VYPR

CVEs

37,974 total · page 611 of 760

  • CVE-2018-21003CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    The buddyforms plugin before 2.2.8 for WordPress has SQL injection.

  • CVE-2016-10935CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    The woocommerce-exporter plugin before 1.8.4 for WordPress has privilege escalation.

  • CVE-2015-9344CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    The link-log plugin before 2.1 for WordPress has SQL injection.

  • CVE-2019-15657CriAug 26, 2019
    risk 0.57cvss 9.8epss 0.02

    In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.

  • CVE-2019-15651CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.01

    wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte is mishandled for a crafted DER certificate in GetLength_ex.

  • CVE-2019-15497CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.03

    Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.

  • CVE-2019-9569CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.05

    Buffer Overflow in dactetra in Delta Controls enteliBUS Manager V3.40_B-571848 allows remote unauthenticated users to execute arbitrary code and possibly cause a denial of service via unspecified vectors.

  • CVE-2019-8001CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.06

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-7998CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.06

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-7997CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.06

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-7993CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.08

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-7992CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.05

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have an out of bound write vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-7990CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.08

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-7975CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.06

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-7974CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.06

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-7973CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.06

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-7972CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.06

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-7971CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.06

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-7970CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.06

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-7969CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.06

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-7968CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.07

    Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.

  • CVE-2019-15548CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are instr and mvwinstr buffer overflows because interaction with C functions is mishandled.

  • CVE-2019-15543CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the slice-deque crate before 0.2.0 for Rust. There is memory corruption in certain allocation cases.

  • CVE-2019-15533CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.01

    XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php.

  • CVE-2019-15503CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.02

    cgi-cpn/xcoding/prontus_videocut.cgi in AltaVoz Prontus (aka ProntusCMS) through 12.0.3.0 has "Improper Neutralization of Special Elements used in an OS Command," allowing attackers to execute OS commands via an HTTP GET parameter.

  • CVE-2019-13020CriAug 26, 2019
    risk 0.65cvss 10.0epss 0.01

    The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas for abuse. First, a specially crafted URL could be used in a phishing attack to hijack the trust the user and the browser have with the website and could serve…

  • CVE-2018-20998CriAug 26, 2019
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in the arrayfire crate before 3.6.0 for Rust. Addition of the repr() attribute to an enum is mishandled, leading to memory corruption.

  • CVE-2018-20997CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing.

  • CVE-2018-20996CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the crossbeam crate before 0.4.1 for Rust. There is a double free because of destructor mishandling.

  • CVE-2018-20995CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the slice-deque crate before 0.1.16 for Rust. move_head_unchecked allows memory corruption because deque updates are mishandled.

  • CVE-2019-15558CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.01

    XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java.

  • CVE-2019-15557CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.02

    XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key.

  • CVE-2019-15555CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.01

    FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnessTrack.php, and server.php.

  • CVE-2019-15560CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.01

    The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js.

  • CVE-2019-15559CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.01

    DianoxDragon Hawn before 2019-07-10 allows SQL injection.

  • CVE-2019-4169CriAug 26, 2019
    risk 0.59cvss 9.1epss 0.02

    IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702.

  • CVE-2019-15574CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.01

    Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php.

  • CVE-2019-15573CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.01

    Gesior-AAC before 2019-05-01 allows SQL injection in tankyou.php.

  • CVE-2019-15572CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.01

    Gesior-AAC before 2019-05-01 allows ServiceCategoryID SQL injection in shop.php.

  • CVE-2019-15571CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.01

    The WEB control panel before 2019-04-30 for ClonOS allows SQL injection in clonos.php.

  • CVE-2019-15570CriAug 26, 2019
    risk 0.57cvss 9.8epss 0.01

    BEdita through 4.0.0-RC2 allows SQL injection during a save operation for a relation with parameters.

  • CVE-2019-15569CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.01

    HM Courts & Tribunals ccd-data-store-api before 2019-06-10 allows SQL injection, related to SearchQueryFactoryOperation.java and SortDirection.java.

  • CVE-2019-15568CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.01

    idseq-web before 2019-07-01 in Infectious Disease Sequencing Platform IDseq allows SQL injection via tax_levels.

  • CVE-2019-15567CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.01

    OpenForis Arena before 2019-05-07 allows SQL injection in the sorting feature.

  • CVE-2019-15566CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.02

    The Alfresco application before 1.8.7 for Android allows SQL injection in HistorySearchProvider.java.

  • CVE-2019-15565CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.01

    The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php.

  • CVE-2019-15564CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.01

    The Compassion Switzerland addons 10.01.4 for Odoo allow SQL injection in models/partner_compassion.py.

  • CVE-2019-15563CriAug 26, 2019
    risk 0.57cvss 9.8epss 0.02

    Observational Health Data Sciences and Informatics (OHDSI) WebAPI before 2.7.2 allows SQL injection in FeatureExtractionService.java.

  • CVE-2019-15554CriAug 26, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the smallvec crate before 0.6.10 for Rust. There is memory corruption for certain grow attempts with less than the current capacity.

  • CVE-2019-15552CriAug 26, 2019
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in the libflate crate before 0.1.25 for Rust. MultiDecoder::read has a use-after-free, leading to arbitrary code execution.