VYPR

CVEs

37,941 total · page 665 of 759

  • CVE-2018-11314CriJul 3, 2018
    risk 0.63cvss 9.6epss 0.02

    The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result in remote device control and privileged device and network information to be exfiltrated by an attacker.

  • CVE-2018-7785CriJul 3, 2018
    risk 0.64cvss 9.8epss 0.03

    In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass.

  • CVE-2018-7784CriJul 3, 2018
    risk 0.64cvss 9.8epss 0.02

    In Schneider Electric U.motion Builder software versions prior to v1.3.4, this exploit occurs when the submitted data of an input string is evaluated as a command by the application. In this way, the attacker could execute code, read the stack, or cause a segmentation fault in…

  • CVE-2018-7780CriJul 3, 2018
    risk 0.64cvss 9.8epss 0.01

    In Schneider Electric Pelco Sarix Professional 1st generation cameras with firmware versions prior to 3.29.69, a buffer overflow vulnerability exist in cgi program "set".

  • CVE-2018-7778CriJul 3, 2018
    risk 0.64cvss 9.8epss 0.02

    In Schneider Electric Evlink Charging Station versions prior to v3.2.0-12_v1, the Web Interface has an issue that may allow a remote attacker to gain administrative privileges without properly authenticating remote users.

  • CVE-2018-4853CriJul 3, 2018
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to port 69/udp could modify the firmware of the device.

  • CVE-2018-4852CriJul 3, 2018
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been identified in SICLOCK TC100 (All versions) and SICLOCK TC400 (All versions). An attacker with network access to the device could potentially circumvent the authentication mechanism if he/she is able to obtain certain knowledge specific to the attacked…

  • CVE-2018-13101CriJul 3, 2018
    risk 0.64cvss 9.8epss 0.02

    KioskSimpleService.exe in RedSwimmer KioskSimple 1.4.7.0 suffers from a privilege escalation vulnerability in the WCF endpoint. The exposed methods allow read and write access to the Windows registry and control of services. These methods may be abused to achieve privilege…

  • CVE-2018-12892CriJul 2, 2018
    risk 0.65cvss 9.9epss 0.03

    An issue was discovered in Xen 4.7 through 4.10.x. libxl fails to pass the readonly flag to qemu when setting up a SCSI disk, due to what was probably an erroneous merge conflict resolution. Malicious guest administrators or (in some situations) users may be able to write to…

  • CVE-2018-12426CriJul 2, 2018
    risk 0.64cvss 9.8epss 0.05

    The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation of allowed file types, as demonstrated by a v1/remote_upload request with a .php filename and the image/jpeg content type.

  • CVE-2018-12575CriJul 2, 2018
    risk 0.64cvss 9.8epss 0.03

    On TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of authentication via an HTTP request.

  • CVE-2018-13050CriJul 2, 2018
    risk 0.67cvss 9.8epss 0.40

    A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_check POST request.

  • CVE-2018-13043CriJul 1, 2018
    risk 0.64cvss 9.8epss 0.02

    scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing.

  • CVE-2018-13038CriJul 1, 2018
    risk 0.64cvss 9.8epss 0.02

    OpenSID 18.06-pasca has an Unrestricted File Upload vulnerability via an Attachment Document in the article feature. This vulnerability leads to uploading arbitrary PHP code via a .php filename with the application/pdf Content-Type.

  • CVE-2018-13026CriJun 30, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Type.

  • CVE-2018-12465CriJun 29, 2018
    risk 0.69cvss 9.1epss 0.80

    An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server. This can be exploited in conjunction with…

  • CVE-2018-12464CriJun 29, 2018
    risk 0.74cvss 10.0epss 0.81

    A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbitrary SQL statements against the database. This can be exploited to create an administrative account…

  • CVE-2018-13011CriJun 29, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Validate.

  • CVE-2018-13009CriJun 29, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest_level (conditional on a buffer_size_longs check).

  • CVE-2018-13008CriJun 29, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for a positive nest_level.

  • CVE-2018-13007CriJun 29, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest_level (not conditional on a buffer_size_longs check).

  • CVE-2018-13006CriJun 29, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump.

  • CVE-2018-13005CriJun 29, 2018
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read.

  • CVE-2018-12993CriJun 29, 2018
    risk 0.64cvss 9.8epss 0.01

    onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefilecms_password fields.

  • CVE-2018-12984CriJun 29, 2018
    risk 0.64cvss 9.8epss 0.03

    Hycus CMS 1.0.4 allows Authentication Bypass via "'=' 'OR'" credentials.

  • CVE-2018-12972CriJun 29, 2018
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in OpenTSDB 2.3.0. Many parameters to the /q URI can execute commands, including o, key, style, and yrange and y2range and their JSON input.

  • CVE-2018-8016CriJun 28, 2018
    risk 0.57cvss 9.8epss 0.02

    The default configuration in Apache Cassandra 3.8 through 3.11.1 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request. This issue is a regression of CVE-2015-0225. The regression was…

  • CVE-2018-12933CriJun 28, 2018
    risk 0.64cvss 9.8epss 0.02

    PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact because the attacker controls the pCreatePen->ihPen array index.

  • CVE-2018-12932CriJun 28, 2018
    risk 0.64cvss 9.8epss 0.02

    PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by triggering a large pAlphaBlend->cbBitsSrc value.

  • CVE-2018-11510CriJun 28, 2018
    risk 0.70cvss 9.8epss 0.44

    The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by embedding OS commands in the 'script' parameter.

  • CVE-2018-12925CriJun 28, 2018
    risk 0.64cvss 9.8epss 0.01

    Baseon Lantronix MSS devices do not require a password for TELNET access.

  • CVE-2018-12924CriJun 28, 2018
    risk 0.64cvss 9.8epss 0.01

    Sollae Serial-Ethernet-Module and Remote-I/O-Device-Server devices have a default password of sollae for the TELNET service.

  • CVE-2017-16726CriJun 27, 2018
    risk 0.59cvss 9.1epss 0.01

    Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and therefore does not include any encryption algorithms because of their negative effect on…

  • CVE-2018-1457CriJun 27, 2018
    risk 0.64cvss 9.8epss 0.02

    An undisclosed vulnerability in IBM Rational DOORS 9.5.1 through 9.6.1.10 application allows an attacker to gain DOORS administrator privileges. IBM X-Force ID: 140208.

  • CVE-2018-12918CriJun 27, 2018
    risk 0.64cvss 9.8epss 0.01

    In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcB_register_fields in bootstrap.c.

  • CVE-2018-12917CriJun 27, 2018
    risk 0.64cvss 9.8epss 0.01

    In libpbc.a in PBC through 2017-03-02, there is a heap-based buffer over-read in _pbcM_ip_new in map.c.

  • CVE-2018-12916CriJun 27, 2018
    risk 0.64cvss 9.8epss 0.01

    In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcP_message_default in proto.c.

  • CVE-2018-12915CriJun 27, 2018
    risk 0.64cvss 9.8epss 0.01

    In libpbc.a in PBC through 2017-03-02, there is a buffer over-read in calc_hash in map.c.

  • CVE-2018-12914CriJun 27, 2018
    risk 0.64cvss 9.8epss 0.04

    A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a directory traversal pathname. After an unzip operation, the attacker can execute arbitrary code by visiting a .jsp URI.

  • CVE-2018-5435CriJun 27, 2018
    risk 0.63cvss 9.6epss 0.03

    The TIBCO Spotfire Client and TIBCO Spotfire Web Player Client components of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs…

  • CVE-2018-12908CriJun 27, 2018
    risk 0.68cvss 9.8epss 0.11

    Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for the /dashboard/deposit URI, as demonstrated by discovering database credentials.

  • CVE-2017-7465CriJun 27, 2018
    risk 0.59cvss 9.0epss 0.03

    It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw to cause remote code execution if they are able to provide XSLT content for parsing. Doing a transform in JAXP requires the use of…

  • CVE-2017-18342CriJun 27, 2018
    risk 0.57cvss 9.8epss 0.06

    In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function.

  • CVE-2018-10594CriJun 26, 2018
    risk 0.72cvss 9.8epss 0.69

    Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS2 and AHSIM_5x0, AHSIM_5x1) utilize a fixed-length stack buffer where an unverified length value can be read from the network…

  • CVE-2018-4846CriJun 26, 2018
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in RAPIDLab 1200 systems / RAPIDPoint 400 systems / RAPIDPoint 500 systems (All versions_without_ use of Siemens Healthineers Informatics products), RAPIDLab 1200 Series (All versions < V3.3 _with_ Siemens Healthineers Informatics products),…

  • CVE-2018-10662CriJun 26, 2018
    risk 0.73cvss 9.8epss 0.80

    An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.

  • CVE-2018-10661CriJun 26, 2018
    risk 0.74cvss 9.8epss 0.86

    An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.

  • CVE-2018-10660CriJun 26, 2018
    risk 0.73cvss 9.8epss 0.82

    An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.

  • CVE-2018-6667CriJun 26, 2018
    risk 0.65cvss 10.0epss 0.04

    Authentication Bypass vulnerability in the administrative user interface in McAfee Web Gateway 7.8.1.0 through 7.8.1.5 allows remote attackers to execute arbitrary code via Java management extensions (JMX).

  • CVE-2017-7658CriJun 26, 2018
    risk 0.58cvss 9.8epss 0.19

    In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the…