TROYANOSYVIRUS

Vulnerabilidades CVE

Base de datos de vulnerabilidades CVE enriquecida con datos de CISA KEV y NVD

Total: 333,770 CVEs
CVE IDCVSSSeveridadKEVAvistamientos
CVE-2019-20790

OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM fie...

9.8CRITICALβ€”0
CVE-2019-4729

IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in f...

4.3MEDIUMβ€”0
CVE-2020-11420

UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that reference files and by doi...

6.5MEDIUMβ€”0
CVE-2020-12272

OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing...

5.3MEDIUMβ€”0
CVE-2020-9489

A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Pa...

5.5MEDIUMβ€”0
CVE-2020-11810

An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arriv...

3.7LOWβ€”0
CVE-2018-21093

Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D8500 before 1.0.3.42, EX3700 before 1.0.0.70, EX3800 before 1.0.0.70, EX6000 before ...

8.8HIGHβ€”0
CVE-2018-21094

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC120 before 2.1.7, WAC505 before 5.0.5.4, WAC510 before 5.0.5.4, WNAP320 before 3.7.11.4, WNAP210v2...

7.3HIGHβ€”0
CVE-2019-18823

HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrat...

9.8CRITICALβ€”0
CVE-2019-20002

Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a Tick...

7.8HIGHβ€”0
CVE-2020-11415

An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP server system username/password (as configured in nxrm) in clea...

4.9MEDIUMβ€”0
CVE-2020-11817

In Rukovoditel V2.5.2, attackers can upload an arbitrary file to the server just changing the the content-type value. As a result of that, an attacker can execute a command on the server. This specifi...

9.8CRITICALβ€”0
CVE-2020-12120

The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's owner password that can be used to modify orders via SOAP. Attacke...

7.5HIGHβ€”0
CVE-2020-12133

The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization.

9.8CRITICALβ€”0
CVE-2020-12138

AMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of several driver routines that map physical memory into the virtual address space of...

8.8HIGHβ€”0
CVE-2017-18388

cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).

N/ANONEβ€”0
CVE-2017-18389

cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).

N/ANONEβ€”0
CVE-2017-18426

cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).

N/ANONEβ€”0
CVE-2017-18390

cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incremental backups (SEC-322).

N/ANONEβ€”0
CVE-2017-18391

cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval (SEC-323).

N/ANONEβ€”0
CVE-2019-10166

It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify ma...

7.8HIGHβ€”0
CVE-2019-10167

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since...

7.8HIGHβ€”0
CVE-2019-10168

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emul...

7.8HIGHβ€”0
CVE-2017-18392

cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325).

N/ANONEβ€”0
CVE-2017-18393

cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326).

N/ANONEβ€”0
CVE-2017-18394

cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327).

N/ANONEβ€”0
CVE-2017-18395

cPanel before 68.0.15 does not block a username of ssl (SEC-328).

N/ANONEβ€”0
CVE-2017-18396

cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329).

N/ANONEβ€”0
CVE-2017-18397

cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330).

N/ANONEβ€”0
CVE-2017-18502

The subscriber plugin before 1.3.5 for WordPress has multiple XSS issues.

N/ANONEβ€”0
CVE-2017-18398

DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331).

N/ANONEβ€”0
CVE-2017-18399

cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabling sqloptimizer (SEC-332).

N/ANONEβ€”0
CVE-2017-18400

cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333).

N/ANONEβ€”0
CVE-2017-18401

cPanel before 68.0.15 allows user accounts to be partially created with invalid username formats (SEC-334).

N/ANONEβ€”0
CVE-2017-18402

cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336).

N/ANONEβ€”0
CVE-2017-18503

The twitter-cards-meta plugin before 2.5.0 for WordPress has XSS.

N/ANONEβ€”0
CVE-2017-18403

cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337).

N/ANONEβ€”0
CVE-2017-18404

cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341).

N/ANONEβ€”0
CVE-2017-18405

cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345).

N/ANONEβ€”0
CVE-2017-18406

cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).

N/ANONEβ€”0
CVE-2017-18407

cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279).

N/ANONEβ€”0
CVE-2017-18504

The twitter-cards-meta plugin before 2.5.0 for WordPress has CSRF.

N/ANONEβ€”0
CVE-2017-18408

cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).

N/ANONEβ€”0
CVE-2017-18409

In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283).

N/ANONEβ€”0
CVE-2017-18410

In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284).

N/ANONEβ€”0
CVE-2017-18411

The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285).

N/ANONEβ€”0
CVE-2017-18412

cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).

N/ANONEβ€”0
CVE-2017-18413

In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).

N/ANONEβ€”0
CVE-2017-18414

cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).

N/ANONEβ€”0
CVE-2017-18415

cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).

N/ANONEβ€”0
Pagina 128 de 6676

This product uses data from the NVD API but is not endorsed or certified by the NVD.