VYPR

CVEs

37,964 total · page 630 of 760

  • CVE-2017-12795CriMay 10, 2019
    risk 0.64cvss 9.8epss 0.02

    OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).

  • CVE-2015-1006CriMay 10, 2019
    risk 0.64cvss 9.8epss 0.05

    A vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions prior to R9.4006, PAC Display Basic versions prior to R9.4f, PAC Display Professional versions prior to R9.4f, OptoOPCServer versions prior to R9.4c, and OptoDataLink…

  • CVE-2019-1867CriMay 10, 2019
    risk 0.67cvss 10.0epss 0.30

    A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to bypass authentication on the REST API. The vulnerability is due to improper validation of API requests. An attacker could exploit this vulnerability by…

  • CVE-2017-12759CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.04

    Ynet Interactive - http://demo.ynetinteractive.com/soa/ SOA School Management 3.0 is affected by: SQL Injection. The impact is: Code execution (remote).

  • CVE-2017-12758CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.03

    https://www.joomlaextensions.co.in/ Joomla! Component Appointment 1.1 is affected by: SQL Injection. The impact is: Code execution (remote). The component is: com_appointment component.

  • CVE-2017-12757CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.04

    Certain Ambit Technologies Pvt. Ltd products are affected by: SQL Injection. This affects iTech B2B Script 4.42i and Tech Business Networking Script 8.26i and Tech Caregiver Script 2.71i and Tech Classifieds Script 7.41i and Tech Dating Script 3.40i and Tech Freelancer Script…

  • CVE-2019-6548CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.01

    GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database. This service is inaccessible to attackers if Windows default firewall settings are used by the end user.

  • CVE-2019-11839CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.02

    njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.push after a resize, related to njs_array_prototype_push in njs/njs_array.c, because of njs_array_expand size mishandling.

  • CVE-2019-11838CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.02

    njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.splice after a resize, related to njs_array_prototype_splice in njs/njs_array.c, because of njs_array_expand size mishandling.

  • CVE-2019-11353CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.03

    The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in ping and traceroute utilities by using different payloads and injecting multiple parameters. This vulnerability is fixed in a later firmware version.

  • CVE-2019-11835CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.03

    cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.

  • CVE-2019-11834CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.03

    cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.

  • CVE-2019-11831CriMay 9, 2019
    risk 0.57cvss 9.8epss 0.05

    The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.

  • CVE-2019-11830CriMay 9, 2019
    risk 0.64cvss 9.8epss 0.03

    PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.

  • CVE-2019-7442CriMay 8, 2019
    risk 0.70cvss 9.8epss 0.40

    An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass authentication via a crafted DTD in the SAML authentication system.

  • CVE-2019-5021CriMay 8, 2019
    risk 0.64cvss 9.8epss 0.06

    Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulnerability appears to be the result of a regression introduced in December of 2015. Due to the nature of this issue, systems deployed using affected versions of…

  • CVE-2019-2047CriMay 8, 2019
    risk 0.64cvss 9.8epss 0.01

    In UpdateLoadElement of ic.cc, there is a possible out-of-bounds write due to type confusion. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android…

  • CVE-2019-2046CriMay 8, 2019
    risk 0.64cvss 9.8epss 0.01

    In CalculateInstanceSizeForDerivedClass of objects.cc, there is possible memory corruption due to an integer overflow. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2019-2045CriMay 8, 2019
    risk 0.64cvss 9.8epss 0.01

    In JSCallTyper of typer.cc, there is an out of bounds write due to an incorrect bounds check. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android…

  • CVE-2019-11510CriKEVMay 8, 2019
    risk 0.94cvss 10.0epss 1.00

    In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

  • CVE-2019-9505CriMay 8, 2019
    risk 0.64cvss 9.8epss 0.03

    The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not sanitize special characters allowing for remote unauthorized changes to configuration files. An unauthenticated attacker may be able to remotely execute arbitrary code with SYSTEM…

  • CVE-2018-5409CriMay 8, 2019
    risk 0.64cvss 9.8epss 0.01

    The PrinterLogic Print Management software, versions up to and including 18.3.1.96, updates and executes the code without sufficiently verifying the origin and integrity of the code. An attacker can execute malicious code by compromising the host server, performing DNS spoofing,…

  • CVE-2019-8387CriMay 8, 2019
    risk 0.71cvss 9.8epss 0.56

    MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.

  • CVE-2019-10712CriMay 7, 2019
    risk 0.64cvss 9.8epss 0.03

    The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x (750-830, 750-849, 750-871, 750-872, 750-873) devices has undocumented service access.

  • CVE-2018-6634CriMay 7, 2019
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized users to maintain access to an account.

  • CVE-2019-7745CriMay 7, 2019
    risk 0.64cvss 9.8epss 0.04

    JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain the Wi-Fi password by making a cgi-bin/qcmap_web_cgi Page=GetWiFi_Setting request and then reading the wpa_security_key field.

  • CVE-2019-7564CriMay 7, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the Wireless SSID doesn't require any type of authentication. By making a POST request to the regx/wireless/wl_security_2G.asp URI, the attacker can change the…

  • CVE-2018-14485CriMay 7, 2019
    risk 0.68cvss 9.8epss 0.16

    BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.

  • CVE-2019-11560CriMay 7, 2019
    risk 0.64cvss 9.8epss 0.02

    A buffer overflow vulnerability in the streaming server provided by hisilicon in HI3516 models allows an unauthenticated attacker to remotely run arbitrary code by sending a special RTSP over HTTP packet. The vulnerability was found in many cameras using hisilicon's hardware and…

  • CVE-2019-5434CriMay 6, 2019
    risk 0.71cvss 9.8epss 0.57

    An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method. Such vulnerability could be used to perform various types of attacks, e.g. exploit serialize-related…

  • CVE-2019-11766CriMay 5, 2019
    risk 0.64cvss 9.8epss 0.02

    dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.

  • CVE-2019-11036CriMay 3, 2019
    risk 0.60cvss 9.1epss 0.07

    When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.

  • CVE-2019-1804CriMay 3, 2019
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to connect to the affected system with the privileges of the root user. The vulnerability is…

  • CVE-2018-16988CriMay 2, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in the plausible situation where the attacker knows that the…

  • CVE-2018-16717CriMay 2, 2019
    risk 0.64cvss 9.8epss 0.02

    A heap-based buffer overflow exists in nph-viewgif.cgi in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox.

  • CVE-2018-16716CriMay 2, 2019
    risk 0.60cvss 9.1epss 0.09

    A path traversal vulnerability exists in viewcgi.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox, which may result in reading of arbitrary files (i.e., significant information disclosure) or file deletion via the nph-viewgif.cgi query string.

  • CVE-2019-11683CriMay 2, 2019
    risk 0.64cvss 9.8epss 0.08

    udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause a denial of service (slab-out-of-bounds memory corruption) or possibly have unspecified other impact via UDP packets with a 0 payload, because of mishandling…

  • CVE-2017-18371CriMay 2, 2019
    risk 0.69cvss 9.8epss 0.23

    The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passwords, including two hardcoded service accounts: one with the username true and password true, and another with the username supervisor and password zyad1234.…

  • CVE-2017-18369CriMay 2, 2019
    risk 0.72cvss 9.8epss 0.68

    The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the adv_remotelog.asp page and can be exploited through…

  • CVE-2017-18368CriKEVMay 2, 2019
    risk 0.86cvss 9.8epss 0.94

    The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page…

  • CVE-2019-11682CriMay 2, 2019
    risk 0.64cvss 9.8epss 0.03

    A buffer overflow in the SMTP response service in MailCarrier 2.51 allows the attacker to execute arbitrary code remotely via a long HELP command, a related issue to CVE-2019-11395.

  • CVE-2019-11678CriMay 2, 2019
    risk 0.64cvss 9.8epss 0.09

    The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection.

  • CVE-2019-11677CriMay 2, 2019
    risk 0.64cvss 9.8epss 0.09

    The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection.

  • CVE-2019-10952CriMay 1, 2019
    risk 0.64cvss 9.8epss 0.10

    An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based buffer overflow vulnerability. A cold restart is required for recovering CompactLogix 5370 L1, L2, and L3 Controllers, Compact…

  • CVE-2019-11627CriApr 30, 2019
    risk 0.64cvss 9.8epss 0.03

    gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a User ID.

  • CVE-2019-3939CriApr 30, 2019
    risk 0.64cvss 9.8epss 0.03

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the web interface. An unauthenticated, remote attacker can use these credentials to gain privileged access to the device.

  • CVE-2019-3935CriApr 30, 2019
    risk 0.59cvss 9.1epss 0.03

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide show via crafted HTTP POST requests to conference.cgi. A remote, unauthenticated attacker can use this vulnerability to start, stop, and disconnect active…

  • CVE-2019-3932CriApr 30, 2019
    risk 0.67cvss 9.8epss 0.36

    Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a hard-coded password in return.tgi. A remote, unauthenticated attacker can use this vulnerability to control external devices via the uart_bridge.

  • CVE-2019-3930CriApr 30, 2019
    risk 0.64cvss 9.8epss 0.07

    The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware…

  • CVE-2019-3929CriKEVApr 30, 2019
    risk 0.87cvss 9.8epss 0.99

    The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmware 1.1.0.7, SHARP PN-L703WA firmware…