VYPR

CVEs

105,912 total · page 1128 of 2,119

  • CVE-2022-42459HigNov 18, 2022
    risk 0.47cvss 7.2epss 0.01

    Auth. WordPress Options Change vulnerability in Image Hover Effects Ultimate plugin <= 9.7.1 on WordPress.

  • CVE-2022-38871HigNov 18, 2022
    risk 0.49cvss 7.5epss 0.01

    In Free5gc v3.0.5, the AMF breaks due to malformed NAS messages.

  • CVE-2022-31694HigNov 18, 2022
    risk 0.47cvss 7.3epss 0.00

    InstallBuilder Qt installers built with versions previous to 22.10 try to load DLLs from the installer binary parent directory when displaying popups. This may allow an attacker to plant a malicious DLL in the installer parent directory to allow executing code with the…

  • CVE-2021-33621HigNov 18, 2022
    risk 0.57cvss 8.8epss 0.02

    The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.

  • CVE-2022-41900HigNov 18, 2022
    risk 0.39cvss 7.1epss 0.01

    TensorFlow is an open source platform for machine learning. The security vulnerability results in FractionalMax(AVG)Pool with illegal pooling_ratio. Attackers using Tensorflow can exploit the vulnerability. They can access heap memory which is not in the control of user, leading…

  • CVE-2022-41894HigNov 18, 2022
    risk 0.39cvss 7.1epss 0.01

    TensorFlow is an open source platform for machine learning. The reference kernel of the `CONV_3D_TRANSPOSE` TensorFlow Lite operator wrongly increments the data_ptr when adding the bias to the result. Instead of `data_ptr += num_channels;` it should be `data_ptr +=…

  • CVE-2022-42904HigNov 18, 2022
    risk 0.47cvss 7.2epss 0.83

    Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.

  • CVE-2022-37197HigNov 18, 2022
    risk 0.54cvss 7.8epss 0.01

    IOBit IOTransfer V4 is vulnerable to Unquoted Service Path.

  • CVE-2022-44820HigNov 18, 2022
    risk 0.47cvss 7.2epss 0.01

    Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=transactions/manage_transaction&id=.

  • CVE-2022-44415HigNov 18, 2022
    risk 0.47cvss 7.2epss 0.01

    Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/mechanics/view_mechanic.php?id=.

  • CVE-2022-44414HigNov 18, 2022
    risk 0.47cvss 7.2epss 0.01

    Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/services/manage_service.php?id=.

  • CVE-2022-44413HigNov 18, 2022
    risk 0.47cvss 7.2epss 0.01

    Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/mechanics/manage_mechanic.php?id=.

  • CVE-2022-41840HigNov 18, 2022
    risk 0.49cvss 7.5epss 0.05

    Unauth. Directory Traversal vulnerability in Welcart eCommerce plugin <= 2.7.7 on WordPress.

  • CVE-2022-44379HigNov 18, 2022
    risk 0.47cvss 7.2epss 0.01

    Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_service.

  • CVE-2022-44378HigNov 18, 2022
    risk 0.47cvss 7.2epss 0.01

    Automotive Shop Management System v1.0 is vulnerable to SQL via /asms/classes/Master.php?f=delete_mechanic.

  • CVE-2022-24037HigNov 18, 2022
    risk 0.53cvss 8.2epss 0.01

    Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to obtain critical information.

  • CVE-2022-43308HigNov 18, 2022
    risk 0.51cvss 7.8epss 0.00

    INTELBRAS SG 2404 MR 20180928-rel64938 allows authenticated attackers to arbitrarily create Administrator accounts via crafted user cookies.

  • CVE-2022-43506HigNov 17, 2022
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in HandlerTag_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

  • CVE-2022-43457HigNov 17, 2022
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in HandlerPage_KID.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

  • CVE-2022-43452HigNov 17, 2022
    risk 0.58cvss 8.8epss 0.08

    SQL Injection in FtyInfoSetting.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

  • CVE-2022-43447HigNov 17, 2022
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in AM_EBillAnalysis.aspx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

  • CVE-2022-42533HigNov 17, 2022
    risk 0.51cvss 7.8epss 0.00

    In shared_metadata_init of SharedMetadata.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-41775HigNov 17, 2022
    risk 0.57cvss 8.8epss 0.01

    SQL Injection in Handler_CFG.ashx in Delta Electronics DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries via Network

  • CVE-2022-40192HigNov 17, 2022
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.

  • CVE-2022-39179HigNov 17, 2022
    risk 0.47cvss 7.2epss 0.01

    College Management System v1.0 - Authenticated remote code execution. An admin user (the authentication can be bypassed using SQL Injection that mentioned in my other report) can upload .php file that contains malicious code via student.php file.

  • CVE-2022-36924HigNov 17, 2022
    risk 0.57cvss 8.8epss 0.00

    The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to the SYSTEM user.

  • CVE-2022-36785HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.02

    D-Link – G integrated Access Device4 Information Disclosure & Authorization Bypass. *Information Disclosure – file contains a URL with private IP at line 15 "login.asp" A. The window.location.href = http://192.168.1.1/setupWizard.asp" http://192.168.1.1/setupWizard.asp" ;…

  • CVE-2022-28768HigNov 17, 2022
    risk 0.57cvss 8.8epss 0.00

    The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to root.

  • CVE-2022-23748HigKEVNov 17, 2022
    risk 0.63cvss 7.8epss 0.09

    mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files.

  • CVE-2022-44725HigNov 17, 2022
    risk 0.51cvss 7.8epss 0.00

    OPC Foundation Local Discovery Server (LDS) through 1.04.403.478 uses a hard-coded file path to a configuration file. This allows a normal user to create a malicious file that is loaded by LDS (running as a high-privilege user).

  • CVE-2022-3090HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Red Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson 3.1 versions 3126.001 and prior, and Crimson 3.2 versions 3.2.0044.0 and prior are vulnerable to path traversal. When attempting to open a file using a specific path, the user's password hash is sent to an…

  • CVE-2022-39389HigNov 17, 2022
    risk 0.46cvss 8.2epss 0.01

    Lightning Network Daemon (lnd) is an implementation of a lightning bitcoin overlay network node. All lnd nodes before version `v0.15.4` are vulnerable to a block parsing bug that can cause a node to enter a degraded state once encountered. In this degraded state, nodes can…

  • CVE-2022-43183HigNov 17, 2022
    risk 0.50cvss 8.8epss 0.02

    XXL-Job before v2.3.1 contains a Server-Side Request Forgery (SSRF) via the component /admin/controller/JobLogController.java.

  • CVE-2022-43179HigNov 17, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Leave Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/?page=user/manage_user&id=.

  • CVE-2022-43163HigNov 17, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /clients/view_client.php.

  • CVE-2022-43162HigNov 17, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tests/view_test.php.

  • CVE-2022-44403HigNov 17, 2022
    risk 0.47cvss 7.2epss 0.01

    Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/admin/?page=user/manage_user&id=.

  • CVE-2022-44402HigNov 17, 2022
    risk 0.47cvss 7.2epss 0.01

    Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_transaction.

  • CVE-2022-44384HigNov 17, 2022
    risk 0.61cvss 8.8epss 0.05

    An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-43140HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.02

    kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the application to make arbitrary requests via injection of crafted URLs…

  • CVE-2022-42894HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). An unauthenticated Server-Side Request Forgery (SSRF) vulnerability was identified in one of the web services exposed on the syngo Dynamics application that could allow for the leaking of NTLM…

  • CVE-2022-42893HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the…

  • CVE-2022-42891HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the…

  • CVE-2022-42734HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the…

  • CVE-2022-42733HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned…

  • CVE-2022-42732HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned…

  • CVE-2022-45461HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root.

  • CVE-2022-42982HigNov 17, 2022
    risk 0.49cvss 7.5epss 0.01

    BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quite long (tens of kBs) and can be requested with a packet of only 30 bytes. This presents a vector that can be used for UDP…

  • CVE-2022-42246HigNov 17, 2022
    risk 0.57cvss 8.8epss 0.00

    Doufox 0.0.4 contains a CSRF vulnerability that can add system administrator account.

  • CVE-2021-38819HigNov 17, 2022
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exits on the Simple Image Gallery System 1.0 application through "id" parameter on the album page.