VYPR

CVEs

37,962 total · page 639 of 760

  • CVE-2019-9047CriFeb 23, 2019
    risk 0.64cvss 9.8epss 0.02

    GoRose v1.0.4 has SQL Injection when the order_by or group_by parameter can be controlled.

  • CVE-2019-9037CriFeb 23, 2019
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a buffer over-read in the function Mat_VarPrint() in mat.c.

  • CVE-2019-9035CriFeb 23, 2019
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in the function ReadNextStructField() in mat5.c.

  • CVE-2019-9034CriFeb 23, 2019
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read for a memcpy in the function ReadNextCell() in mat5.c.

  • CVE-2019-9033CriFeb 23, 2019
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read for the "Rank and Dimension" feature in the function ReadNextCell() in mat5.c.

  • CVE-2019-9030CriFeb 23, 2019
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in Mat_VarReadNextInfo5() in mat5.c.

  • CVE-2019-9028CriFeb 23, 2019
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in the function InflateDimensions() in inflate.c when called from ReadNextCell in mat5.c.

  • CVE-2019-9025CriFeb 22, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in PHP 7.3.x before 7.3.1. An invalid multibyte string supplied as an argument to the mb_split() function in ext/mbstring/php_mbregex.c can cause PHP to execute memcpy() with a negative argument, which could read and write past buffers allocated for the…

  • CVE-2019-9023CriFeb 22, 2019
    risk 0.64cvss 9.8epss 0.09

    An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A number of heap-based buffer over-read instances are present in mbstring regular expression functions when supplied with invalid multibyte data. These occur in…

  • CVE-2019-9021CriFeb 22, 2019
    risk 0.65cvss 9.8epss 0.10

    An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. A heap-based buffer over-read in PHAR reading functions in the PHAR extension may allow an attacker to read allocated or unallocated memory past the actual data when…

  • CVE-2019-9020CriFeb 22, 2019
    risk 0.65cvss 9.8epss 0.10

    An issue was discovered in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1. Invalid input to the function xmlrpc_decode() can lead to an invalid memory access (heap out of bounds read or read after free). This is related to xml_elem_parse_buf in…

  • CVE-2019-9015CriFeb 22, 2019
    risk 0.59cvss 9.1epss 0.02

    A Path Traversal vulnerability was discovered in MOPCMS through 2018-11-30, leading to deletion of unexpected critical files. The exploitation point is in the "column management" function. The path added to the column is not verified. When a column is deleted by an attacker, the…

  • CVE-2018-20784CriFeb 22, 2019
    risk 0.64cvss 9.8epss 0.04

    In the Linux kernel before 4.20.2, kernel/sched/fair.c mishandles leaf cfs_rq's, which allows attackers to cause a denial of service (infinite loop in update_blocked_averages) or possibly have unspecified other impact by inducing a high load.

  • CVE-2019-9002CriFeb 22, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Tiny Issue 1.3.1 and pixeline Bugs through 1.3.2c. install/config-setup.php allows remote attackers to execute arbitrary PHP code via the database_host parameter if the installer remains present in its original directory after installation is completed.

  • CVE-2019-8996CriFeb 21, 2019
    risk 0.64cvss 9.8epss 0.02

    In Signiant Manager+Agents before 13.5, the implementation of the set command has a Buffer Overflow.

  • CVE-2019-8985CriFeb 21, 2019
    risk 0.65cvss 9.8epss 0.13

    On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code execution. This vulnerability…

  • CVE-2019-8982CriFeb 21, 2019
    risk 0.68cvss 9.6epss 0.28

    com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.

  • CVE-2018-20122CriFeb 21, 2019
    risk 0.64cvss 9.8epss 0.05

    The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1.0.1b) exposed a CGI binary that is vulnerable to a command injection vulnerability that can be exploited to achieve remote code execution with root privileges.…

  • CVE-2019-8979CriFeb 21, 2019
    risk 0.64cvss 9.8epss 0.03

    Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled.

  • CVE-2019-8950CriFeb 20, 2019
    risk 0.64cvss 9.8epss 0.03

    The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to login to the admin account via TELNET.

  • CVE-2019-8948CriFeb 20, 2019
    risk 0.64cvss 9.8epss 0.04

    PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163.

  • CVE-2019-7164CriFeb 20, 2019
    risk 0.57cvss 9.8epss 0.04

    SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

  • CVE-2019-5759CriFeb 19, 2019
    risk 0.63cvss 9.6epss 0.01

    Incorrect lifetime handling in HTML select elements in Google Chrome on Android and Mac prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2019-7629CriFeb 18, 2019
    risk 0.64cvss 9.8epss 0.05

    Stack-based buffer overflow in the strip_vt102_codes function in TinTin++ 2.01.6 and WinTin++ 2.01.6 allows remote attackers to execute arbitrary code by sending a long message to the client.

  • CVE-2019-8917CriFeb 18, 2019
    risk 0.67cvss 9.8epss 0.36

    SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The…

  • CVE-2019-8908CriFeb 18, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in WTCMS 1.0. It allows remote attackers to execute arbitrary PHP code by going to the "Setting -> Mailbox configuration -> Registration email template" screen, and uploading an image file, as demonstrated by a .php filename and the "Content-Type:…

  • CVE-2019-0101CriFeb 18, 2019
    risk 0.64cvss 9.8epss 0.02

    Authentication bypass in the Intel Unite(R) solution versions 3.2 through 3.3 may allow an unauthenticated user to potentially enable escalation of privilege to the Intel Unite(R) Solution administrative portal via network access.

  • CVE-2019-8429CriFeb 18, 2019
    risk 0.57cvss 9.8epss 0.02

    ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.

  • CVE-2019-8428CriFeb 18, 2019
    risk 0.57cvss 9.8epss 0.02

    ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated by a newGroup[MonitorIds][] value.

  • CVE-2019-8427CriFeb 18, 2019
    risk 0.64cvss 9.8epss 0.02

    daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.

  • CVE-2019-8424CriFeb 18, 2019
    risk 0.57cvss 9.8epss 0.02

    ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.

  • CVE-2019-8423CriFeb 18, 2019
    risk 0.64cvss 9.8epss 0.02

    ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] parameter.

  • CVE-2019-8393CriFeb 17, 2019
    risk 0.64cvss 9.8epss 0.01

    Hotels_Server through 2018-11-05 has SQL Injection via the API because the controller/api/login.php telephone parameter is mishandled.

  • CVE-2019-8395CriFeb 17, 2019
    risk 0.64cvss 9.8epss 0.07

    An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.

  • CVE-2019-8360CriFeb 16, 2019
    risk 0.64cvss 9.8epss 0.02

    Themerig Find a Place CMS Directory 1.5 has SQL Injection via the find/assets/external/data_2.php cate parameter.

  • CVE-2015-4615CriFeb 15, 2019
    risk 0.64cvss 9.8epss 0.02

    Vulnerability in Easy2map-photos WordPress Plugin v1.09 allows SQL Injection via unsanitized mapTemplateName, mapName, mapSettingsXML, parentCSSXML, photoCSSXML, mapCSSXML, mapHTML,mapID variables

  • CVE-2013-5654CriFeb 15, 2019
    risk 0.59cvss 9.1epss 0.02

    Vulnerability in YingZhi Python Programming Language v1.9 allows arbitrary anonymous uploads to the phone's storage

  • CVE-2019-4059CriFeb 15, 2019
    risk 0.64cvss 9.8epss 0.02

    IBM Rational ClearCase 1.0.0.0 GIT connector does not sufficiently protect the document database password. An attacker could obtain the password and gain unauthorized access to the document database. IBM X-Force ID: 156583.

  • CVE-2019-0261CriFeb 15, 2019
    risk 0.64cvss 9.8epss 0.04

    Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and business users. Fixed in 1.0.97 to 1.0.99 (running on SAP HANA 1 or SAP HANA 2 SPS0 (second S stands for…

  • CVE-2019-0259CriFeb 15, 2019
    risk 0.64cvss 9.8epss 0.02

    SAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file format validation.

  • CVE-2019-8341CriFeb 15, 2019
    risk 0.70cvss 9.8epss 0.45

    An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION COMMANDS}} in a URI. NOTE:…

  • CVE-2019-5916CriFeb 13, 2019
    risk 0.64cvss 9.8epss 0.01

    Input validation issue in POWER EGG(Ver 2.0.1, Ver 2.02 Patch 3 and earlier, Ver 2.1 Patch 4 and earlier, Ver 2.2 Patch 7 and earlier, Ver 2.3 Patch 9 and earlier, Ver 2.4 Patch 13 and earlier, Ver 2.5 Patch 12 and earlier, Ver 2.6 Patch 8 and earlier, Ver 2.7 Patch 6 and…

  • CVE-2019-5909CriFeb 13, 2019
    risk 0.64cvss 9.8epss 0.05

    License Manager Service of YOKOGAWA products (CENTUM VP (R5.01.00 - R6.06.00), CENTUM VP Entry Class (R5.01.00 - R6.06.00), ProSafe-RS (R3.01.00 - R4.04.00), PRM (R4.01.00 - R4.02.00), B/M9000 VP(R7.01.01 - R8.02.03)) allows remote attackers to bypass access restriction to send…

  • CVE-2019-6543CriFeb 13, 2019
    risk 0.68cvss 9.8epss 0.17

    AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine.

  • CVE-2018-19645CriFeb 12, 2019
    risk 0.64cvss 9.8epss 0.01

    An Authentication Bypass issue exists in Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.

  • CVE-2019-7743CriFeb 12, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks because there is no protection mechanism (such as the TYPO3 PHAR stream wrapper) to prevent use of the phar:// handler for non .phar-files.

  • CVE-2019-6533CriFeb 12, 2019
    risk 0.59cvss 9.1epss 0.01

    Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166).

  • CVE-2019-6527CriFeb 12, 2019
    risk 0.64cvss 9.8epss 0.01

    PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the password for an admin user who is currently or previously logged in, provided the device has not been restarted.

  • CVE-2018-9583CriFeb 11, 2019
    risk 0.64cvss 9.8epss 0.02

    In bta_ag_parse_cmer of bta_ag_cmd.cc in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution in the bluetooth server with no additional…

  • CVE-2019-7747CriFeb 11, 2019
    risk 0.63cvss 9.6epss 0.01

    DbNinja 3.2.7 allows session fixation via the data.php sessid parameter.