VYPR

CVEs

37,997 total · page 599 of 760

  • CVE-2013-2091CriNov 20, 2019
    risk 0.57cvss 9.8epss 0.03

    SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.

  • CVE-2019-18858CriNov 20, 2019
    risk 0.64cvss 9.8epss 0.02

    CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.

  • CVE-2019-5541CriNov 20, 2019
    risk 0.59cvss 9.1epss 0.01

    VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in the e1000e virtual network adapter. Successful exploitation of this issue may lead to code execution on the host from the guest or may allow attackers to…

  • CVE-2019-10765CriNov 20, 2019
    risk 0.57cvss 9.8epss 0.02

    iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory.

  • CVE-2010-4660CriNov 20, 2019
    risk 0.64cvss 9.8epss 0.01

    Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..

  • CVE-2016-9652CriNov 20, 2019
    risk 0.64cvss 9.8epss 0.02

    Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75.

  • CVE-2016-5194CriNov 20, 2019
    risk 0.64cvss 9.8epss 0.01

    Unspecified vulnerabilities in Google Chrome before 54.0.2840.59.

  • CVE-2011-1028CriNov 20, 2019
    risk 0.57cvss 9.8epss 0.02

    The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.

  • CVE-2011-3350CriNov 19, 2019
    risk 0.64cvss 9.8epss 0.02

    masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.

  • CVE-2019-10766CriNov 19, 2019
    risk 0.57cvss 9.8epss 0.01

    Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sanitization.

  • CVE-2011-2921CriNov 19, 2019
    risk 0.73cvss 9.8epss 0.83

    ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.

  • CVE-2012-0824CriNov 19, 2019
    risk 0.64cvss 9.8epss 0.02

    gnusound 0.7.5 has format string issue

  • CVE-2016-1000006CriNov 19, 2019
    risk 0.57cvss 9.8epss 0.02

    hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.

  • CVE-2019-12409CriNov 18, 2019
    risk 0.65cvss 9.8epss 0.21

    The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the affected releases, then JMX monitoring…

  • CVE-2019-12271CriNov 18, 2019
    risk 0.64cvss 9.8epss 0.02

    Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of adding ".jpg" to any uploaded filename is not enforced on the server side.

  • CVE-2018-20687CriNov 18, 2019
    risk 0.64cvss 9.8epss 0.03

    An XML external entity (XXE) vulnerability in CommandCenterWebServices/.*?wsdl in Raritan CommandCenter Secure Gateway before 8.0.0 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML…

  • CVE-2011-5331CriNov 18, 2019
    risk 0.64cvss 9.8epss 0.03

    Distributed Ruby (aka DRuby) 1.8 mishandles instance_eval.

  • CVE-2011-5330CriNov 18, 2019
    risk 0.64cvss 9.8epss 0.02

    Distributed Ruby (aka DRuby) 1.8 mishandles the sending of syscalls.

  • CVE-2019-19113CriNov 18, 2019
    risk 0.64cvss 9.8epss 0.02

    main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.

  • CVE-2019-17058CriNov 18, 2019
    risk 0.59cvss 9.1epss 0.02

    Footy Tipping Software AFL Web Edition 2019 allows arbitrary file upload and resultant remote code execution because a whitelist can be bypassed by an Administrator who uploads a crafted upload.dat file.

  • CVE-2019-19012CriNov 17, 2019
    risk 0.65cvss 9.8epss 0.11

    An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a…

  • CVE-2019-19010CriNov 16, 2019
    risk 0.57cvss 9.8epss 0.02

    Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.

  • CVE-2019-13582CriNov 15, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A stack overflow could lead to denial of service or arbitrary code execution.

  • CVE-2019-13581CriNov 15, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive FC6050W module. A heap-based buffer overflow allows remote attackers to cause a denial of service…

  • CVE-2011-0703CriNov 15, 2019
    risk 0.64cvss 9.8epss 0.01

    In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to overtake an administrator X11 session.

  • CVE-2013-7088CriNov 15, 2019
    risk 0.57cvss 9.8epss 0.03

    ClamAV before 0.97.7 has buffer overflow in the libclamav component

  • CVE-2013-7087CriNov 15, 2019
    risk 0.57cvss 9.8epss 0.03

    ClamAV before 0.97.7 has WWPack corrupt heap memory

  • CVE-2019-14345CriNov 15, 2019
    risk 0.64cvss 9.8epss 0.02

    TemaTres 3.0 allows remote unprivileged users to create an administrator account

  • CVE-2019-18985CriNov 15, 2019
    risk 0.57cvss 9.8epss 0.01

    Pimcore before 6.2.2 lacks brute force protection for the 2FA token.

  • CVE-2019-18981CriNov 15, 2019
    risk 0.57cvss 9.8epss 0.01

    Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.

  • CVE-2019-18928CriNov 15, 2019
    risk 0.57cvss 9.8epss 0.02

    Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.

  • CVE-2019-15803CriNov 14, 2019
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of keypresses, undocumented functionality is triggered. A diagnostics shell is triggered via CTRL-ALT-t, which prompts for the password returned by…

  • CVE-2019-15800CriNov 14, 2019
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in the cmd_sys_traceroute_exec(), cmd_sys_arp_clear(), and cmd_sys_ping_exec() functions in the libclicmd.so library contained in the firmware, an attacker could…

  • CVE-2019-14678CriNov 14, 2019
    risk 0.65cvss 10.0epss 0.03

    SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This…

  • CVE-2013-4108CriNov 14, 2019
    risk 0.64cvss 9.8epss 0.02

    Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors.

  • CVE-2019-18939CriNov 14, 2019
    risk 0.67cvss 9.8epss 0.41

    eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi and exec1.cgi scripts, which execute TCL script content from an HTTP POST…

  • CVE-2019-18938CriNov 14, 2019
    risk 0.66cvss 9.8epss 0.34

    eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the save.cgi script for payload upload and the testtcl.cgi script for its execution.

  • CVE-2019-18937CriNov 14, 2019
    risk 0.66cvss 9.8epss 0.34

    eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the exec.cgi script, which executes TCL script content from an HTTP POST request.

  • CVE-2013-3072CriNov 14, 2019
    risk 0.64cvss 9.8epss 0.02

    An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a password to access the web administration…

  • CVE-2013-3073CriNov 14, 2019
    risk 0.64cvss 9.8epss 0.04

    A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.

  • CVE-2019-11171CriNov 14, 2019
    risk 0.64cvss 9.8epss 0.02

    Heap corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via network access.

  • CVE-2019-11168CriNov 14, 2019
    risk 0.59cvss 9.1epss 0.01

    Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access.

  • CVE-2019-8248CriNov 14, 2019
    risk 0.64cvss 9.8epss 0.04

    Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .

  • CVE-2019-8247CriNov 14, 2019
    risk 0.64cvss 9.8epss 0.04

    Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution .

  • CVE-2019-8246CriNov 14, 2019
    risk 0.64cvss 9.8epss 0.05

    Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .

  • CVE-2011-1930CriNov 14, 2019
    risk 0.68cvss 9.8epss 0.21

    In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP…

  • CVE-2019-3663CriNov 14, 2019
    risk 0.64cvss 9.8epss 0.01

    Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensitive files on the system. This was originally published with a CVSS rating of High, further…

  • CVE-2019-5029CriNov 13, 2019
    risk 0.71cvss 9.8epss 0.57

    An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor process when it launches…

  • CVE-2019-18952CriNov 13, 2019
    risk 0.67cvss 9.8epss 0.45

    SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.

  • CVE-2019-18240CriNov 13, 2019
    risk 0.65cvss 9.8epss 0.14

    In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an attacker to remotely execute arbitrary code.