VYPR

CVEs

38,008 total · page 592 of 761

  • CVE-2019-9812CriJan 8, 2020
    risk 0.61cvss 9.3epss 0.02

    Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a malicious Firefox Sync account. Preference settings that disable the sandbox are then…

  • CVE-2020-5510CriJan 8, 2020
    risk 0.64cvss 9.8epss 0.02

    PHPGurukul Hostel Management System v2.0 allows SQL injection via the id parameter in the full-profile.php file.

  • CVE-2019-19495CriJan 8, 2020
    risk 0.64cvss 9.8epss 0.04

    The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to configure the cable modem via JavaScript in a victim's browser. The attacker can then configure the cable modem to port forward the modem's internal TELNET…

  • CVE-2019-5082CriJan 8, 2020
    risk 0.64cvss 9.8epss 0.03

    An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can…

  • CVE-2019-20367CriJan 8, 2020
    risk 0.52cvss 9.1epss 0.03

    nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).

  • CVE-2019-10777CriJan 8, 2020
    risk 0.64cvss 9.8epss 0.02

    In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any sanitization. It is possible for a user to inject arbitrary commands to the "zipCmd" used within "config.FunctionName".

  • CVE-2019-19518CriJan 8, 2020
    risk 0.64cvss 9.8epss 0.03

    CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server port, that potentially allows remote attackers to execute arbitrary commands.

  • CVE-2019-17076CriJan 8, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in several APIs may cause Denial of Service (DoS), remote code execution (RCE), and/or deletion of files on the Jamf Pro server.

  • CVE-2019-10778CriJan 8, 2020
    risk 0.57cvss 9.8epss 0.03

    devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable `commonName` controlled by user input is used as part of the `exec` function without any sanitization.

  • CVE-2014-2072CriJan 8, 2020
    risk 0.67cvss 9.8epss 0.07

    Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks

  • CVE-2014-1860CriJan 8, 2020
    risk 0.57cvss 9.8epss 0.04

    Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities

  • CVE-2014-1409CriJan 8, 2020
    risk 0.59cvss 9.1epss 0.04

    MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with obfuscated passwords

  • CVE-2014-1598CriJan 8, 2020
    risk 0.64cvss 9.8epss 0.01

    centurystar 7.12 ActiveX Control has a Stack Buffer Overflow

  • CVE-2020-6170CriJan 8, 2020
    risk 0.67cvss 9.8epss 0.07

    An authentication bypass vulnerability on Genexis Platinum-4410 v2.1 P4410-V2 1.28 devices allows attackers to obtain cleartext credentials from the HTML source code of the cgi-bin/index2.asp URI.

  • CVE-2019-20361CriJan 8, 2020
    risk 0.74cvss 9.8epss 0.85

    There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).

  • CVE-2019-17146CriJan 7, 2020
    risk 0.64cvss 9.8epss 0.10

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HNAP service, which listens on TCP port 80 by default.…

  • CVE-2020-5841CriJan 7, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OpServices OpMon 9.3.1-1. Using password change parameters, an attacker could perform SQL injection without authentication.

  • CVE-2019-14906CriJan 7, 2020
    risk 0.64cvss 9.8epss 0.02

    A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow flaw while copying an existing surface…

  • CVE-2020-5307CriJan 7, 2020
    risk 0.65cvss 9.8epss 0.16

    PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and…

  • CVE-2019-10776CriJan 7, 2020
    risk 0.57cvss 9.8epss 0.02

    In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2.

  • CVE-2014-8673CriJan 7, 2020
    risk 0.68cvss 9.8epss 0.12

    Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPlanning)before 1.33.

  • CVE-2019-14837CriJan 7, 2020
    risk 0.52cvss 9.1epss 0.02

    A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client name 'test' the email address will be…

  • CVE-2013-5122CriJan 7, 2020
    risk 0.64cvss 9.8epss 0.04

    Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access

  • CVE-2015-5951CriJan 6, 2020
    risk 0.65cvss 9.9epss 0.03

    A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to upload arbitrary PHP files to the web root and execute system commands.

  • CVE-2019-16273CriJan 6, 2020
    risk 0.64cvss 9.8epss 0.02

    DTEN D5 and D7 before 1.3.4 devices allow unauthenticated root shell access through Android Debug Bridge (adb), leading to arbitrary code execution and system administration. Also, this provides a covert ability to capture screen data from the Zoom Client on Windows by executing…

  • CVE-2019-16272CriJan 6, 2020
    risk 0.64cvss 9.8epss 0.01

    On DTEN D5 and D7 before 1.3.4 devices, factory settings allows for firmware reflash and Android Debug Bridge (adb) enablement.

  • CVE-2020-5514CriJan 6, 2020
    risk 0.63cvss 9.1epss 0.44

    Gila CMS 1.11.8 allows Unrestricted Upload of a File with a Dangerous Type via .phar or .phtml to the lzld/thumb?src= URI.

  • CVE-2019-18792CriJan 6, 2020
    risk 0.52cvss 9.1epss 0.03

    An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake FIN packet. The fake FIN packet is injected just before the PUSH ACK packet we want to bypass. The PUSH ACK packet (containing the data)…

  • CVE-2016-11017CriJan 6, 2020
    risk 0.64cvss 9.8epss 0.04

    The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a failed login attempt returns the command-injection output to a limited login…

  • CVE-2019-20343CriJan 6, 2020
    risk 0.64cvss 9.8epss 0.02

    The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can also specify arbitrary command-line arguments in an…

  • CVE-2020-5519CriJan 6, 2020
    risk 0.57cvss 9.8epss 0.01

    The WebAdmin Console in OpenLiteSpeed before v1.6.5 does not strictly check request URLs, as demonstrated by the "Server Configuration > External App" screen.

  • CVE-2019-15976CriJan 6, 2020
    risk 0.74cvss 9.8epss 0.93

    Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information…

  • CVE-2019-15975CriJan 6, 2020
    risk 0.74cvss 9.8epss 0.96

    Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. For more information…

  • CVE-2019-19628CriJan 5, 2020
    risk 0.64cvss 9.8epss 0.04

    In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.

  • CVE-2020-5499CriJan 4, 2020
    risk 0.64cvss 9.8epss 0.03

    Baidu Rust SGX SDK through 1.0.8 has an enclave ID race. There are non-deterministic results in which, sometimes, two global IDs are the same.

  • CVE-2014-8516CriJan 3, 2020
    risk 0.73cvss 9.8epss 0.82

    Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.

  • CVE-2014-8337CriJan 3, 2020
    risk 0.64cvss 9.8epss 0.05

    Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the…

  • CVE-2012-5878CriJan 3, 2020
    risk 0.67cvss 9.8epss 0.09

    Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to…

  • CVE-2019-11994CriJan 3, 2020
    risk 0.64cvss 9.8epss 0.07

    A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell…

  • CVE-2019-19088CriJan 3, 2020
    risk 0.64cvss 9.8epss 0.02

    Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.

  • CVE-2019-20330CriJan 3, 2020
    risk 0.57cvss 9.8epss 0.09

    FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

  • CVE-2020-5312CriJan 3, 2020
    risk 0.57cvss 9.8epss 0.04

    libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.

  • CVE-2020-5311CriJan 3, 2020
    risk 0.57cvss 9.8epss 0.04

    libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.

  • CVE-2016-1000027CriJan 2, 2020
    risk 0.59cvss 9.8epss 0.33

    Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required.…

  • CVE-2014-0011CriJan 2, 2020
    risk 0.57cvss 9.8epss 0.02

    Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, when NDEBUG is enabled, allow remote VNC servers to cause a denial of service (vncviewer crash) and possibly execute arbitrary code via vectors related to screen…

  • CVE-2013-3941CriJan 2, 2020
    risk 0.64cvss 9.8epss 0.03

    Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a QCD marker in a crafted JPEG2000 file, which leads to a heap-based buffer…

  • CVE-2014-0048CriJan 2, 2020
    risk 0.64cvss 9.8epss 0.07

    An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.

  • CVE-2019-14859CriJan 2, 2020
    risk 0.52cvss 9.1epss 0.02

    A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could…

  • CVE-2019-10158CriJan 2, 2020
    risk 0.57cvss 9.8epss 0.02

    A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling.

  • CVE-2013-7070CriDec 31, 2019
    risk 0.57cvss 9.8epss 0.04

    The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the URI.