VYPR

CVEs

105,914 total · page 1116 of 2,119

  • CVE-2022-46117HigDec 14, 2022
    risk 0.47cvss 7.2epss 0.01

    Helmet Store Showroom Site v1.0 is vulnerable to SQL Injection via /hss/?page=view_product&id=.

  • CVE-2022-46074HigDec 14, 2022
    risk 0.57cvss 8.8epss 0.00

    Helmet Store Showroom 1.0 is vulnerable to Cross Site Request Forgery (CSRF). An unauthenticated user can add an admin account due to missing CSRF protection.

  • CVE-2022-23519HigDec 14, 2022
    risk 0.47cvss 7.2epss 0.01

    rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden…

  • CVE-2022-23517HigDec 14, 2022
    risk 0.42cvss 7.5epss 0.01

    rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes.…

  • CVE-2022-44898HigDec 14, 2022
    risk 0.51cvss 7.8epss 0.00

    The MsIo64.sys component in Asus Aura Sync through v1.07.79 does not properly validate input to IOCTL 0x80102040, 0x80102044, 0x80102050, and 0x80102054, allowing attackers to trigger a memory corruption and cause a Denial of Service (DoS) or escalate privileges via crafted…

  • CVE-2022-23516HigDec 14, 2022
    risk 0.42cvss 7.5epss 0.01

    Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, making it susceptible to stack exhaustion and raising a SystemStackError exception. …

  • CVE-2022-23514HigDec 14, 2022
    risk 0.42cvss 7.5epss 0.02

    Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes.…

  • CVE-2022-23512HigDec 14, 2022
    risk 0.50cvss 7.7epss 0.01

    MeterSphere is a one-stop open source continuous testing platform. Versions prior to 2.4.1 are vulnerable to Path Injection in ApiTestCaseService::deleteBodyFiles which takes a user-controlled string id and passes it to ApiTestCaseService, which uses the user-provided value…

  • CVE-2022-34271HigDec 14, 2022
    risk 0.50cvss 8.8epss 0.01

    A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.

  • CVE-2022-23503HigDec 14, 2022
    risk 0.42cvss 7.5epss 0.01

    TYPO3 is an open source PHP based web content management system. Versions prior to 8.7.49, 9.5.38, 10.4.33, 11.5.20, and 12.1.1 are vulnerable to Code Injection. Due to the lack of separating user-submitted data from the internal configuration in the Form Designer backend…

  • CVE-2022-4440HigDec 14, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Profiles in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-4439HigDec 14, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: High)

  • CVE-2022-4438HigDec 14, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Blink Frames in Google Chrome prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-4437HigDec 14, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-4436HigDec 14, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Blink Media in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-24377HigDec 14, 2022
    risk 0.41cvss 7.4epss 0.02

    The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.

  • CVE-2022-42140HigDec 14, 2022
    risk 0.47cvss 7.2epss 0.02

    Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.

  • CVE-2022-42139HigDec 14, 2022
    risk 0.59cvss 8.8epss 0.18

    Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.

  • CVE-2022-37155HigDec 14, 2022
    risk 0.60cvss 8.8epss 0.40

    RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.

  • CVE-2022-38355HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.00

    Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to attackers with access to the local area network (LAN) to disclose sensitive information stored by the affected product without requiring authentication.

  • CVE-2022-2951HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to improper validation of array index vulnerability during processing of H3D files. A DWORD value from a PoC file is extracted and used as an index to write to a buffer, leading to memory corruption. …

  • CVE-2022-2950HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an uninitialized buffer and, after sign extension, is used as an index into a stack variable to…

  • CVE-2022-2949HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an uninitialized buffer and, after sign extension, is used as an index into a stack variable to…

  • CVE-2022-2947HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    Altair HyperView Player versions 2021.1.0.27 and prior perform operations on a memory buffer but can read from or write to a memory location outside of the intended boundary of the buffer. This hits initially as a read access violation, leading to a memory corruption…

  • CVE-2022-47213HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Graphics Remote Code Execution Vulnerability

  • CVE-2022-47212HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Graphics Remote Code Execution Vulnerability

  • CVE-2022-47211HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Graphics Remote Code Execution Vulnerability

  • CVE-2022-44713HigDec 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Microsoft Outlook for Mac Spoofing Vulnerability

  • CVE-2022-44710HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.01

    DirectX Graphics Kernel Elevation of Privilege Vulnerability

  • CVE-2022-44708HigDec 13, 2022
    risk 0.54cvss 8.3epss 0.02

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2022-44704HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability

  • CVE-2022-44702HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows Terminal Remote Code Execution Vulnerability

  • CVE-2022-44697HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows Graphics Component Elevation of Privilege Vulnerability

  • CVE-2022-44696HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Visio Remote Code Execution Vulnerability

  • CVE-2022-44695HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Visio Remote Code Execution Vulnerability

  • CVE-2022-44694HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Visio Remote Code Execution Vulnerability

  • CVE-2022-44693HigDec 13, 2022
    risk 0.57cvss 8.8epss 0.02

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2022-44692HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Graphics Remote Code Execution Vulnerability

  • CVE-2022-44691HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office OneNote Remote Code Execution Vulnerability

  • CVE-2022-44690HigDec 13, 2022
    risk 0.64cvss 8.8epss 0.82

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2022-44689HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability

  • CVE-2022-44687HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Raw Image Extension Remote Code Execution Vulnerability

  • CVE-2022-44683HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.08

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2022-44681HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows Print Spooler Elevation of Privilege Vulnerability

  • CVE-2022-44680HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    Windows Graphics Component Elevation of Privilege Vulnerability

  • CVE-2022-44678HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows Print Spooler Elevation of Privilege Vulnerability

  • CVE-2022-44677HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    Windows Projected File System Elevation of Privilege Vulnerability

  • CVE-2022-44676HigDec 13, 2022
    risk 0.53cvss 8.1epss 0.01

    Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

  • CVE-2022-44675HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.05

    Windows Bluetooth Driver Elevation of Privilege Vulnerability

  • CVE-2022-44673HigDec 13, 2022
    risk 0.46cvss 7.0epss 0.05

    Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability