VYPR

CVEs

105,912 total · page 1126 of 2,119

  • CVE-2022-38166HigNov 25, 2022
    risk 0.49cvss 7.5epss 0.01

    In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dll unpacker handler crashes. This can lead to a scanning engine crash, triggerable remotely by an attacker for denial of service.

  • CVE-2022-4141HigNov 25, 2022
    risk 0.00cvss 7.8epss 0.00

    Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

  • CVE-2022-40282HigNov 25, 2022
    risk 0.58cvss 8.8epss 0.04

    The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authenticated attacker to pass commands to the shell of the system because the dir parameter of the FsCreateDir Ajax function is not sufficiently sanitized. The…

  • CVE-2022-2721HigNov 25, 2022
    risk 0.49cvss 7.5epss 0.01

    In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plaint-text in when verbose logging is enabled.

  • CVE-2022-45886HigNov 25, 2022
    risk 0.00cvss 7.0epss 0.00

    An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_net.c has a .disconnect versus dvb_device_open race condition that leads to a use-after-free.

  • CVE-2022-45885HigNov 25, 2022
    risk 0.00cvss 7.0epss 0.00

    An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvb_frontend.c has a race condition that can cause a use-after-free when a device is disconnected.

  • CVE-2022-45884HigNov 25, 2022
    risk 0.00cvss 7.0epss 0.00

    An issue was discovered in the Linux kernel through 6.0.9. drivers/media/dvb-core/dvbdev.c has a use-after-free, related to dvb_register_device dynamically allocating fops.

  • CVE-2022-29831HigNov 25, 2022
    risk 0.49cvss 7.5epss 0.01

    Use of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from 1.015R to 1.095Z allows a remote unauthenticated attacker to obtain information about the project file for MELSEC safety CPU modules.

  • CVE-2022-25164HigNov 25, 2022
    risk 0.56cvss 8.6epss 0.01

    Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z and Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior allows a remote unauthenticated attacker to disclose sensitive information.…

  • CVE-2022-26885HigNov 24, 2022
    risk 0.42cvss 7.5epss 0.01

    When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher.

  • CVE-2022-4088HigNov 24, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument user/password leads to sql injection. The attack may be launched…

  • CVE-2022-40977HigNov 24, 2022
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability was discovered in Pilz PASvisu Server before 1.12.0. An unauthenticated remote attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability.

  • CVE-2022-44748HigNov 24, 2022
    risk 0.46cvss 7.1epss 0.01

    A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Server since 4.3.0 can result in arbitrary files being overwritten on the server's file system. This vulnerability is also known as 'Zip-Slip'. An attacker can create a KNIME workflow that,…

  • CVE-2022-45868HigNov 23, 2022
    risk 0.48cvss 8.4epss 0.00

    The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the web admin console. Consequently, a local user (or an attacker that has obtained…

  • CVE-2022-45278HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component.

  • CVE-2022-44789HigNov 23, 2022
    risk 0.00cvss 8.8epss 0.02

    A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.

  • CVE-2022-41932HigNov 23, 2022
    risk 0.49cvss 7.5epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make XWiki create many new schemas and fill them with tables just by using a crafted user identifier in the login form. This may lead to degraded database…

  • CVE-2022-44140HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component.

  • CVE-2021-29334HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in JIZHI CMS 1.9.4. There is a CSRF vulnerability that can add an admin account via index, /admin.php/Admin/adminadd.html

  • CVE-2022-41930HigNov 23, 2022
    risk 0.42cvss 7.5epss 0.01

    org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged in or not) with access to the page XWiki.XWikiUserProfileSheet can enable or disable any user profile. This might allow to a disabled user to re-enable…

  • CVE-2022-41927HigNov 23, 2022
    risk 0.41cvss 7.4epss 0.00

    XWiki Platform is vulnerable to Cross-Site Request Forgery (CSRF) that may allow attackers to delete or rename tags without needing any confirmation. The problem has been patched in XWiki 13.10.7, 14.4.1 and 14.5RC1. Workarounds: It's possible to patch existing instances…

  • CVE-2022-41925HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability identified in the Tailscale client allows a malicious website to access the peer API, which can then be used to access Tailscale environment variables. In the Tailscale client, the peer API was vulnerable to DNS rebinding. This allowed an attacker-controlled…

  • CVE-2021-43258HigNov 23, 2022
    risk 0.04cvss 8.8epss 0.11

    CartView.php in ChurchInfo 1.3.0 allows attackers to achieve remote code execution through insecure uploads. This requires authenticated access tot he ChurchInfo application. Once authenticated, a user can add names to their cart, and compose an email. Uploading an attachment…

  • CVE-2022-41922HigNov 23, 2022
    risk 0.46cvss 8.1epss 0.01

    `yiisoft/yii` before version 1.1.27 are vulnerable to Remote Code Execution (RCE) if the application calls `unserialize()` on arbitrary user input. This has been patched in 1.1.27.

  • CVE-2022-40304HigNov 23, 2022
    risk 0.01cvss 7.8epss 0.07

    An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.

  • CVE-2022-39833HigNov 23, 2022
    risk 0.47cvss 7.2epss 0.03

    FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API endpoints via a crafted HTTP request.

  • CVE-2022-23740HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.01

    CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. To exploit this vulnerability, an attacker would need permission to create and build GitHub Pages using GitHub…

  • CVE-2009-1143HigNov 23, 2022
    risk 0.46cvss 7.0epss 0.00

    An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mounting shares via a symlink attack that leverages a realpath race condition in mount.vmhgfs (aka hgfsmounter).

  • CVE-2022-44278HigNov 23, 2022
    risk 0.47cvss 7.2epss 0.01

    Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=user/manage_user&id=.

  • CVE-2022-44260HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter sPort/ePort in the setIpPortFilterRules function.

  • CVE-2022-44259HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter week, sTime, and eTime in the setParentalRules function.

  • CVE-2022-44258HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function.

  • CVE-2022-44257HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.

  • CVE-2022-44256HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function.

  • CVE-2022-44254HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function.

  • CVE-2022-44253HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter ip in the setDiagnosisCfg function.

  • CVE-2022-42896HigNov 23, 2022
    risk 0.00cvss 8.0epss 0.02

    There are use-after-free vulnerabilities in the Linux kernel's net/bluetooth/l2cap_core.c's l2cap_connect and l2cap_le_connect_req functions which may allow code execution and leaking kernel memory (respectively) remotely via Bluetooth. A remote attacker could execute code…

  • CVE-2021-46854HigNov 23, 2022
    risk 0.00cvss 7.5epss 0.01

    mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.

  • CVE-2022-40770HigNov 23, 2022
    risk 0.53cvss 7.2epss 0.83

    Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.

  • CVE-2022-36337HigNov 23, 2022
    risk 0.53cvss 8.2epss 0.00

    An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitrary code execution. Control of a UEFI variable under the OS can cause this overflow when read by BIOS code.

  • CVE-2022-34830HigNov 23, 2022
    risk 0.49cvss 7.5epss 0.01

    An Arm product family through 2022-06-29 has a TOCTOU Race Condition that allows non-privileged user to make improper GPU processing operations to gain access to already freed memory.

  • CVE-2022-37772HigNov 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Maarch RM 2.8.3 solution contains an improper restriction of excessive authentication attempts due to excessive verbose responses from the application. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compromised accounts.

  • CVE-2020-23592HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to Reset ONU to Factory Default through ' /mgm_dev_reset.asp.' Resetting to…

  • CVE-2020-23585HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.01

    A remote attacker can conduct a cross-site request forgery (CSRF) attack on OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028. The vulnerability is due to insufficient CSRF protections for the "mgm_config_file.asp" because of which attacker can…

  • CVE-2022-43751HigNov 23, 2022
    risk 0.51cvss 7.8epss 0.00

    McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to a subdirectory that may be controllable by an unprivileged user. This may have allowed the unprivileged user to execute arbitrary…

  • CVE-2022-40870HigNov 23, 2022
    risk 0.53cvss 8.1epss 0.01

    The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnerability allows attackers to execute arbitrary commands via a crafted payload injected into the Host header.

  • CVE-2022-40303HigNov 23, 2022
    risk 0.02cvss 7.5epss 0.23

    An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a…

  • CVE-2022-45331HigNov 22, 2022
    risk 0.49cvss 7.5epss 0.01

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the p_id parameter at \post.php. This vulnerability allows attackers to access database information.

  • CVE-2022-45330HigNov 22, 2022
    risk 0.49cvss 7.5epss 0.01

    AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the Category parameter at \category.php. This vulnerability allows attackers to access database information.

  • CVE-2022-41942HigNov 22, 2022
    risk 0.51cvss 7.9epss 0.02

    Sourcegraph is a code intelligence platform. In versions prior to 4.1.0 a command Injection vulnerability existed in the gitserver service, present in all Sourcegraph deployments. This vulnerability was caused by a lack of input validation on the host parameter of the…