VYPR

CVEs

37,899 total · page 670 of 758

  • CVE-2018-11736CriJun 5, 2018
    risk 0.60cvss 9.8epss 0.09

    An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.

  • CVE-2017-16042CriJun 4, 2018
    risk 0.57cvss 9.8epss 0.04

    Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.

  • CVE-2017-16020CriJun 4, 2018
    risk 0.64cvss 9.8epss 0.03

    Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.

  • CVE-2018-11714CriJun 4, 2018
    risk 0.69cvss 9.8epss 0.68

    An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker…

  • CVE-2018-10611CriJun 4, 2018
    risk 0.64cvss 9.8epss 0.05

    Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unauthenticated users to launch applications and support remote code execution through web services.

  • CVE-2018-11711CriJun 4, 2018
    risk 0.64cvss 9.8epss 0.05

    A remote attacker can bypass the System Manager Mode on the Canon MF210 and MF220 web interface without knowing the PIN for /login.html via vectors involving /portal_top.html to get full access to the device. NOTE: the vendor reportedly responded that this issue occurs when a…

  • CVE-2018-11692CriJun 4, 2018
    risk 0.64cvss 9.8epss 0.04

    An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for /tlogin.cgi via vectors involving frame.cgi?page=DevStatus. NOTE: the vendor reportedly responded that this issue occurs when a…

  • CVE-2018-11682CriJun 2, 2018
    risk 0.64cvss 9.8epss 0.04

    Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products using the Stanza Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a…

  • CVE-2018-11681CriJun 2, 2018
    risk 0.64cvss 9.8epss 0.04

    Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the RadioRA 2 Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id…

  • CVE-2018-11629CriJun 2, 2018
    risk 0.64cvss 9.8epss 0.04

    Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the HomeWorks QS Lutron integration protocol Revision M to Revision Y. NOTE: The vendor…

  • CVE-2018-11143CriJun 2, 2018
    risk 0.67cvss 9.8epss 0.37

    Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46).

  • CVE-2018-3757CriJun 1, 2018
    risk 0.57cvss 9.8epss 0.05

    Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.

  • CVE-2018-3746CriJun 1, 2018
    risk 0.57cvss 9.8epss 0.05

    The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim's machine.

  • CVE-2018-11652CriJun 1, 2018
    risk 0.69cvss 9.8epss 0.24

    CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.

  • CVE-2016-10554CriMay 31, 2018
    risk 0.57cvss 9.8epss 0.02

    sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. Before version 1.7.0-alpha3, sequelize defaulted SQLite to use MySQL backslash escaping, even though SQLite…

  • CVE-2016-10553CriMay 31, 2018
    risk 0.64cvss 9.8epss 0.01

    sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. A fix was pushed out that fixed potential SQL injection in sequelize 2.1.3 and earlier.

  • CVE-2016-10550CriMay 31, 2018
    risk 0.64cvss 9.8epss 0.02

    sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS If user input goes into the `limit` or `order` parameters, a malicious user can put in their own SQL statements.…

  • CVE-2016-10546CriMay 31, 2018
    risk 0.64cvss 9.8epss 0.03

    An arbitrary code injection vector was found in PouchDB 6.0.4 and lesser via the map/reduce functions used in PouchDB temporary views and design documents. The code execution engine for this branch is not properly sandboxed and may be used to run arbitrary JavaScript as well as…

  • CVE-2016-10541CriMay 31, 2018
    risk 0.64cvss 9.8epss 0.02

    The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform code injection.

  • CVE-2016-10532CriMay 31, 2018
    risk 0.64cvss 9.8epss 0.02

    console-io is a module that allows users to implement a web console in their application. A malicious user could bypass the authentication and execute any command that the user who is running the console-io application 2.2.13 and earlier is able to run. This means that if…

  • CVE-2018-11141CriMay 31, 2018
    risk 0.64cvss 9.8epss 0.02

    The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to write and delete files respectively via Directory Traversal. Files can be at any location where the…

  • CVE-2018-11140CriMay 31, 2018
    risk 0.64cvss 9.8epss 0.01

    The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, an error-based type).

  • CVE-2018-11138CriKEVMay 31, 2018
    risk 0.92cvss 9.8epss 0.92

    The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.

  • CVE-2018-11136CriMay 31, 2018
    risk 0.64cvss 9.8epss 0.01

    The 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, a blind time-based type).

  • CVE-2018-9318CriMay 31, 2018
    risk 0.64cvss 9.8epss 0.04

    The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a remote attack via a cellular network.

  • CVE-2018-9311CriMay 31, 2018
    risk 0.64cvss 9.8epss 0.04

    The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a remote attack via a cellular network.

  • CVE-2018-11036CriMay 31, 2018
    risk 0.59cvss 9.1epss 0.01

    Ruckus SmartZone (formerly Virtual SmartCell Gateway or vSCG) 3.5.0, 3.5.1, 3.6.0, and 3.6.1 (Essentials and High Scale) on vSZ, SZ-100, SZ-300, and SCG-200 devices allows remote attackers to obtain sensitive information or modify data.

  • CVE-2018-11576CriMay 31, 2018
    risk 0.64cvss 9.8epss 0.01

    ngiflib.c in MiniUPnP ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor.

  • CVE-2018-11575CriMay 31, 2018
    risk 0.64cvss 9.8epss 0.02

    ngiflib.c in MiniUPnP ngiflib 0.4 has a stack-based buffer overflow in DecodeGifImg.

  • CVE-2018-11482CriMay 30, 2018
    risk 0.64cvss 9.8epss 0.01

    /usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a hardcoded zMiVw8Kw0oxKXL0 password.

  • CVE-2018-11547CriMay 29, 2018
    risk 0.64cvss 9.8epss 0.02

    md_is_link_reference_definition_helper in md4c 0.2.5 has a heap-based buffer over-read because md_is_link_label mishandles loop termination.

  • CVE-2018-11546CriMay 29, 2018
    risk 0.64cvss 9.8epss 0.02

    md4c 0.2.5 has a heap-based buffer over-read because md_is_named_entity_contents has an off-by-one error.

  • CVE-2018-11545CriMay 29, 2018
    risk 0.64cvss 9.8epss 0.02

    md4c 0.2.5 has a heap-based buffer overflow in md_merge_lines because md_is_link_label mishandles the case of a link label composed solely of backslash escapes.

  • CVE-2018-11544CriMay 29, 2018
    risk 0.64cvss 9.8epss 0.01

    The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.ftpserver_preferences.xml file as the prefUsername and prefUserpass strings.

  • CVE-2018-3745CriMay 29, 2018
    risk 0.59cvss 9.1epss 0.02

    atob 2.0.3 and earlier allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.

  • CVE-2018-3744CriMay 29, 2018
    risk 0.64cvss 9.8epss 0.02

    The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.

  • CVE-2018-10466CriMay 29, 2018
    risk 0.65cvss 9.8epss 0.17

    Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.

  • CVE-2016-10551CriMay 29, 2018
    risk 0.57cvss 9.8epss 0.02

    waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith` will end up in waterline-sequel with the potential for malicious code. A malicious user can input their…

  • CVE-2016-10525CriMay 29, 2018
    risk 0.57cvss 9.8epss 0.02

    When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authentication.

  • CVE-2015-9244CriMay 29, 2018
    risk 0.64cvss 9.8epss 0.02

    Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.

  • CVE-2015-9235CriMay 29, 2018
    risk 0.57cvss 9.8epss 0.09

    In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family).

  • CVE-2018-1235CriMay 29, 2018
    risk 0.70cvss 9.8epss 0.42

    Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to execute arbitrary commands on the affected system with…

  • CVE-2018-5241CriMay 29, 2018
    risk 0.64cvss 9.8epss 0.05

    Symantec Advanced Secure Gateway (ASG) 6.6 and 6.7, and ProxySG 6.5, 6.6, and 6.7 are susceptible to a SAML authentication bypass vulnerability. The products can be configured with a SAML authentication realm to authenticate network users in intercepted proxy traffic. When…

  • CVE-2018-11536CriMay 29, 2018
    risk 0.64cvss 9.8epss 0.02

    md4c before 0.2.5 has a heap-based buffer overflow because md_split_simple_pairing_mark mishandles splits.

  • CVE-2018-11535CriMay 29, 2018
    risk 0.67cvss 9.8epss 0.03

    An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.php is exploitable using SQL injection.

  • CVE-2018-11531CriMay 29, 2018
    risk 0.64cvss 9.8epss 0.03

    Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.

  • CVE-2018-11528CriMay 29, 2018
    risk 0.64cvss 9.8epss 0.02

    WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI.

  • CVE-2018-11523CriMay 29, 2018
    risk 0.67cvss 9.8epss 0.09

    upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.

  • CVE-2018-11309CriMay 28, 2018
    risk 0.64cvss 9.8epss 0.02

    Blind SQL injection in coupon_code in the MemberMouse plugin 2.2.8 and prior for WordPress allows an unauthenticated attacker to dump the WordPress MySQL database via an applyCoupon action in an admin-ajax.php request.

  • CVE-2018-11515CriMay 28, 2018
    risk 0.64cvss 9.8epss 0.02

    The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.