VYPR

CVEs

105,912 total · page 1125 of 2,119

  • CVE-2022-44635HigNov 29, 2022
    risk 0.63cvss 8.8epss 0.69

    Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. This issue affects Apache Fineract version 1.8.0 and prior versions. We…

  • CVE-2022-45329HigNov 29, 2022
    risk 0.49cvss 7.5epss 0.01

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Search parameter. This vulnerability allows attackers to access database information.

  • CVE-2022-43326HigNov 29, 2022
    risk 0.49cvss 7.5epss 0.01

    An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node 1.0.0-1.4.[*] allows attackers to arbitrarily change user and Administrator account passwords.

  • CVE-2022-41568HigNov 29, 2022
    risk 0.49cvss 7.5epss 0.01

    LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.

  • CVE-2022-40799HigKEVNov 29, 2022
    risk 0.72cvss 8.8epss 0.32

    Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.

  • CVE-2022-45202HigNov 29, 2022
    risk 0.51cvss 7.8epss 0.00

    GPAC v2.1-DEV-rev428-gcb8ae46c8-master was discovered to contain a stack overflow via the function dimC_box_read at isomedia/box_code_3gpp.c.

  • CVE-2022-44037HigNov 29, 2022
    risk 0.57cvss 8.8epss 0.01

    An access control issue in APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software V4.1NA, V3.11.4, W2.1NA, V4.1SAA, C1.2.2 allows attackers to access sensitive data and execute specific commands and functions with full admin rights without authenticating allows him…

  • CVE-2022-41675HigNov 29, 2022
    risk 0.52cvss 8.0epss 0.01

    A remote attacker with general user privilege can inject malicious code in the form content of Raiden MAILD Mail Server website. Other users export form content as CSV file can trigger arbitrary code execution and allow the attacker to perform arbitrary system operation or…

  • CVE-2022-3088HigNov 28, 2022
    risk 0.51cvss 7.8epss 0.00

    UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image: Versions v1.0 to v 1.12, UC-3100 System Image: Versions v1.0 to v1.6, UC-5100 System Image: Versions v1.0 to v1.4, UC-8100 System Image: Versions…

  • CVE-2022-24190HigNov 28, 2022
    risk 0.49cvss 7.5epss 0.01

    The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is not implemented or present on this end-point. An attacker can send a request to bind their account to any users picture frame, then send a…

  • CVE-2022-24188HigNov 28, 2022
    risk 0.49cvss 7.5epss 0.00

    The /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functionality within the picture frame devices. The deviceVideoCallPassword and mqttPassword are returned in clear-text. The lack of sessions management and presence of…

  • CVE-2022-24187HigNov 28, 2022
    risk 0.49cvss 7.5epss 0.01

    The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from insecure direct object reference vulnerabilities. Other end-users user_id and device_id values can be enumerated by incrementing or decrementing id numbers. The impact of this…

  • CVE-2022-46147HigNov 28, 2022
    risk 0.48cvss 8.4epss 0.01

    Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0.0 are vulnerable to cross-site scripting in multiple XBlock Fields. Any platform that has deployed the XBlock may be impacted.…

  • CVE-2022-45921HigNov 28, 2022
    risk 0.49cvss 7.5epss 0.01

    FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be specific, an attacker may be able to view or retrieve any file readable by the user running the FusionAuth process.

  • CVE-2022-45442HigNov 28, 2022
    risk 0.50cvss 8.8epss 0.01

    Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response…

  • CVE-2022-38140HigNov 28, 2022
    risk 0.49cvss 7.6epss 0.01

    Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress.

  • CVE-2021-45036HigNov 28, 2022
    risk 0.57cvss 8.7epss 0.01

    Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's username and hashed password to spoof the victim's id against the server.

  • CVE-2022-41957HigNov 28, 2022
    risk 0.42cvss 7.5epss 0.01

    Muhammara is a node module with c/cpp bindings to modify PDF with JavaScript for node or electron. The package muhammara before 2.6.2 and from 3.0.0 and before 3.3.0, as well as all versions of muhammara's predecessor package hummus, are vulnerable to Denial of Service (DoS)…

  • CVE-2022-31877HigNov 28, 2022
    risk 0.57cvss 8.8epss 0.00

    An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.

  • CVE-2022-3865HigNov 28, 2022
    risk 0.57cvss 8.8epss 0.01

    The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin

  • CVE-2022-3849HigNov 28, 2022
    risk 0.57cvss 8.8epss 0.01

    The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin

  • CVE-2022-3848HigNov 28, 2022
    risk 0.57cvss 8.8epss 0.01

    The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin

  • CVE-2022-3769HigNov 28, 2022
    risk 0.57cvss 8.8epss 0.01

    The OWM Weather WordPress plugin before 5.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as contributor

  • CVE-2022-3768HigNov 28, 2022
    risk 0.57cvss 8.8epss 0.04

    The WPSmartContracts WordPress plugin before 1.3.12 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author

  • CVE-2022-3689HigNov 28, 2022
    risk 0.47cvss 7.2epss 0.02

    The HTML Forms WordPress plugin before 1.3.25 does not properly properly escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users

  • CVE-2022-3490HigNov 28, 2022
    risk 0.47cvss 7.2epss 0.01

    The Checkout Field Editor (Checkout Manager) for WooCommerce WordPress plugin before 1.8.0 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present

  • CVE-2022-4020HigNov 28, 2022
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the HQSwSmiDxe DXE driver on some consumer Acer Notebook devices may allow an attacker with elevated privileges to modify UEFI Secure Boot settings by modifying an NVRAM variable.

  • CVE-2022-38900HigNov 28, 2022
    risk 0.44cvss 7.5epss 0.25

    decode-uri-component 0.2.0 is vulnerable to Improper Input Validation resulting in DoS.

  • CVE-2022-45939HigNov 28, 2022
    risk 0.51cvss 7.8epss 0.01

    GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may use the "ctags *" command…

  • CVE-2022-45934HigNov 27, 2022
    risk 0.00cvss 7.8epss 0.01

    An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.

  • CVE-2022-45932HigNov 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/RoleStore.java deleteRole function is affected when the API interface /auth/v1/roles/ is used.

  • CVE-2022-45931HigNov 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/UserStore.java deleteUser function is affected when the API interface /auth/v1/users/ is used.

  • CVE-2022-45930HigNov 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A SQL injection issue was discovered in AAA in OpenDaylight (ODL) before 0.16.5. The aaa-idm-store-h2/src/main/java/org/opendaylight/aaa/datastore/h2/DomainStore.java deleteDomain function is affected for the /auth/v1/domains/ API interface.

  • CVE-2022-45919HigNov 27, 2022
    risk 0.00cvss 7.0epss 0.00

    An issue was discovered in the Linux kernel through 6.0.10. In drivers/media/dvb-core/dvb_ca_en50221.c, a use-after-free can occur is there is a disconnect after an open, because of the lack of a wait_event.

  • CVE-2022-24999HigNov 26, 2022
    risk 0.43cvss 7.5epss 0.15

    qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack…

  • CVE-2022-41158HigNov 25, 2022
    risk 0.47cvss 7.2epss 0.02

    Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A remote attacker could exploit the vulnerability to execute or inject malicious code.

  • CVE-2022-41157HigNov 25, 2022
    risk 0.53cvss 8.1epss 0.01

    A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vulnerability could allow attackers to leak or steal sensitive information or execute malicious commands.

  • CVE-2022-41156HigNov 25, 2022
    risk 0.51cvss 7.8epss 0.00

    Remote code execution vulnerability due to insufficient verification of URLs, etc. in OndiskPlayerAgent. A remote attacker could exploit the vulnerability to cause remote code execution by causing an arbitrary user to download and execute malicious code.

  • CVE-2022-44860HigNov 25, 2022
    risk 0.47cvss 7.2epss 0.01

    Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/transactions/update_status.php.

  • CVE-2022-44859HigNov 25, 2022
    risk 0.47cvss 7.2epss 0.01

    Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/admin/products/manage_product.php.

  • CVE-2022-44858HigNov 25, 2022
    risk 0.47cvss 7.2epss 0.01

    Automotive Shop Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /asms/products/view_product.php.

  • CVE-2022-41958HigNov 25, 2022
    risk 0.00cvss 7.3epss 0.00

    super-xray is a web vulnerability scanning tool. Versions prior to 0.7 assumed trusted input for the program config which is stored in a yaml file. An attacker with local access to the file could exploit this and compromise the program. This issue has been addressed in commit…

  • CVE-2022-41706HigNov 25, 2022
    risk 0.46cvss 8.2epss 0.01

    Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.

  • CVE-2022-43984HigNov 25, 2022
    risk 0.46cvss 8.2epss 0.01

    Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content imported from an external source passed to the Browsershot::html method does not contain URLs that use…

  • CVE-2022-43983HigNov 25, 2022
    risk 0.46cvss 8.2epss 0.01

    Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the HTML content passed to the Browsershot::html method does not contain URL's that use the file:// protocol.

  • CVE-2022-38813HigNov 25, 2022
    risk 0.53cvss 8.1epss 0.01

    PHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, delete the users, add and manage Blood Group, and Submit Report.

  • CVE-2022-23044HigNov 25, 2022
    risk 0.57cvss 8.8epss 0.00

    Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application. This is possible because the application is vulnerable to CSRF.

  • CVE-2022-45039HigNov 25, 2022
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in the Server Settings module of WBCE CMS v1.5.4 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-44411HigNov 25, 2022
    risk 0.49cvss 7.5epss 0.00

    Web Based Quiz System v1.0 transmits user passwords in plaintext during the authentication process, allowing attackers to obtain users' passwords via a bruteforce attack.

  • CVE-2022-38767HigNov 25, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Wind River VxWorks 6.9 and 7, that allows a specifically crafted packet sent by a Radius server, may cause Denial of Service during the IP Radius access procedure.