VYPR

CVEs

105,912 total · page 1127 of 2,119

  • CVE-2022-39066HigNov 22, 2022
    risk 0.59cvss 8.8epss 0.27

    There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to execute arbitrary SQL injection.

  • CVE-2022-33012HigNov 22, 2022
    risk 0.57cvss 8.8epss 0.01

    Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.

  • CVE-2022-42098HigNov 22, 2022
    risk 0.57cvss 8.8epss 0.01

    KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php.

  • CVE-2022-3910HigNov 22, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free vulnerability in Linux Kernel allows Privilege Escalation. An improper Update of Reference Count in io_uring leads to Use-After-Free and Local Privilege Escalation. When io_msg_ring was invoked with a fixed file, it called io_fput_file() which improperly decreased…

  • CVE-2022-0222HigNov 22, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. Affected products: Modicon M340 CPUs(BMXP34* versions prior to V3.40), Modicon M340 X80…

  • CVE-2022-37301HigNov 22, 2022
    risk 0.49cvss 7.5epss 0.01

    A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access violations when using the Modbus TCP protocol. Affected products: Modicon M340 CPU (part numbers BMXP34*)(V3.40 and prior), Modicon…

  • CVE-2022-2513HigNov 22, 2022
    risk 0.46cvss 7.1epss 0.00

    A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage function in Hitachi Energy’s PCM600 product included in the versions listed below, where IEDs credentials are stored in a cleartext format in the PCM600…

  • CVE-2022-41131HigNov 22, 2022
    risk 0.44cvss 7.8epss 0.02

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without write access to DAG files. This issue…

  • CVE-2022-37931HigNov 22, 2022
    risk 0.47cvss 7.3epss 0.00

    A vulnerability in NetBatch-Plus software allows unauthorized access to the application.  HPE has provided a workaround and fix. Please refer to HPE Security Bulletin HPESBNS04388 for details.

  • CVE-2022-35407HigNov 22, 2022
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SetupUtility driver on Intel platforms. An attacker can change the values of certain UEFI variables. If the size of the second variable…

  • CVE-2022-43685HigNov 22, 2022
    risk 0.57cvss 8.8epss 0.01

    CKAN through 2.9.6 account takeovers by unauthenticated users when an existing user id is sent via an HTTP POST request. This allows a user to take over an existing account including superuser accounts.

  • CVE-2022-41940HigNov 22, 2022
    risk 0.39cvss 7.1epss 0.02

    Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the…

  • CVE-2022-30529HigNov 22, 2022
    risk 0.47cvss 7.2epss 0.01

    File upload vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to upload arbitrary files via /system/application/libs/js/tinymce/plugins/filemanager/dialog.php and /system/application/libs/js/tinymce/plugins/filemanager/up…

  • CVE-2022-44786HigNov 21, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Appalti & Contratti 9.12.2. The target web applications allow Local File Inclusion in any page relying on the href parameter to specify the JSP page to be rendered. This affects ApriPagina.do POST and GET requests to each application.

  • CVE-2022-44784HigNov 21, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Appalti & Contratti 9.12.2. The target web applications LFS and DL229 expose a set of services provided by the Axis 1.4 instance, embedded directly into the applications, as hinted by the WEB-INF/web.xml file leaked through Local File Inclusion. Among…

  • CVE-2022-3388HigNov 21, 2022
    risk 0.57cvss 8.8epss 0.00

    An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.

  • CVE-2022-44830HigNov 21, 2022
    risk 0.51cvss 7.8epss 0.01

    Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.

  • CVE-2022-40746HigNov 21, 2022
    risk 0.47cvss 7.2epss 0.00

    IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised folder, an attacker…

  • CVE-2022-45422HigNov 21, 2022
    risk 0.51cvss 7.8epss 0.00

    When LG SmartShare is installed, local privilege escalation is possible through DLL Hijacking attack. The LG ID is LVE-HOT-220005.

  • CVE-2022-45470HigNov 21, 2022
    risk 0.49cvss 7.5epss 0.01

    missing input validation in Apache Hama may cause information disclosure through path traversal and XSS. Since Apache Hama is EOL, we do not expect these issues to be fixed.

  • CVE-2022-44163HigNov 21, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.

  • CVE-2022-44158HigNov 21, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC21 V16.03.08.15 is vulnerable to Buffer Overflow via function via set_device_name.

  • CVE-2022-44156HigNov 21, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetIpMacBind.

  • CVE-2022-40129HigNov 21, 2022
    risk 0.51cvss 7.8epss 0.01

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigger the reuse of previously freed memory via misusing Optional Content Group API, which can lead to arbitrary code…

  • CVE-2022-38148HigNov 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Silverstripe silverstripe/framework through 4.11 allows SQL Injection.

  • CVE-2022-38097HigNov 21, 2022
    risk 0.51cvss 7.8epss 0.01

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely destroying annotation objects, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code…

  • CVE-2022-37332HigNov 21, 2022
    risk 0.51cvss 7.8epss 0.01

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigger the reuse of previously freed memory via misusing media player API, which can lead to arbitrary code execution. An…

  • CVE-2022-32774HigNov 21, 2022
    risk 0.51cvss 7.8epss 0.01

    A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely deleting objects associated with pages, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to…

  • CVE-2022-44169HigNov 21, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC15 V15.03.05.18 is vulnerable to Buffer Overflow via function formSetVirtualSer.

  • CVE-2022-44168HigNov 21, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC15 V15.03.05.18 is vulnerable to Buffer Overflow via function fromSetRouteStatic..

  • CVE-2022-44167HigNov 21, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC15 V15.03.05.18 is avulnerable to Buffer Overflow via function formSetPPTPServer.

  • CVE-2022-3861HigNov 21, 2022
    risk 0.57cvss 8.8epss 0.02

    The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via deserialization of untrusted input supplied via the import, mfn-items-import-page, and mfn-items-import parameters passed through the mfn_builder_import,…

  • CVE-2022-3763HigNov 21, 2022
    risk 0.53cvss 8.1epss 0.00

    The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not have CSRF check in place when deleting files uploaded at the checkout, allowing attackers to…

  • CVE-2022-3720HigNov 21, 2022
    risk 0.47cvss 7.2epss 0.01

    The Event Monster WordPress plugin before 1.2.0 does not validate and escape some parameters before using them in SQL statements, which could lead to SQL Injection exploitable by high privilege users

  • CVE-2022-3691HigNov 21, 2022
    risk 0.49cvss 7.5epss 0.01

    The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.

  • CVE-2022-3688HigNov 21, 2022
    risk 0.57cvss 8.8epss 0.00

    The WPQA Builder WordPress plugin before 5.9 does not have CSRF check when following and unfollowing users, which could allow attackers to make logged in users perform such actions via CSRF attacks

  • CVE-2022-1579HigNov 21, 2022
    risk 0.49cvss 7.5epss 0.01

    The function check_is_login_page() uses headers for the IP check, which can be easily spoofed.

  • CVE-2022-1578HigNov 21, 2022
    risk 0.57cvss 8.8epss 0.00

    The My wpdb WordPress plugin before 2.5 is missing CSRF check when running SQL queries, which could allow attacker to make a logged in admin run arbitrary SQL query via a CSRF attack

  • CVE-2022-3589HigNov 21, 2022
    risk 0.53cvss 8.1epss 0.01

    An API Endpoint used by Miele's "AppWash" MobileApp in all versions was vulnerable to an authorization bypass. A low privileged, remote attacker would have been able to gain read and partial write access to other users data by modifying a small part of a HTTP request sent to the…

  • CVE-2022-3525HigNov 20, 2022
    risk 0.50cvss 8.8epss 0.01

    Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0.

  • CVE-2022-4055HigNov 19, 2022
    risk 0.48cvss 7.4epss 0.01

    When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but…

  • CVE-2022-31617HigNov 19, 2022
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a local user with basic capabilities can cause an out-of-bounds read, which may lead to code execution, denial of service, escalation of privileges, information…

  • CVE-2022-31613HigNov 19, 2022
    risk 0.46cvss 7.1epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where any local user can cause a null-pointer dereference, which may lead to a kernel panic.

  • CVE-2022-31612HigNov 19, 2022
    risk 0.46cvss 7.1epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a local user with basic capabilities can cause an out-of-bounds read, which may lead to a system crash or a leak of internal kernel information.

  • CVE-2022-31610HigNov 19, 2022
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a local user with basic capabilities can cause an out-of-bounds write, which may lead to code execution, denial of service, escalation of privileges, information…

  • CVE-2022-31608HigNov 19, 2022
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability in an optional D-Bus configuration file, where a local user with basic capabilities can impact protected D-Bus endpoints, which may lead to code execution, denial of service, escalation of privileges, information…

  • CVE-2022-31607HigNov 19, 2022
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where a local user with basic capabilities can cause improper input validation, which may lead to denial of service, escalation of privileges, data tampering, and limited…

  • CVE-2022-31606HigNov 19, 2022
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a failure to properly validate data might allow an attacker with basic user capabilities to cause an out-of-bounds access in kernel mode, which…

  • CVE-2022-30256HigNov 19, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in MaraDNS Deadwood through 3.5.0021 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would be…

  • CVE-2022-44583HigNov 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.