VYPR

CVEs

105,912 total · page 1120 of 2,119

  • CVE-2022-46157HigDec 9, 2022
    risk 0.50cvss 8.8epss 0.01

    Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Community Edition versions before v5.0.119 and v6.0.53 allows remote authenticated users to execute arbitrary PHP code on the server by uploading a crafted image. Akeneo PIM Community Edition after the…

  • CVE-2022-44790HigDec 9, 2022
    risk 0.49cvss 7.5epss 0.01

    Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists.

  • CVE-2022-2993HigDec 9, 2022
    risk 0.56cvss 8.6epss 0.01

    There is an error in the condition of the last if-statement in the function smp_check_keys. It was rejecting current keys if all requirements were unmet.

  • CVE-2022-3259HigDec 9, 2022
    risk 0.48cvss 7.4epss 0.01

    Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.

  • CVE-2022-23484HigDec 9, 2022
    risk 0.53cvss 8.2epss 0.01

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Integer Overflow in xrdp_mm_process_rail_update_window_text() function. There are no known workarounds for this issue. Users…

  • CVE-2022-23483HigDec 9, 2022
    risk 0.49cvss 7.5epss 0.01

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in libxrdp_send_to_channel() function. There are no known workarounds for this issue. Users are advised to…

  • CVE-2022-44838HigDec 9, 2022
    risk 0.47cvss 7.2epss 0.01

    Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /services/view_service.php.

  • CVE-2022-46153HigDec 8, 2022
    risk 0.46cvss 8.1epss 0.00

    Traefik is an open source HTTP reverse proxy and load balancer. In affected versions there is a potential vulnerability in Traefik managing TLS connections. A router configured with a not well-formatted TLSOption is exposed with an empty TLSOption. For instance, a route secured…

  • CVE-2022-23496HigDec 8, 2022
    risk 0.42cvss 7.5epss 0.01

    Yet Another UserAgent Analyzer (Yauaa) is a java library that tries to parse and analyze the useragent string and extract as many relevant attributes as possible. Applications using the Client Hints analysis feature introduced with 7.0.0 can crash because the Yauaa library…

  • CVE-2022-23495HigDec 8, 2022
    risk 0.00cvss 7.5epss 0.01

    go-merkledag implements the 'DAGService' interface and adds two ipld node types, Protobuf and Raw for the ipfs project. A `ProtoNode` may be modified in such a way as to cause various encode errors which will trigger a panic on common method calls that don't allow for error…

  • CVE-2022-4366HigDec 8, 2022
    risk 0.00cvss 7.5epss 0.01

    Missing Authorization in GitHub repository lirantal/daloradius prior to master branch.

  • CVE-2022-46829HigDec 8, 2022
    risk 0.46cvss 7.1epss 0.00

    In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.

  • CVE-2022-45877HigDec 8, 2022
    risk 0.54cvss 8.3epss 0.00

    OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text during cross-device authentication, which reduces the difficulty of man-in-the-middle attacks.

  • CVE-2022-45525HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the downaction parameter at /goform/CertListInfo.

  • CVE-2022-45524HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the opttype parameter at /goform/IPSECsave.

  • CVE-2022-45523HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/L7Im.

  • CVE-2022-45522HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeClientFilter.

  • CVE-2022-45521HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeUrlFilter.

  • CVE-2022-45520HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/qossetting.

  • CVE-2022-45519HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the Go parameter at /goform/SafeMacFilter.

  • CVE-2022-45518HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SetIpBind.

  • CVE-2022-45517HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/VirtualSer.

  • CVE-2022-45516HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/NatStaticSetting.

  • CVE-2022-45515HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the entries parameter at /goform/addressNat.

  • CVE-2022-45514HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/webExcptypemanFilter.

  • CVE-2022-45513HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/P2pListFilter.

  • CVE-2022-45512HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeEmailFilter.

  • CVE-2022-45511HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the PPPOEPassword parameter at /goform/QuickIndex.

  • CVE-2022-45510HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the mit_ssid_index parameter at /goform/AdvSetWrlsafeset.

  • CVE-2022-45509HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the account parameter at /goform/addUserName.

  • CVE-2022-45508HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the new_account parameter at /goform/editUserName.

  • CVE-2022-45507HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the editNameMit parameter at /goform/editFileName.

  • CVE-2022-45505HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the cmdinput parameter at /goform/exeCommand.

  • CVE-2022-45504HigDec 8, 2022
    risk 0.50cvss 7.5epss 0.18

    An issue in the component tpi_systool_handle(0) (/goform/SysToolRestoreSet) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device.

  • CVE-2022-45503HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the linkEn parameter at /goform/setAutoPing.

  • CVE-2022-45501HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/wifiSSIDset.

  • CVE-2022-45499HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda W6-S v1.0.0.4(510) was discovered to contain a stack overflow via the wl_radio parameter at /goform/WifiMacFilterGet.

  • CVE-2022-45498HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue in the component tpi_systool_handle(0) (/goform/SysToolReboot) of Tenda W6-S v1.0.0.4(510) allows unauthenticated attackers to arbitrarily reboot the device.

  • CVE-2022-44932HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    An access control issue in Tenda A18 v15.13.07.09 allows unauthenticated attackers to access the Telnet service.

  • CVE-2022-44931HigDec 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.

  • CVE-2022-3262HigDec 8, 2022
    risk 0.53cvss 8.1epss 0.01

    A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.

  • CVE-2022-39909HigDec 8, 2022
    risk 0.46cvss 7.1epss 0.00

    Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers to create arbitrary file using symbolic link.

  • CVE-2022-38754HigDec 8, 2022
    risk 0.52cvss 8.0epss 0.01

    A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could be exploited by a malicious authenticated OBM (Operations Bridge Manager) user to run Java Scripts in the browser context of another OBM user. Please note: The…

  • CVE-2022-37918HigDec 8, 2022
    risk 0.53cvss 8.1epss 0.01

    Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change…

  • CVE-2022-37917HigDec 8, 2022
    risk 0.53cvss 8.1epss 0.01

    Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change…

  • CVE-2022-37916HigDec 8, 2022
    risk 0.53cvss 8.1epss 0.01

    Vulnerabilities in the AirWave Management Platform web-based management interface exist which expose some URLs to a lack of proper access controls. These vulnerabilities could allow a remote attacker with limited privileges to gain access to sensitive information and/or change…

  • CVE-2022-4364HigDec 8, 2022
    risk 0.48cvss 7.3epss 0.04

    A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command injection. The attack is possible to be…

  • CVE-2022-46792HigDec 8, 2022
    risk 0.57cvss 8.8epss 0.01

    Hasura GraphQL Engine before 2.15.2 mishandles row-level authorization in the Update Many API for Postgres backends. The fixed versions are 2.10.2, 2.11.3, 2.12.1, 2.13.2, 2.14.1, and 2.15.2. (Versions before 2.10.0 are unaffected.)

  • CVE-2022-23476HigDec 8, 2022
    risk 0.42cvss 7.5epss 0.02

    Nokogiri is an open source XML and HTML library for the Ruby programming language. Nokogiri `1.13.8` and `1.13.9` fail to check the return value from `xmlTextReaderExpand` in the method `Nokogiri::XML::Reader#attribute_hash`. This can lead to a null pointer exception when…

  • CVE-2022-23492HigDec 8, 2022
    risk 0.42cvss 7.5epss 0.01

    go-libp2p is the offical libp2p implementation in the Go programming language. Version `0.18.0` and older of go-libp2p are vulnerable to targeted resource exhaustion attacks. These attacks target libp2p’s connection, stream, peer, and memory management. An attacker can cause…