VYPR

CVEs

105,912 total · page 1124 of 2,119

  • CVE-2022-2969HigDec 1, 2022
    risk 0.53cvss 8.1epss 0.02

    Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname intended to identify a file or directory located underneath a restricted parent directory. However, the software does not properly neutralize special elements…

  • CVE-2022-37017HigDec 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly…

  • CVE-2022-28607HigDec 1, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to gain sensitive information via the action parameter to /system/user/modules/mod_users/controller.php.

  • CVE-2022-1471HigDec 1, 2022
    risk 0.58cvss 8.3epss 1.00

    SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to…

  • CVE-2022-45640HigDec 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda Tenda AC6V1.0 V15.03.05.19 is affected by buffer overflow. Causes a denial of service (local).

  • CVE-2022-45045HigDec 1, 2022
    risk 0.57cvss 8.8epss 0.01

    Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and…

  • CVE-2022-40489HigDec 1, 2022
    risk 0.50cvss 8.8epss 0.00

    ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injected into administrative users.

  • CVE-2022-46162HigNov 30, 2022
    risk 0.00cvss 8.8epss 0.01

    discourse-bbcode is the official BBCode plugin for Discourse. Prior to commit 91478f5, CSS injection can occur when rendering content generated with the discourse-bccode plugin. This vulnerability only affects sites which have the discourse-bbcode plugin installed and enabled.…

  • CVE-2022-46156HigNov 30, 2022
    risk 0.40cvss 7.2epss 0.00

    The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application provides probe functionality and executes network checks for monitoring remote targets. Users running the Synthetic Monitoring agent prior to version 0.12.0 in their local network are impacted. The…

  • CVE-2022-23746HigNov 30, 2022
    risk 0.49cvss 7.5epss 0.01

    The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on usernames and passwords.

  • CVE-2022-44296HigNov 30, 2022
    risk 0.47cvss 7.2epss 0.01

    Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/quotes/manage_remark.php?id=.

  • CVE-2022-44295HigNov 30, 2022
    risk 0.47cvss 7.2epss 0.01

    Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/assign_team.php?id=.

  • CVE-2022-44294HigNov 30, 2022
    risk 0.47cvss 7.2epss 0.01

    Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=services/manage_service&id=.

  • CVE-2022-4229HigNov 30, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in SourceCodester Book Store Management System 1.0. This vulnerability affects unknown code of the file /bsms_ci/index.php. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has…

  • CVE-2022-41412HigNov 30, 2022
    risk 0.56cvss 8.6epss 0.04

    An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forgery (SSRF) attacks.

  • CVE-2022-45337HigNov 30, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda TX9 Pro v22.03.02.10 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.

  • CVE-2022-45332HigNov 30, 2022
    risk 0.51cvss 7.8epss 0.00

    LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r11.c.

  • CVE-2022-45328HigNov 30, 2022
    risk 0.47cvss 7.2epss 0.01

    Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_members.php.

  • CVE-2022-40265HigNov 30, 2022
    risk 0.56cvss 8.6epss 0.01

    Improper Input Validation vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series RJ71EN71 Firmware version "65" and prior and Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120ENCPU Network Part Firmware version "65" and prior allows a remote…

  • CVE-2022-4194HigNov 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Accessibility in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-4193HigNov 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Insufficient policy enforcement in File System API in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-4192HigNov 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Live Caption in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via UI interaction. (Chromium security severity: Medium)

  • CVE-2022-4191HigNov 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Sign-In in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via profile destruction. (Chromium security severity: Medium)

  • CVE-2022-4190HigNov 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Insufficient data validation in Directory in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-4181HigNov 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Forms in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-4180HigNov 30, 2022
    risk 0.57cvss 8.8epss 0.00

    Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

  • CVE-2022-4179HigNov 30, 2022
    risk 0.57cvss 8.8epss 0.00

    Use after free in Audio in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

  • CVE-2022-4178HigNov 30, 2022
    risk 0.59cvss 8.8epss 0.24

    Use after free in Mojo in Google Chrome prior to 108.0.5359.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-4177HigNov 30, 2022
    risk 0.57cvss 8.8epss 0.00

    Use after free in Extensions in Google Chrome prior to 108.0.5359.71 allowed an attacker who convinced a user to install an extension to potentially exploit heap corruption via a crafted Chrome Extension and UI interaction. (Chromium security severity: High)

  • CVE-2022-4176HigNov 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Out of bounds write in Lacros Graphics in Google Chrome on Chrome OS and Lacros prior to 108.0.5359.71 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via UI interactions. (Chromium security severity:…

  • CVE-2022-4175HigNov 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Camera Capture in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-4174HigNov 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Type confusion in V8 in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-46155HigNov 29, 2022
    risk 0.00cvss 7.6epss 0.00

    Airtable.js is the JavaScript client for Airtable. Prior to version 0.11.6, Airtable.js had a misconfigured build script in its source package. When the build script is run, it would bundle environment variables into the build target of a transpiled bundle. Specifically, the…

  • CVE-2022-4035HigNov 29, 2022
    risk 0.47cvss 7.2epss 0.01

    The Appointment Hour Booking plugin for WordPress is vulnerable to iFrame Injection via the ‘email’ or general field parameters in versions up to, and including, 1.3.72 due to insufficient input sanitization and output escaping that makes injecting iFrame tags possible. This…

  • CVE-2022-4032HigNov 29, 2022
    risk 0.47cvss 7.2epss 0.01

    The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in versions up to, and including, 8.0.4 due to insufficient input sanitization and output escaping that allowed iframe tags to be injected. This makes it possible…

  • CVE-2022-4030HigNov 29, 2022
    risk 0.53cvss 8.1epss 0.02

    The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'file' parameter which can be manipulated during user avatar deletion. This makes it possible with attackers, with minimal permissions such as a subscriber, to…

  • CVE-2022-4027HigNov 29, 2022
    risk 0.47cvss 7.2epss 0.01

    The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipulated during a forum response in versions up to, and including, 6.8 due to insufficient input sanitization and output escaping that makes injecting object and…

  • CVE-2022-3898HigNov 29, 2022
    risk 0.57cvss 8.8epss 0.00

    The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.9. This is due to missing or incorrect nonce validation on various functions including the affiliates_menu method. This makes it possible for…

  • CVE-2022-3747HigNov 29, 2022
    risk 0.57cvss 8.8epss 0.01

    The Becustom plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5.2. This is due to missing nonce validation when saving the plugin's settings. This makes it possible for unauthenticated attackers to update the plugin's…

  • CVE-2022-3384HigNov 29, 2022
    risk 0.47cvss 7.2epss 0.03

    The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts user supplied input and passes it through call_user_func(). This is restricted to non-parameter PHP…

  • CVE-2022-3383HigNov 29, 2022
    risk 0.47cvss 7.2epss 0.03

    The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from_callback function that accepts user supplied input and passes it through call_user_func(). This makes it possible for…

  • CVE-2022-36964HigNov 29, 2022
    risk 0.59cvss 8.8epss 0.17

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2022-36962HigNov 29, 2022
    risk 0.48cvss 7.2epss 0.09

    SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds database to execute arbitrary commands.

  • CVE-2022-36960HigNov 29, 2022
    risk 0.57cvss 8.8epss 0.01

    SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to escalate user privileges.

  • CVE-2022-46152HigNov 29, 2022
    risk 0.53cvss 8.2epss 0.00

    OP-TEE Trusted OS is the secure side implementation of OP-TEE project, a Trusted Execution Environment. Versions prior to 3.19.0, contain an Improper Validation of Array Index vulnerability. The function `cleanup_shm_refs()` is called by both `entry_invoke_command()` and…

  • CVE-2022-46148HigNov 29, 2022
    risk 0.46cvss 7.1epss 0.00

    Discourse is an open-source messaging platform. In versions 2.8.10 and prior on the `stable` branch and versions 2.9.0.beta11 and prior on the `beta` and `tests-passed` branches, users composing malicious messages and navigating to drafts page could self-XSS. This vulnerability…

  • CVE-2022-44356HigNov 29, 2022
    risk 0.49cvss 7.5epss 0.03

    WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allows unauthenticated attackers to download configuration data and log files.

  • CVE-2022-25848HigNov 29, 2022
    risk 0.49cvss 7.5epss 0.01

    This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the path accessed are relative to that of the root directory.

  • CVE-2022-21126HigNov 29, 2022
    risk 0.41cvss 7.3epss 0.01

    The package com.github.samtools:htsjdk before 3.0.1 are vulnerable to Creation of Temporary File in Directory with Insecure Permissions due to the createTempDir() function in util/IOUtil.java not checking for the existence of the temporary directory before attempting to create…

  • CVE-2022-45343HigNov 29, 2022
    risk 0.51cvss 7.8epss 0.00

    GPAC v2.1-DEV-rev478-g696e6f868-master was discovered to contain a heap use-after-free via the Q_IsTypeOn function at /gpac/src/bifs/unquantize.c.