VYPR

CVEs

1,665 total · page 14 of 34

  • CVE-2022-41091MedKEVNov 9, 2022
    risk 0.53cvss 5.4epss 0.02

    Windows Mark of the Web Security Feature Bypass Vulnerability

  • CVE-2022-41080HigKEVNov 9, 2022
    risk 0.81cvss 8.8epss 0.77

    Microsoft Exchange Server Elevation of Privilege Vulnerability

  • CVE-2022-41073HigKEVNov 9, 2022
    risk 0.69cvss 7.8epss 0.02

    Windows Print Spooler Elevation of Privilege Vulnerability

  • CVE-2022-41049MedKEVNov 9, 2022
    risk 0.47cvss 5.4epss 0.02

    Windows Mark of the Web Security Feature Bypass Vulnerability

  • CVE-2022-31199CriKEVNov 8, 2022
    risk 0.85cvss 9.8epss 0.36

    Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by…

  • CVE-2022-3723HigKEVNov 1, 2022
    risk 0.70cvss 8.8epss 0.08

    Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-42827HigKEVNov 1, 2022
    risk 0.63cvss 7.8epss 0.01

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have…

  • CVE-2022-38181HigKEVOct 25, 2022
    risk 0.70cvss 8.8epss 0.13

    The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0.

  • CVE-2016-20017CriKEVOct 19, 2022
    risk 0.84cvss 9.8epss 0.65

    D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.

  • CVE-2022-21587CriKEVOct 18, 2022
    risk 0.93cvss 9.8epss 0.98

    Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2022-40684CriKEVOct 18, 2022
    risk 0.93cvss 9.8epss 1.00

    An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated…

  • CVE-2022-41033HigKEVOct 11, 2022
    risk 0.63cvss 7.8epss 0.02

    Windows COM+ Event System Service Elevation of Privilege Vulnerability

  • CVE-2022-38028HigKEVOct 11, 2022
    risk 0.64cvss 7.8epss 0.15

    Windows Print Spooler Elevation of Privilege Vulnerability

  • CVE-2022-41082HigKEVOct 3, 2022
    risk 0.81cvss 8.0epss 1.00

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2022-41040HigKEVOct 3, 2022
    risk 0.86cvss 8.8epss 1.00

    Microsoft Exchange Server Elevation of Privilege Vulnerability

  • CVE-2022-20775HigKEVSep 30, 2022
    risk 0.64cvss 7.8epss 0.12

    A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running…

  • CVE-2022-3075CriKEVSep 26, 2022
    risk 0.75cvss 9.6epss 0.06

    Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2022-3038HigKEVSep 26, 2022
    risk 0.71cvss 8.8epss 0.25

    Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-2856MedKEVSep 26, 2022
    risk 0.55cvss 6.5epss 0.05

    Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.

  • CVE-2022-41352CriKEVSep 26, 2022
    risk 0.86cvss 9.8epss 0.95

    An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends…

  • CVE-2022-3236CriKEVSep 23, 2022
    risk 0.84cvss 9.8epss 0.99

    A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

  • CVE-2022-39197MedKEVSep 22, 2022
    risk 0.55cvss 6.1epss 0.46

    An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the…

  • CVE-2022-32917HigKEVSep 20, 2022
    risk 0.63cvss 7.8epss 0.06

    The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have…

  • CVE-2022-40139HigKEVSep 19, 2022
    risk 0.59cvss 7.2epss 0.03

    Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to…

  • CVE-2022-35914CriKEVSep 19, 2022
    risk 0.87cvss 9.8epss 1.00

    /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.

  • CVE-2022-37969HigKEVSep 13, 2022
    risk 0.65cvss 7.8epss 0.28

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2022-27593CriKEVSep 8, 2022
    risk 0.90cvss 10.0epss 0.88

    An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo…

  • CVE-2022-37055CriKEVAug 28, 2022
    risk 0.80cvss 9.8epss 0.57

    D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,

  • CVE-2022-36537HigKEVAug 26, 2022
    risk 0.67cvss 7.5epss 0.95

    ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.

  • CVE-2022-36804HigKEVAug 25, 2022
    risk 0.80cvss 8.8epss 0.99

    Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from…

  • CVE-2022-32894HigKEVAug 24, 2022
    risk 0.63cvss 7.8epss 0.03

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have…

  • CVE-2022-32893HigKEVAug 24, 2022
    risk 0.70cvss 8.8epss 0.10

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that…

  • CVE-2022-37042CriKEVAug 12, 2022
    risk 0.92cvss 9.8epss 0.92

    Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal…

  • CVE-2022-0028HigKEVAug 10, 2022
    risk 0.68cvss 8.6epss 0.02

    A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (virtual) and CN-Series…

  • CVE-2022-34713HigKEVAug 9, 2022
    risk 0.68cvss 7.8epss 0.68

    Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

  • CVE-2022-2294HigKEVJul 28, 2022
    risk 0.81cvss 8.8epss 0.70

    Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-1364HigKEVJul 26, 2022
    risk 0.70cvss 8.8epss 0.14

    Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-1096HigKEVJul 23, 2022
    risk 0.71cvss 8.8epss 0.24

    Type confusion in V8 in Google Chrome prior to 99.0.4844.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-26138CriKEVJul 20, 2022
    risk 0.84cvss 9.8epss 0.98

    The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded…

  • CVE-2022-35405CriKEVJul 19, 2022
    risk 0.87cvss 9.8epss 1.00

    Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)

  • CVE-2022-33891HigKEVJul 18, 2022
    risk 0.80cvss 8.8epss 0.93

    The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in HttpSecurityFilter…

  • CVE-2022-26352CriKEVJul 17, 2022
    risk 0.92cvss 9.8epss 0.91

    An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage…

  • CVE-2022-22047HigKEVJul 12, 2022
    risk 0.64cvss 7.8epss 0.17

    Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

  • CVE-2022-22071HigKEVJun 14, 2022
    risk 0.67cvss 8.4epss 0.00

    Possible use after free when process shell memory is freed using IOCTL munmap call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2022-26134CriKEVJun 3, 2022
    risk 0.93cvss 9.8epss 1.00

    In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from…

  • CVE-2022-30190HigKEVJun 1, 2022
    risk 0.80cvss 7.8epss 0.99

    A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then…

  • CVE-2022-22675HigKEVMay 26, 2022
    risk 0.64cvss 7.8epss 0.12

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code with kernel privileges. Apple…

  • CVE-2022-22674MedKEVMay 26, 2022
    risk 0.48cvss 5.5epss 0.01

    An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel…

  • CVE-2022-20821MedKEVMay 26, 2022
    risk 0.55cvss 6.5epss 0.12

    A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 by default upon…

  • CVE-2022-29303CriKEVMay 12, 2022
    risk 0.87cvss 9.8epss 0.98

    SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.