VYPR

CVEs

112,083 total · page 1111 of 2,242

  • CVE-2023-39948HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.01

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0 and 2.6.5, the `BadParamException` thrown by Fast CDR is not caught in Fast DDS. This can remotely crash any Fast DDS process. Versions…

  • CVE-2023-39947HigAug 11, 2023
    risk 0.53cvss 8.2epss 0.01

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, even after the fix at commit 3492270, malformed `PID_PROPERTY_LIST` parameters cause heap overflow at a…

  • CVE-2023-39946HigAug 11, 2023
    risk 0.53cvss 8.2epss 0.01

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, heap can be overflowed by providing a PID_PROPERTY_LIST parameter that contains a CDR string with length larger…

  • CVE-2023-39945HigAug 11, 2023
    risk 0.53cvss 8.2epss 0.01

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.0, 2.10.2, 2.9.2, and 2.6.5, a data submessage sent to PDP port raises unhandled `BadParamException` in fastcdr, which in turn crashes…

  • CVE-2023-39534HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.01

    eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0, 2.9.2, and 2.6.5, a malformed GAP submessage can trigger assertion failure, crashing FastDDS. Version 2.10.0, 2.9.2, and 2.6.5 contain a…

  • CVE-2021-29378HigAug 11, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in pear-admin-think version 2.1.2, allows attackers to execute arbitrary code and escalate privileges via crafted GET request to Crud.php.

  • CVE-2021-28835HigAug 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in XNView before 2.50, allows local attackers to execute arbitrary code via crafted GEM bitmap file.

  • CVE-2021-28427HigAug 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in XNView version 2.49.3, allows local attackers to execute arbitrary code via crafted TIFF file.

  • CVE-2021-26504HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information via crafted request in res.sendFile API in hue-magic.js.

  • CVE-2021-25857HigAug 11, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in pcmt superMicro-CMS version 3.11, allows authenticated attackers to execute arbitrary code via the font_type parameter to setup.php.

  • CVE-2020-36138HigAug 11, 2023
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in decode_frame in libavcodec/tiff.c in FFmpeg version 4.3, allows remote attackers to cause a denial of service (DoS).

  • CVE-2020-36136HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability in cskaza cszcms version 1.2.9, allows attackers to gain sensitive information via pm_sendmail parameter in csz_model.php.

  • CVE-2020-36037HigAug 11, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was disocvered in wuzhicms version 4.1.0, allows remote attackers to execte arbitrary code via the setting parameter to the ueditor in index.php.

  • CVE-2020-35141HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in OFPQueueGetConfigReply in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite loop).

  • CVE-2020-35139HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in OFPBundleCtrlMsg in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite loop).

  • CVE-2020-28848HigAug 11, 2023
    risk 0.57cvss 8.8epss 0.01

    CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file.

  • CVE-2020-28840HigAug 11, 2023
    risk 0.00cvss 7.8epss 0.00

    Buffer Overflow vulnerability in jpgfile.c in Matthias-Wandel jhead version 3.04, allows local attackers to execute arbitrary code and cause a denial of service (DoS).

  • CVE-2020-24950HigAug 11, 2023
    risk 0.50cvss 8.8epss 0.01

    SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbitrary code via the col parameter to function list_items.

  • CVE-2020-24922HigAug 11, 2023
    risk 0.57cvss 8.8epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file.

  • CVE-2020-24222HigAug 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in jfif_decode() function in rockcarry ffjpeg through version 1.0.0, allows local attackers to execute arbitrary code due to an issue with ALIGN.

  • CVE-2020-23595HigAug 11, 2023
    risk 0.57cvss 8.8epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in yzmcms version 5.6, allows remote attackers to escalate privileges and gain sensitive information sitemodel/add.html endpoint.

  • CVE-2023-39417HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.02

    IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, trusted, non-bundled extension,…

  • CVE-2023-3864HigAug 11, 2023
    risk 0.47cvss 7.2epss 0.00

    Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.

  • CVE-2023-39553HigAug 11, 2023
    risk 0.42cvss 7.5epss 0.02

    Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Drill Provider. Apache Airflow Drill Provider is affected by a vulnerability that allows an attacker to pass in malicious parameters when establishing a connection with DrillHook giving an…

  • CVE-2023-40254HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Malicious Software Update.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Genian NAC V5.0: from…

  • CVE-2023-3823HigAug 11, 2023
    risk 0.56cvss 8.6epss 0.02

    In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly…

  • CVE-2023-34438HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-34086HigAug 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-32617HigAug 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Improper input validation in some Intel(R) NUC Rugged Kit, Intel(R) NUC Kit and Intel(R) Compute Element BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-29494HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Improper input validation in BIOS firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-28714HigAug 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-28385HigAug 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Improper authorization in the Intel(R) NUC Pro Software Suite for Windows before version 2.0.0.9 may allow a privileged user to potentially enable escalation of privilage via local access.

  • CVE-2023-28380HigAug 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Uncontrolled search path for the Intel(R) AI Hackathon software before version 2.0.0 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2023-27515HigAug 11, 2023
    risk 0.53cvss 8.1epss 0.00

    Cross-site scripting (XSS) for the Intel(R) DSA software before version 23.1.9 may allow unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2023-26587HigAug 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper input validation for the Intel(R) Easy Streaming Wizard software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-25773HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Improper access control in the Intel(R) Unite(R) Hub software installer for Windows before version 4.2.34962 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-25757HigAug 11, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper access control in some Intel(R) Unison(TM) software before version 10.12 may allow a privileged user to potentially enable escalation of privilege via network access.

  • CVE-2023-22449HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-46329HigAug 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-45112HigAug 11, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper access control in some Intel(R) VROC software before version 8.0.0.4035 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-41804HigAug 11, 2023
    risk 0.47cvss 7.2epss 0.00

    Unauthorized error injection in Intel(R) SGX or Intel(R) TDX for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-40964HigAug 11, 2023
    risk 0.51cvss 7.9epss 0.00

    Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-38102HigAug 11, 2023
    risk 0.47cvss 7.2epss 0.00

    Improper Input validation in firmware for some Intel(R) Converged Security and Management Engine before versions 15.0.45, and 16.1.27 may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2022-37343HigAug 11, 2023
    risk 0.47cvss 7.2epss 0.00

    Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-37336HigAug 11, 2023
    risk 0.51cvss 7.9epss 0.00

    Improper input validation in BIOS firmware for some Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-36392HigAug 11, 2023
    risk 0.56cvss 8.6epss 0.01

    Improper input validation in some firmware for Intel(R) AMT and Intel(R) Standard Manageability before versions 11.8.94, 11.12.94, 11.22.94, 12.0.93, 14.1.70, 15.0.45, and 16.1.27 in Intel (R) CSME may allow an unauthenticated user to potentially enable denial of service via…

  • CVE-2022-36372HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.00

    Improper buffer restrictions in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-29887HigAug 11, 2023
    risk 0.53cvss 8.1epss 0.01

    Cross-site Scripting (XSS) in some Intel(R) Manageability Commander software before version 2.3 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2022-27635HigAug 11, 2023
    risk 0.53cvss 8.2epss 0.00

    Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-35179HigAug 11, 2023
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action.