VYPR

CVEs

37,968 total · page 615 of 760

  • CVE-2016-10886CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    The wp-editor plugin before 1.2.6 for WordPress has incorrect permissions.

  • CVE-2015-9310CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    The all-in-one-wp-security-and-firewall plugin before 3.9.1 for WordPress has multiple SQL injection issues.

  • CVE-2019-15025CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    The ninja-forms plugin before 3.3.21.2 for WordPress has SQL injection in the search filter on the submissions page.

  • CVE-2017-18514CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.

  • CVE-2016-10889CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    The nextgen-gallery plugin before 2.1.57 for WordPress has SQL injection via a gallery name.

  • CVE-2015-9316CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.03

    The wp-fastest-cache plugin before 0.8.4.9 for WordPress has SQL injection in wp-admin/admin-ajax.php?action=wpfc_wppolls_ajax_request via the poll_id parameter.

  • CVE-2015-9315CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    The newstatpress plugin before 1.0.1 for WordPress has SQL injection.

  • CVE-2015-9313CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.

  • CVE-2019-0345CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.02

    A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick the application server into leaking authentication…

  • CVE-2019-0344CriKEVAug 14, 2019
    risk 0.76cvss 9.8epss 0.07

    Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.

  • CVE-2017-18515CriAug 14, 2019
    risk 0.57cvss 9.8epss 0.03

    The wp-statistics plugin before 12.0.8 for WordPress has SQL injection.

  • CVE-2019-15027CriAug 14, 2019
    risk 0.64cvss 9.8epss 0.03

    The MediaTek Embedded Multimedia Card (eMMC) subsystem for Android on MT65xx, MT66xx, and MT8163 SoC devices allows attackers to execute arbitrary commands as root via shell metacharacters in a filename under /data, because clear_emmc_nomedia_entry in…

  • CVE-2019-14809CriAug 13, 2019
    risk 0.64cvss 9.8epss 0.08

    net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications. This is related to a Host field with a suffix appearing in neither Hostname() nor Port(), and is related to a non-numeric port…

  • CVE-2019-12479CriAug 13, 2019
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in 20|20 Storage 2.11.0. A Path Traversal vulnerability in the TwentyTwenty.Storage library in the LocalStorageProvider allows creating and reading files outside of the specified basepath. If the application using this library does not sanitize…

  • CVE-2019-14985CriAug 13, 2019
    risk 0.64cvss 9.8epss 0.08

    eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with access to the web interface, because this interface can access the CMD_EXEC virtual device type 28.

  • CVE-2015-9301CriAug 13, 2019
    risk 0.64cvss 9.8epss 0.02

    The liveforms plugin before 3.2.0 for WordPress has SQL injection.

  • CVE-2015-9298CriAug 13, 2019
    risk 0.64cvss 9.8epss 0.02

    The events-manager plugin before 5.6 for WordPress has code injection.

  • CVE-2019-14968CriAug 12, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in imcat 4.9. There is SQL Injection via the index.php order parameter in a mod=faqs action.

  • CVE-2019-14965CriAug 12, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.

  • CVE-2019-13462CriAug 12, 2019
    risk 0.60cvss 9.1epss 0.11

    Lansweeper before 7.1.117.4 allows unauthenticated SQL injection.

  • CVE-2019-12618CriAug 12, 2019
    risk 0.64cvss 9.8epss 0.02

    HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.

  • CVE-2019-12261CriAug 9, 2019
    risk 0.64cvss 9.8epss 0.09

    Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.

  • CVE-2019-12260CriAug 9, 2019
    risk 0.66cvss 9.8epss 0.23

    Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option.

  • CVE-2019-12255CriAug 9, 2019
    risk 0.73cvss 9.8epss 0.75

    Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.

  • CVE-2019-11581CriKEVAug 9, 2019
    risk 0.82cvss 9.8epss 0.85

    There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Jira Server or Data Center. All versions…

  • CVE-2019-5402CriAug 9, 2019
    risk 0.61cvss 9.4epss 0.04

    A remote authorization bypass vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

  • CVE-2019-5399CriAug 9, 2019
    risk 0.61cvss 9.4epss 0.02

    A remote gain authorized access vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

  • CVE-2019-5397CriAug 9, 2019
    risk 0.61cvss 9.4epss 0.04

    A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

  • CVE-2019-12256CriAug 9, 2019
    risk 0.66cvss 9.8epss 0.27

    Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options.

  • CVE-2019-5396CriAug 9, 2019
    risk 0.62cvss 9.4epss 0.05

    A remote authentication bypass vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

  • CVE-2019-14801CriAug 9, 2019
    risk 0.64cvss 9.8epss 0.02

    The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows email subscription SQL injection.

  • CVE-2019-14234CriAug 9, 2019
    risk 0.61cvss 9.8epss 0.48

    An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and key lookups for django.contrib.postgres.fields.HStoreField,…

  • CVE-2018-20955CriAug 8, 2019
    risk 0.64cvss 9.8epss 0.02

    Swann SWWHD-INTCAM-HD devices have the twipc root password, leading to FTP access as root. NOTE: all affected customers were migrated by 2020-08-31.

  • CVE-2019-12994CriAug 8, 2019
    risk 0.60cvss 9.1epss 0.04

    Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.

  • CVE-2019-11208CriAug 8, 2019
    risk 0.64cvss 9.9epss 0.01

    The authorization component of TIBCO Software Inc.'s TIBCO API Exchange Gateway, and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically processes OAuth authorization incorrectly, leading to potential escalation of…

  • CVE-2019-14754CriAug 8, 2019
    risk 0.64cvss 9.8epss 0.02

    Open-School 3.0, and Community Edition 2.3, allows SQL Injection via the index.php?r=students/students/document id parameter.

  • CVE-2019-14255CriAug 8, 2019
    risk 0.64cvss 9.8epss 0.02

    A Server Side Request Forgery (SSRF) vulnerability in go-camo up to version 1.1.4 allows a remote attacker to perform HTTP requests to internal endpoints.

  • CVE-2019-13101CriAug 8, 2019
    risk 0.72cvss 9.8epss 0.67

    An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information about the WAN, and can also be leveraged by an attacker to modify the data fields of the page.

  • CVE-2019-1971CriAug 8, 2019
    risk 0.64cvss 9.8epss 0.04

    A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vulnerability is due to insufficient input…

  • CVE-2019-14771CriAug 8, 2019
    risk 0.64cvss 9.8epss 0.03

    Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, potentially allowing non-configuration scripts to be…

  • CVE-2019-1895CriAug 7, 2019
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to access the VNC console session of an administrative user on an affected device. The…

  • CVE-2019-5476CriAug 7, 2019
    risk 0.64cvss 9.8epss 0.02

    An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticated users to be able to execute arbitrary SQL commands.

  • CVE-2019-14537CriAug 7, 2019
    risk 0.64cvss 9.8epss 0.06

    YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.

  • CVE-2019-14746CriAug 7, 2019
    risk 0.64cvss 9.8epss 0.01

    A issue was discovered in KuaiFanCMS 5.0. It allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.

  • CVE-2018-20961CriAug 7, 2019
    risk 0.64cvss 9.8epss 0.06

    In the Linux kernel before 4.16.4, a double free vulnerability in the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi driver may allow attackers to cause a denial of service or possibly have unspecified other impact.

  • CVE-2019-1913CriAug 7, 2019
    risk 0.69cvss 9.8epss 0.26

    Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to overflow a buffer, which then allows the execution of arbitrary code with root privileges on the underlying operating…

  • CVE-2019-1912CriAug 7, 2019
    risk 0.64cvss 9.1epss 0.17

    A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthenticated, remote attacker to upload arbitrary files. The vulnerability is due to incomplete authorization checks in the web management interface. An attacker…

  • CVE-2019-14709CriAug 6, 2019
    risk 0.64cvss 9.8epss 0.02

    A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera is compromised, the attacker can gain access to passwords and abuse them to compromise further…

  • CVE-2019-14708CriAug 6, 2019
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. A buffer overflow in the action parameter leads to remote code execution in the context of the nobody account.

  • CVE-2019-14704CriAug 6, 2019
    risk 0.64cvss 9.8epss 0.02

    An SSRF issue was discovered in HTTPD on MicroDigital N-series cameras with firmware through 6400.0.8.5 via FTP commands following a newline character in the uploadfile field.