VYPR

CVEs

105,912 total · page 1119 of 2,119

  • CVE-2022-45977HigDec 12, 2022
    risk 0.57cvss 8.8epss 0.02

    Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.

  • CVE-2022-45957HigDec 12, 2022
    risk 0.50cvss 7.5epss 0.11

    ZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 is vulnerable to remote stack buffer overflow.

  • CVE-2022-45043HigDec 12, 2022
    risk 0.57cvss 8.8epss 0.02

    Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set.

  • CVE-2022-45968HigDec 12, 2022
    risk 0.50cvss 8.8epss 0.01

    Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a password protected one).

  • CVE-2022-44654HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Affected builds of Trend Micro Apex One and Apex One as a Service contain a monitor engine component that is complied without the /SAFESEH memory protection mechanism which helps to monitor for malicious payloads. The affected component's memory protection mechanism has been…

  • CVE-2022-44653HigDec 12, 2022
    risk 0.51cvss 7.8epss 0.01

    A security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2022-44652HigDec 12, 2022
    risk 0.51cvss 7.8epss 0.00

    An improper handling of exceptional conditions vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code…

  • CVE-2022-44651HigDec 12, 2022
    risk 0.46cvss 7.0epss 0.00

    A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2022-44650HigDec 12, 2022
    risk 0.51cvss 7.8epss 0.00

    A memory corruption vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obtain the ability to execute…

  • CVE-2022-44649HigDec 12, 2022
    risk 0.51cvss 7.8epss 0.00

    An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obtain the ability to…

  • CVE-2022-44533HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the Aruba EdgeConnect Enterprise web management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system…

  • CVE-2022-43780HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Certain HP ENVY, OfficeJet, and DeskJet printers may be vulnerable to a Denial of Service attack.

  • CVE-2022-43542HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.01

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system…

  • CVE-2022-43541HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system…

  • CVE-2022-3510HigDec 12, 2022
    risk 0.42cvss 7.5epss 0.00

    A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with…

  • CVE-2022-3509HigDec 12, 2022
    risk 0.42cvss 7.5epss 0.01

    A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or…

  • CVE-2022-38656HigDec 12, 2022
    risk 0.56cvss 8.6epss 0.01

    HCL Commerce, when using Elasticsearch, can allow a remote attacker to cause a denial of service attack on the site and make administrative changes.

  • CVE-2022-38395HigDec 12, 2022
    risk 0.51cvss 7.8epss 0.03

    HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possible for an attacker to exploit the DLL hijacking vulnerability and elevate privileges when Fusion launches the HP Performance…

  • CVE-2022-37932HigDec 12, 2022
    risk 0.57cvss 8.8epss 0.03

    A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches. The vulnerability could be remotely exploited to allow authentication bypass. HPE has made the following software updates to resolve the…

  • CVE-2022-37928HigDec 12, 2022
    risk 0.52cvss 8.0epss 0.00

    Insufficient Verification of Data Authenticity vulnerability in Hewlett Packard Enterprise HPE Nimble Storage Hybrid Flash Arrays and Nimble Storage Secondary Flash Arrays.

  • CVE-2022-37924HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system…

  • CVE-2022-37923HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.01

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system…

  • CVE-2022-37922HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.01

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system…

  • CVE-2022-37921HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.01

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system…

  • CVE-2022-37920HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.01

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system…

  • CVE-2022-37919HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability exists in the API of Aruba EdgeConnect Enterprise. An unauthenticated attacker can exploit this condition via the web-based management interface to create a denial-of-service condition which prevents the appliance from properly responding to API requests in Aruba…

  • CVE-2022-37912HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2022-37903HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full compromise the underlying host operating system.

  • CVE-2022-37902HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2022-37901HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2022-37900HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2022-37899HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2022-37898HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.01

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2022-37018HigDec 12, 2022
    risk 0.55cvss 8.4epss 0.00

    A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerability.

  • CVE-2022-2794HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack.

  • CVE-2022-23511HigDec 12, 2022
    risk 0.39cvss 7.1epss 0.00

    A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2 instances and on-premises servers, in versions up to and including v1.247354. When users trigger a repair of the Agent, a pop-up window…

  • CVE-2022-1038HigDec 12, 2022
    risk 0.51cvss 7.8epss 0.00

    A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of privilege. HP is recommending that customers uninstall HP Jumpstart and use myHP software.

  • CVE-2021-3661HigDec 12, 2022
    risk 0.55cvss 8.4epss 0.00

    A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.

  • CVE-2022-45797HigDec 12, 2022
    risk 0.46cvss 7.1epss 0.01

    An arbitrary file deletion vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges and delete files on affected installations. Please note: an attacker must first…

  • CVE-2022-3641HigDec 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated user to spoof a privileged account.

  • CVE-2022-20968HigDec 12, 2022
    risk 0.53cvss 8.1epss 0.06

    A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could allow an unauthenticated, adjacent attacker to cause a stack overflow on an affected device. This vulnerability is due to insufficient input validation of…

  • CVE-2022-46908HigDec 12, 2022
    risk 0.47cvss 7.3epss 0.00

    SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.

  • CVE-2022-25837HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.00

    Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when at least one device supports BR/EDR Secure Connections pairing and the other BR/EDR Legacy PIN code…

  • CVE-2022-25836HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.00

    Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to acquire credentials with two pairing devices via adjacent access when the MITM negotiates Legacy Passkey Pairing with the pairing Initiator and Secure…

  • CVE-2022-45760HigDec 12, 2022
    risk 0.57cvss 8.8epss 0.01

    SENS v1.0 is vulnerable to Incorrect Access Control vulnerability.

  • CVE-2022-45759HigDec 12, 2022
    risk 0.57cvss 8.8epss 0.01

    SENS v1.0 has a file upload vulnerability.

  • CVE-2022-45227HigDec 12, 2022
    risk 0.49cvss 7.5epss 0.01

    The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https://10.10.20.74/lib/. This address has a backup file which can be downloaded without any authentication.

  • CVE-2022-4409HigDec 11, 2022
    risk 0.42cvss 7.5epss 0.00

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

  • CVE-2022-4398HigDec 10, 2022
    risk 0.00cvss 7.8epss 0.00

    Integer Overflow or Wraparound in GitHub repository radareorg/radare2 prior to 5.8.0.

  • CVE-2022-46166HigDec 9, 2022
    risk 0.00cvss 8.0epss 0.01

    Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are…