VYPR

CVEs

37,995 total · page 605 of 760

  • CVE-2019-17552CriOct 14, 2019
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.

  • CVE-2019-17408CriOct 14, 2019
    risk 0.64cvss 9.8epss 0.04

    parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations such as strtr.

  • CVE-2019-17545CriOct 14, 2019
    risk 0.57cvss 9.8epss 0.03

    GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.

  • CVE-2019-17544CriOct 14, 2019
    risk 0.52cvss 9.1epss 0.03

    libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.

  • CVE-2019-17542CriOct 14, 2019
    risk 0.57cvss 9.8epss 0.02

    FFmpeg before 4.2 has a heap-based buffer overflow in vqa_decode_chunk because of an out-of-array access in vqa_decode_init in libavcodec/vqavideo.c.

  • CVE-2019-17539CriOct 14, 2019
    risk 0.57cvss 9.8epss 0.02

    In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereference and possibly unspecified other impact when there is no valid close function pointer.

  • CVE-2019-17531CriOct 12, 2019
    risk 0.57cvss 9.8epss 0.05

    A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the…

  • CVE-2019-17510CriOct 11, 2019
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetWizardConfig with shell metacharacters to /squashfs-root/www/HNAP1/control/SetWizardConfig.php.

  • CVE-2019-17509CriOct 11, 2019
    risk 0.64cvss 9.8epss 0.03

    D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetMasterWLanSettings with shell metacharacters to /squashfs-root/www/HNAP1/control/SetMasterWLanSettings.php.

  • CVE-2019-17508CriOct 11, 2019
    risk 0.68cvss 9.8epss 0.16

    On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SERVER variable.

  • CVE-2019-17506CriOct 11, 2019
    risk 0.68cvss 9.8epss 0.56

    There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 routers. An attacker can get the router's username and password (and other information) via a DEVICE.ACCOUNT value for SERVICES in conjunction with…

  • CVE-2018-21027CriOct 11, 2019
    risk 0.64cvss 9.8epss 0.02

    Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled.

  • CVE-2019-17059CriOct 11, 2019
    risk 0.64cvss 9.8epss 0.07

    A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbitrary commands via the Web Admin and SSL VPN consoles.

  • CVE-2019-17495CriOct 10, 2019
    risk 0.57cvss 9.8epss 0.06

    A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product…

  • CVE-2019-9533CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.02

    The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This could allow an attacker to reverse-engineer the password from available versions to gain authenticated access to the device.

  • CVE-2019-9531CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.03

    The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454. This could allow an unauthenticated, remote attacker to connect to this port via Telnet and execute 86 Attention (AT) commands, including some that provide…

  • CVE-2019-11526CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write files with superuser privileges in specific locations.

  • CVE-2019-17455CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.03

    Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.

  • CVE-2015-9479CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.03

    The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.

  • CVE-2015-9471CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.04

    The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.

  • CVE-2015-9467CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.02

    The broken-link-manager plugin before 0.5.0 for WordPress has wpslDelURL or wpslEditURL SQL injection via the url parameter.

  • CVE-2015-9466CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.02

    The wti-like-post plugin before 1.4.3 for WordPress has WtiLikePostProcessVote SQL injection via the HTTP_CLIENT_IP, HTTP_X_FORWARDED_FOR, HTTP_X_FORWARDED, HTTP_FORWARDED_FOR, or HTTP_FORWARDED variable.

  • CVE-2019-17320CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.02

    NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary checks when copying file name from an attacker controlled FTP server. That leads attacker to execute arbitrary code by sending a crafted filename.

  • CVE-2019-1372CriOct 10, 2019
    risk 0.66cvss 10.0epss 0.19

    An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to…

  • CVE-2019-1365CriOct 10, 2019
    risk 0.65cvss 9.9epss 0.04

    An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability can allow an unprivileged function ran by the user to execute code in the…

  • CVE-2019-17429CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.01

    Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter.

  • CVE-2019-17072CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.02

    The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Injection via all-query-page.php.

  • CVE-2019-17426CriOct 10, 2019
    risk 0.52cvss 9.1epss 0.02

    Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's…

  • CVE-2019-17415CriOct 9, 2019
    risk 0.64cvss 9.8epss 0.04

    A Structured Exception Handler (SEH) based buffer overflow in File Sharing Wizard 1.5.0 26-8-2008 allows remote unauthenticated attackers to execute arbitrary code via the HTTP DELETE method, a similar issue to CVE-2019-16724 and CVE-2010-2331.

  • CVE-2019-1584CriOct 9, 2019
    risk 0.64cvss 9.8epss 0.03

    A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if the Inspector were sent a malicious command from the Zingbox cloud, or if the Zingbox Inspector were tampered with to connect to an attacker's cloud endpoint.

  • CVE-2019-15020CriOct 9, 2019
    risk 0.64cvss 9.8epss 0.01

    A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector that could result in command injection.

  • CVE-2019-15019CriOct 9, 2019
    risk 0.64cvss 9.8epss 0.01

    A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that could allow an attacker to supply an invalid software update image to the Zingbox Inspector.

  • CVE-2019-9535CriOct 9, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execute arbitrary commands by providing malicious output to the terminal. This affects versions of iTerm2 up to and including 3.3.5. This vulnerability may allow an…

  • CVE-2019-17399CriOct 9, 2019
    risk 0.64cvss 9.8epss 0.02

    The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment.

  • CVE-2019-17383CriOct 9, 2019
    risk 0.57cvss 9.8epss 0.02

    The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.

  • CVE-2019-17124CriOct 9, 2019
    risk 0.69cvss 9.8epss 0.23

    Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.

  • CVE-2019-15859CriOct 9, 2019
    risk 0.66cvss 9.8epss 0.31

    Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI.

  • CVE-2019-17382CriOct 9, 2019
    risk 0.63cvss 9.1epss 0.54

    An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). All…

  • CVE-2019-17373CriOct 9, 2019
    risk 0.64cvss 9.8epss 0.02

    Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, such as by appending ?x=1.jpg to a URL. This affects MBR1515, MBR1516, DGN2200, DGN2200M, DGND3700, WNR2000v2, WNDR3300, WNDR3400, WNR3500, and WNR834Bv2.

  • CVE-2019-17354CriOct 9, 2019
    risk 0.61cvss 9.4epss 0.01

    wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify data fields of the page.

  • CVE-2019-17362CriOct 9, 2019
    risk 0.52cvss 9.1epss 0.03

    In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) or read information from…

  • CVE-2019-3980CriOct 8, 2019
    risk 0.64cvss 9.8epss 0.05

    The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an…

  • CVE-2019-10757CriOct 8, 2019
    risk 0.64cvss 9.8epss 0.01

    knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.

  • CVE-2019-17134CriOct 8, 2019
    risk 0.52cvss 9.1epss 0.02

    Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration commands via simple HTTP requests to the…

  • CVE-2018-21024CriOct 8, 2019
    risk 0.64cvss 9.8epss 0.02

    licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.

  • CVE-2019-13336CriOct 8, 2019
    risk 0.64cvss 9.8epss 0.03

    The dbell Wi-Fi Smart Video Doorbell DB01-S Gen 1 allows remote attackers to launch commands with no authentication verification via TCP port 81, because the loginuse and loginpass parameters to openlock.cgi can have arbitrary values. NOTE: the vendor's position is that this…

  • CVE-2018-21025CriOct 8, 2019
    risk 0.64cvss 9.8epss 0.03

    In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced configuration files.

  • CVE-2019-17042CriOct 7, 2019
    risk 0.57cvss 9.8epss 0.03

    An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon), but fails to account for strings that do not satisfy…

  • CVE-2019-17041CriOct 7, 2019
    risk 0.57cvss 9.8epss 0.04

    An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon) but fails to account for strings that do…

  • CVE-2019-12812CriOct 7, 2019
    risk 0.64cvss 9.8epss 0.03

    MyBuilder viewer before 6.2.2019.814 allow an attacker to execute arbitrary command via specifically crafted configuration file. This can be leveraged for code execution.