VYPR

CVEs

38,008 total · page 591 of 761

  • CVE-2020-2587CriJan 15, 2020
    risk 0.64cvss 9.9epss 0.02

    Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2020-2586CriJan 15, 2020
    risk 0.64cvss 9.9epss 0.02

    Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Hierarchy Diagrammers). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2020-2555CriKEVJan 15, 2020
    risk 0.86cvss 9.8epss 0.97

    Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2020-2551CriKEVJan 15, 2020
    risk 0.83cvss 9.8epss 0.93

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS Core Components). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2020-2546CriJan 15, 2020
    risk 0.64cvss 9.8epss 0.05

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Application Container - JavaEE). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access…

  • CVE-2015-5952CriJan 15, 2020
    risk 0.64cvss 9.8epss 0.03

    Directory traversal vulnerability in Thomson Reuters for FATCA before 5.2 allows remote attackers to execute arbitrary files via the item parameter.

  • CVE-2007-4773CriJan 15, 2020
    risk 0.64cvss 9.8epss 0.02

    Systrace before 1.6.0 has insufficient escape policy enforcement.

  • CVE-2005-4891CriJan 15, 2020
    risk 0.67cvss 9.8epss 0.02

    Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements.

  • CVE-2015-7874CriJan 15, 2020
    risk 0.68cvss 9.8epss 0.14

    Buffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary code via a long nickname.

  • CVE-2020-0654CriJan 14, 2020
    risk 0.59cvss 9.1epss 0.03

    A security feature bypass vulnerability exists in Microsoft OneDrive App for Android.This could allow an attacker to bypass the passcode or fingerprint requirements of the App.The security update addresses the vulnerability by correcting the way Microsoft OneDrive App for…

  • CVE-2020-0646CriKEVJan 14, 2020
    risk 0.87cvss 9.8epss 0.99

    A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

  • CVE-2020-0610CriJan 14, 2020
    risk 0.72cvss 9.8epss 0.68

    A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution…

  • CVE-2020-0609CriJan 14, 2020
    risk 0.73cvss 9.8epss 0.78

    A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution…

  • CVE-2011-2715CriJan 14, 2020
    risk 0.64cvss 9.8epss 0.01

    An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.

  • CVE-2011-3203CriJan 14, 2020
    risk 0.64cvss 9.8epss 0.02

    A Code Execution vulnerability exists the attachment parameter to index.php in Jcow CMS 4.x to 4.2 and 5.2 to 5.2.

  • CVE-2020-5505CriJan 14, 2020
    risk 0.67cvss 9.8epss 0.44

    Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-php"} to the /api/files/ URI.

  • CVE-2015-8367CriJan 14, 2020
    risk 0.64cvss 9.8epss 0.06

    The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arbitrary code, related to memory object initialization.

  • CVE-2015-8366CriJan 14, 2020
    risk 0.64cvss 9.8epss 0.05

    Array index error in smal_decode_segment function in LibRaw before 0.17.1 allows context-dependent attackers to cause memory errors and possibly execute arbitrary code via vectors related to indexes.

  • CVE-2019-0219CriJan 14, 2020
    risk 0.64cvss 9.8epss 0.08

    A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.

  • CVE-2020-6958CriJan 14, 2020
    risk 0.59cvss 9.1epss 0.02

    An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.

  • CVE-2012-4750CriJan 13, 2020
    risk 0.67cvss 9.8epss 0.09

    A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, which could let a remote malicious user execute arbitrary code or cause a Denial of Service

  • CVE-2020-6948CriJan 13, 2020
    risk 0.57cvss 9.8epss 0.03

    A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call that mishandles the URL, repository, username, and password.

  • CVE-2013-6225CriJan 13, 2020
    risk 0.69cvss 9.8epss 0.27

    LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability

  • CVE-2014-5381CriJan 13, 2020
    risk 0.67cvss 9.8epss 0.07

    Grand MA 300 allows a brute-force attack on the PIN.

  • CVE-2020-6840CriJan 11, 2020
    risk 0.64cvss 9.8epss 0.02

    In mruby 2.1.0, there is a use-after-free in hash_slice in mrbgems/mruby-hash-ext/src/hash-ext.c.

  • CVE-2020-6839CriJan 11, 2020
    risk 0.64cvss 9.8epss 0.01

    In mruby 2.1.0, there is a stack-based buffer overflow in mrb_str_len_to_dbl in string.c.

  • CVE-2020-6838CriJan 11, 2020
    risk 0.64cvss 9.8epss 0.01

    In mruby 2.1.0, there is a use-after-free in hash_values_at in mrbgems/mruby-hash-ext/src/hash-ext.c.

  • CVE-2020-6836CriJan 11, 2020
    risk 0.57cvss 9.8epss 0.02

    grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concatenates them in an eval call. If a value of the formula is taken from…

  • CVE-2020-6835CriJan 10, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking.

  • CVE-2012-4284CriJan 10, 2020
    risk 0.72cvss 9.8epss 0.70

    A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary code

  • CVE-2011-5020CriJan 10, 2020
    risk 0.64cvss 9.8epss 0.01

    An SQL Injection vulnerability exists in the ID parameter in Online TV Database 2011.

  • CVE-2020-6162CriJan 10, 2020
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in Bftpd 5.3. Under certain circumstances, an out-of-bounds read is triggered due to an uninitialized value. The daemon crashes at startup in the hidegroups_init function in dirlist.c.

  • CVE-2014-5093CriJan 10, 2020
    risk 0.67cvss 9.8epss 0.04

    Status2k does not remove the install directory allowing credential reset.

  • CVE-2013-7380CriJan 10, 2020
    risk 0.64cvss 9.8epss 0.02

    The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability

  • CVE-2014-5081CriJan 10, 2020
    risk 0.68cvss 9.8epss 0.10

    sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass

  • CVE-2014-4984CriJan 10, 2020
    risk 0.64cvss 9.8epss 0.03

    Déjà Vu Crescendo Sales CRM has remote SQL Injection

  • CVE-2014-4982CriJan 10, 2020
    risk 0.64cvss 9.8epss 0.05

    LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server.

  • CVE-2020-6756CriJan 9, 2020
    risk 0.68cvss 9.8epss 0.11

    languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter.

  • CVE-2019-20374CriJan 9, 2020
    risk 0.63cvss 9.6epss 0.02

    A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability is then triggered due to…

  • CVE-2012-3807CriJan 9, 2020
    risk 0.69cvss 9.8epss 0.32

    Samsung Kies before 2.5.0.12094_27_11 has arbitrary file execution.

  • CVE-2012-2226CriJan 9, 2020
    risk 0.67cvss 9.8epss 0.07

    Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.

  • CVE-2012-2714CriJan 9, 2020
    risk 0.64cvss 9.8epss 0.03

    The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier.

  • CVE-2012-1259CriJan 9, 2020
    risk 0.67cvss 9.8epss 0.04

    Multiple SQL injection vulnerabilities in Plixer International Scrutinizer NetFlow & sFlow Analyzer 8.6.2.16204, and possibly other versions before 9.0.1.19899, allow remote attackers to execute arbitrary SQL commands via the (1) addip parameter to…

  • CVE-2019-6330CriJan 9, 2020
    risk 0.64cvss 9.8epss 0.02

    A potential security vulnerability has been identified in the software solution HP Access Control versions prior to 16.7. This vulnerability could potentially grant elevation of privilege.

  • CVE-2019-4651CriJan 9, 2020
    risk 0.64cvss 9.8epss 0.01

    IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 170962.

  • CVE-2014-3449CriJan 9, 2020
    risk 0.64cvss 9.8epss 0.03

    BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability

  • CVE-2014-3448CriJan 9, 2020
    risk 0.64cvss 9.8epss 0.04

    BSS Continuity CMS 4.2.22640.0 has a Remote Code Execution vulnerability due to unauthenticated file upload

  • CVE-2014-2651CriJan 9, 2020
    risk 0.64cvss 9.8epss 0.02

    Unify OpenStage/OpenScape Desk Phone IP SIP before V3 R3.11.0 has an authentication bypass in the default mode of the Workpoint Interface

  • CVE-2014-2650CriJan 9, 2020
    risk 0.64cvss 9.8epss 0.03

    Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface

  • CVE-2011-5266CriJan 8, 2020
    risk 0.64cvss 9.8epss 0.01

    Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.