VYPR

CVEs

37,996 total · page 603 of 760

  • CVE-2019-13553CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.02

    Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems is configured using hard-coded credentials. These credentials could allow attackers to influence the primary operations of the…

  • CVE-2019-16265CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.02

    CODESYS V2.3 ENI server up to V3.2.2.24 has a Buffer Overflow.

  • CVE-2019-14451CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.04

    RepetierServer.exe in Repetier-Server 0.8 through 0.91 does not properly validate the XML data structure provided when uploading a new printer configuration. When this is combined with CVE-2019-14450, an attacker can upload an "external command" configuration as a printer…

  • CVE-2013-4658CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.09

    Linksys EA6500 has SMB Symlink Traversal allowing symbolic links to be created to locations outside of the Samba share.

  • CVE-2019-8088CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.06

    Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2013-4857CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-865L has PHP File Inclusion in the router xml file.

  • CVE-2016-5202CriOct 25, 2019
    risk 0.59cvss 9.1epss 0.01

    browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase…

  • CVE-2016-2360CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.02

    Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' installations.

  • CVE-2016-2359CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.03

    Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultaneously making a request for the unprotected vb.htm resource.

  • CVE-2016-2358CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.02

    Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials. They are accessible if the customer has not configured 10 actual user accounts.

  • CVE-2016-2357CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.02

    Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory.

  • CVE-2016-2356CriOct 25, 2019
    risk 0.64cvss 9.8epss 0.03

    Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password.

  • CVE-2015-0270CriOct 25, 2019
    risk 0.57cvss 9.8epss 0.01

    Zend Framework before 2.2.10 and 2.3.x before 2.3.5 has Potential SQL injection in PostgreSQL Zend\Db adapter.

  • CVE-2019-18418CriOct 24, 2019
    risk 0.67cvss 9.8epss 0.04

    clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no session management.

  • CVE-2019-15929CriOct 24, 2019
    risk 0.64cvss 9.8epss 0.02

    In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.

  • CVE-2019-18200CriOct 24, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption of 2.4 GHz communication, they are prone to keystroke injection attacks.

  • CVE-2019-13653CriOct 24, 2019
    risk 0.64cvss 9.8epss 0.02

    TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow triggerPort OS Command Injection (issue 5 of 5).

  • CVE-2019-13652CriOct 24, 2019
    risk 0.64cvss 9.8epss 0.03

    TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow serviceName OS Command Injection (issue 4 of 5).

  • CVE-2019-13651CriOct 24, 2019
    risk 0.64cvss 9.8epss 0.03

    TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow portMappingProtocol OS Command Injection (issue 3 of 5).

  • CVE-2019-13650CriOct 24, 2019
    risk 0.64cvss 9.8epss 0.03

    TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow internalPort OS Command Injection (issue 2 of 5).

  • CVE-2019-13649CriOct 24, 2019
    risk 0.64cvss 9.8epss 0.03

    TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow externalPort OS Command Injection (issue 1 of 5).

  • CVE-2019-12017CriOct 24, 2019
    risk 0.64cvss 9.8epss 0.03

    A remote code execution vulnerability exists in MapR CLDB code, specifically in the JSON framework that is used in the CLDB code that handles login and ticket issuance. An attacker can use the 'class' property of the JSON request sent to the CLDB to influence the JSON library's…

  • CVE-2019-18394CriOct 24, 2019
    risk 0.59cvss 9.8epss 0.32

    A Server Side Request Forgery (SSRF) vulnerability in FaviconServlet.java in Ignite Realtime Openfire through 4.4.2 allows attackers to send arbitrary HTTP GET requests.

  • CVE-2019-18387CriOct 23, 2019
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Hotel and Lodge Management System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the id parameter to the edit page for Customer, Room, Currency, Room Booking Details, or Tax Details.

  • CVE-2019-8237CriOct 23, 2019
    risk 0.64cvss 9.8epss 0.03

    Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an insufficiently robust encryption vulnerability. Successful…

  • CVE-2019-8236CriOct 23, 2019
    risk 0.64cvss 9.8epss 0.03

    Creative Cloud Desktop Application version 4.6.1 and earlier versions have Security Bypass vulnerability. Successful exploitation could lead to Privilege Escalation in the context of the current user.

  • CVE-2019-18370CriOct 23, 2019
    risk 0.67cvss 9.8epss 0.40

    An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed directory. In addition, the…

  • CVE-2019-18355CriOct 23, 2019
    risk 0.64cvss 9.8epss 0.02

    An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7.

  • CVE-2019-11933CriOct 23, 2019
    risk 0.64cvss 9.8epss 0.04

    A heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19.291 could allow remote attackers to execute arbitrary code or cause a denial of service.

  • CVE-2019-18344CriOct 23, 2019
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers to execute arbitrary SQL commands via the student, instructor, department, room, class, or user page (id or classid parameter).

  • CVE-2015-9499CriOct 22, 2019
    risk 0.65cvss 9.8epss 0.16

    The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.

  • CVE-2019-12148CriOct 22, 2019
    risk 0.64cvss 9.8epss 0.04

    The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection vulnerability involving special characters in the username field. Upon successful exploitation, a remote unauthenticated user can login…

  • CVE-2019-12147CriOct 22, 2019
    risk 0.64cvss 9.8epss 0.03

    The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the username field. Upon successful exploitation, a remote unauthenticated user can create a local system user with sudo privileges, and use that…

  • CVE-2019-18225CriOct 21, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before build 62.10, 12.1 before build 54.16, and 13.0 before build 41.28. An attacker with management-interface access can bypass…

  • CVE-2019-18224CriOct 21, 2019
    risk 0.57cvss 9.8epss 0.04

    idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.

  • CVE-2019-17526CriOct 18, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary commands on the underlying operating system, as demonstrated by an…

  • CVE-2019-17393CriOct 18, 2019
    risk 0.64cvss 9.8epss 0.02

    The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized actors. Basic authentication is used for the authentication, making it possible to base64 decode the sniffed credentials and…

  • CVE-2019-15900CriOct 18, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used without checking for error cases. Instead, the uninitialized variable errstr was checked and in some cases returned success even if…

  • CVE-2019-8221CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.04

    Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution…

  • CVE-2019-8220CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.04

    Adobe Acrobat and Reader versions, 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .

  • CVE-2019-8215CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.04

    Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution…

  • CVE-2019-8214CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.04

    Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution…

  • CVE-2019-8213CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.04

    Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution…

  • CVE-2019-8212CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.04

    Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution…

  • CVE-2019-8211CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.04

    Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution…

  • CVE-2019-8206CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.04

    Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code…

  • CVE-2019-8205CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.04

    Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary…

  • CVE-2019-8200CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.04

    Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .

  • CVE-2019-8199CriOct 17, 2019
    risk 0.64cvss 9.8epss 0.04

    Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code…

  • CVE-2019-8197CriOct 17, 2019
    risk 0.68cvss 9.8epss 0.17

    Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, 2015.006.30503 and earlier, and 2015.006.30503 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .