VYPR

CVEs

1,665 total · page 17 of 34

  • CVE-2021-37975HigKEVOct 8, 2021
    risk 0.72cvss 8.8epss 0.35

    Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-37973CriKEVOct 8, 2021
    risk 0.75cvss 9.6epss 0.12

    Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-30633CriKEVOct 8, 2021
    risk 0.77cvss 9.6epss 0.33

    Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-30632HigKEVOct 8, 2021
    risk 0.74cvss 8.8epss 0.65

    Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-42013CriKEVOct 7, 2021
    risk 0.86cvss 9.8epss 1.00

    It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by…

  • CVE-2021-25489LowKEVOct 6, 2021
    risk 0.33cvss 3.3epss 0.01

    Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.

  • CVE-2021-25487HigKEVOct 6, 2021
    risk 0.59cvss 7.3epss 0.01

    Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.

  • CVE-2021-39226CriKEVOct 5, 2021
    risk 0.77cvss 9.8epss 1.00

    Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot…

  • CVE-2021-41773CriKEVOct 5, 2021
    risk 0.86cvss 9.8epss 1.00

    A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the…

  • CVE-2021-20035MedKEVSep 27, 2021
    risk 0.55cvss 6.5epss 0.04

    Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.

  • CVE-2021-40655HigKEVSep 24, 2021
    risk 0.68cvss 7.5epss 0.87

    An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name and password by forging a post request to the / getcfg.php page

  • CVE-2021-22941CriKEVSep 23, 2021
    risk 0.86cvss 9.8epss 0.54

    Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.

  • CVE-2021-22017MedKEVSep 23, 2021
    risk 0.50cvss 5.3epss 0.49

    Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.

  • CVE-2021-22005CriKEVSep 23, 2021
    risk 0.93cvss 9.8epss 1.00

    The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.

  • CVE-2021-36260CriKEVSep 22, 2021
    risk 0.87cvss 9.8epss 1.00

    A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.

  • CVE-2021-38406HigKEVSep 17, 2021
    risk 0.69cvss 7.8epss 0.78

    Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of…

  • CVE-2021-40438CriKEVSep 16, 2021
    risk 0.85cvss 9.0epss 1.00

    A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

  • CVE-2021-33045CriKEVSep 15, 2021
    risk 0.84cvss 9.8epss 1.00

    The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

  • CVE-2021-33044CriKEVSep 15, 2021
    risk 0.84cvss 9.8epss 1.00

    The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

  • CVE-2021-40444HigKEVSep 15, 2021
    risk 0.86cvss 8.8epss 0.97

    Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An attacker could craft…

  • CVE-2021-38649HigKEVSep 15, 2021
    risk 0.58cvss 7.0epss 0.03

    Open Management Infrastructure Elevation of Privilege Vulnerability

  • CVE-2021-38648HigKEVSep 15, 2021
    risk 0.67cvss 7.8epss 0.11

    Open Management Infrastructure Elevation of Privilege Vulnerability

  • CVE-2021-38647CriKEVSep 15, 2021
    risk 0.93cvss 9.8epss 1.00

    Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

  • CVE-2021-38646HigKEVSep 15, 2021
    risk 0.69cvss 7.8epss 0.08

    Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

  • CVE-2021-38645HigKEVSep 15, 2021
    risk 0.63cvss 7.8epss 0.03

    Open Management Infrastructure Elevation of Privilege Vulnerability

  • CVE-2021-36955HigKEVSep 15, 2021
    risk 0.69cvss 7.8epss 0.04

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2021-38163CriKEVSep 14, 2021
    risk 0.79cvss 9.9epss 0.36

    SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with…

  • CVE-2021-40870CriKEVSep 13, 2021
    risk 0.83cvss 9.8epss 0.93

    An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

  • CVE-2021-30713HigKEVSep 8, 2021
    risk 0.63cvss 7.8epss 0.07

    A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.4. A malicious application may be able to bypass Privacy preferences. Apple is aware of a report that this issue may have been actively exploited..

  • CVE-2021-30666HigKEVSep 8, 2021
    risk 0.69cvss 8.8epss 0.03

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.5.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

  • CVE-2021-30665HigKEVSep 8, 2021
    risk 0.69cvss 8.8epss 0.04

    A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 7.4.1, iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is…

  • CVE-2021-30663HigKEVSep 8, 2021
    risk 0.69cvss 8.8epss 0.04

    An integer overflow was addressed with improved input validation. This issue is fixed in iOS 14.5.1 and iPadOS 14.5.1, tvOS 14.6, iOS 12.5.3, Safari 14.1.1, macOS Big Sur 11.3.1. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2021-30661HigKEVSep 8, 2021
    risk 0.70cvss 8.8epss 0.04

    A use after free issue was addressed with improved memory management. This issue is fixed in Safari 14.1, iOS 12.5.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is…

  • CVE-2021-30657MedKEVSep 8, 2021
    risk 0.56cvss 5.5epss 0.69

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..

  • CVE-2021-30762HigKEVSep 8, 2021
    risk 0.70cvss 8.8epss 0.11

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

  • CVE-2021-30761HigKEVSep 8, 2021
    risk 0.70cvss 8.8epss 0.11

    A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.5.4. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

  • CVE-2021-40539CriKEVSep 7, 2021
    risk 0.93cvss 9.8epss 0.99

    Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

  • CVE-2021-28550HigKEVSep 2, 2021
    risk 0.73cvss 8.8epss 0.52

    Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in…

  • CVE-2021-37415CriKEVSep 1, 2021
    risk 0.84cvss 9.8epss 1.00

    Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.

  • CVE-2021-26084CriKEVAug 30, 2021
    risk 0.93cvss 9.8epss 1.00

    In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version…

  • CVE-2021-32648HigKEVAug 26, 2021
    risk 0.66cvss 8.2epss 0.90

    octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472…

  • CVE-2021-31010HigKEVAug 24, 2021
    risk 0.61cvss 7.5epss 0.04

    A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was…

  • CVE-2021-30983HigKEVAug 24, 2021
    risk 0.63cvss 7.8epss 0.03

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 15.2 and iPadOS 15.2. An application may be able to execute arbitrary code with kernel privileges.

  • CVE-2021-30952HigKEVAug 24, 2021
    risk 0.63cvss 7.8epss 0.08

    An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2021-30900HigKEVAug 24, 2021
    risk 0.63cvss 7.8epss 0.05

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 14.8.1 and iPadOS 14.8.1, iOS 15.1 and iPadOS 15.1. A malicious application may be able to execute arbitrary code with kernel privileges.

  • CVE-2021-30883HigKEVAug 24, 2021
    risk 0.64cvss 7.8epss 0.15

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 15.0.2 and iPadOS 15.0.2, macOS Monterey 12.0.1, iOS 14.8.1 and iPadOS 14.8.1, tvOS 15.1, watchOS 8.1, macOS Big Sur 11.6.1. An application may be able to execute arbitrary code…

  • CVE-2021-30869HigKEVAug 24, 2021
    risk 0.63cvss 7.8epss 0.04

    A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 12.5.5, iOS 14.4 and iPadOS 14.4, macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, Security Update 2021-006 Catalina. A malicious application may…

  • CVE-2021-30860HigKEVAug 24, 2021
    risk 0.62cvss 7.8epss 0.76

    An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a…

  • CVE-2021-30858HigKEVAug 24, 2021
    risk 0.70cvss 8.8epss 0.13

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been…

  • CVE-2021-39144HigKEVAug 23, 2021
    risk 0.71cvss 8.5epss 0.98

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed…