DCS-1100L/1130L 1.04, DCS-1100/1130 1.03, DCS-1100/1130 1.04_US, DCS-2102/2121 1.05_RU, DCS-3410 1.02, DCS-5230 1.02, DCS-5230L…

  • CVE-2020-4207CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.05

    IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking when handling a failed HTTP request with specific content in the headers. By sending a specially crafted HTTP request, a remote attacker…

  • CVE-2015-8011CriJan 28, 2020
    risk 0.57cvss 9.8epss 0.05

    Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.

  • CVE-2020-8086CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.02

    The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username of a local admin.

  • CVE-2013-4864CriJan 28, 2020
    risk 0.67cvss 9.8epss 0.06

    MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side Request Forgery (SSRF) issue.

  • CVE-2014-2914CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.03

    fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by set_prompt.

  • CVE-2014-2898CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.03

    wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers an out-of-bounds read when an error occurs, related to not checking the return code and MAC verification failure.

  • CVE-2014-2897CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.03

    The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows remote attackers to have unspecified impact via a crafted HMAC, which triggers an out-of-bounds read.

  • CVE-2014-2896CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.03

    The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an out-of-bounds read.

  • CVE-2013-2060CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.06

    The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart.

  • CVE-2014-3445CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.05

    backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash.

  • CVE-2013-2571CriJan 28, 2020
    risk 0.68cvss 9.8epss 0.16

    Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer.

  • CVE-2013-1437CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.03

    Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.