VYPR

CVEs

103,466 total · page 1129 of 2,070

  • CVE-2022-27493HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper initialization in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable an escalation of privilege via local access.

  • CVE-2022-37768HigAug 18, 2022
    risk 0.49cvss 7.5epss 0.01

    libjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer.

  • CVE-2022-37049HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE: this is different from CVE-2022-27942.

  • CVE-2022-37048HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. NOTE: this is different from CVE-2022-27941.

  • CVE-2022-37047HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. NOTE: this is different from CVE-2022-27940.

  • CVE-2022-30296HigAug 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Insufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an unauthenticated user to potentially enable information disclosure via network access.

  • CVE-2022-28757HigAug 18, 2022
    risk 0.57cvss 8.8epss 0.00

    The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.6 contains a vulnerability in the auto update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

  • CVE-2022-28696HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in the Intel(R) Distribution for Python before version 2022.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-26844HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Insufficiently protected credentials in the installation binaries for Intel(R) SEAPI in all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-26374HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-26344HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-26017HigAug 18, 2022
    risk 0.52cvss 8.0epss 0.00

    Improper access control in the Intel(R) DSA software for before version 22.2.14 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2022-25999HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path element in the Intel(R) Enpirion(R) Digital Power Configurator GUI software, all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-25966HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper access control in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-25841HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path elements in the Intel(R) Datacenter Group Event Android application, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-23182HigAug 18, 2022
    risk 0.57cvss 8.8epss 0.00

    Improper access control in the Intel(R) Data Center Manager software before version 4.1 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2022-21812HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper access control in the Intel(R) HAXM software before version 7.7.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-21807HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Uncontrolled search path elements in the Intel(R) VTune(TM) Profiler software before version 2022.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-21229HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper buffer restrictions for some Intel(R) NUC 9 Extreme Laptop Kit drivers before version 2.2.0.22 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-21225HigAug 18, 2022
    risk 0.52cvss 8.0epss 0.02

    Improper neutralization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2022-21197HigAug 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via network access.

  • CVE-2022-21181HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-21160HigAug 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via network access.

  • CVE-2022-21148HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper access control in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-21139HigAug 18, 2022
    risk 0.57cvss 8.8epss 0.00

    Inadequate encryption strength for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2021-37409HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-33847HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33060HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-23223HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper initialization for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-23179HigAug 18, 2022
    risk 0.46cvss 7.1epss 0.00

    Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2022-37422HigAug 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Payara through 5.2022.2 allows directory traversal without authentication. This affects Payara Server, Payara Micro, and Payara Server Embedded.

  • CVE-2022-2625HigAug 18, 2022
    risk 0.52cvss 8.0epss 0.02

    A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a…

  • CVE-2021-32862HigAug 18, 2022
    risk 0.49cvss 7.5epss 0.01

    The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS)…

  • CVE-2022-37062HigAug 18, 2022
    risk 0.49cvss 7.5epss 0.03

    All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains the path of the SQLite…

  • CVE-2022-37060HigAug 18, 2022
    risk 0.50cvss 7.5epss 0.15

    FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains directory traversal characters to disclose the…

  • CVE-2022-36023HigAug 18, 2022
    risk 0.39cvss 7.0epss 0.01

    Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. If a gateway client application sends a malformed request to a gateway peer it may crash the peer node. Version 2.4.6 checks for the malformed gateway…

  • CVE-2022-36024HigAug 18, 2022
    risk 0.42cvss 7.5epss 0.01

    py-cord is a an API wrapper for Discord written in Python. Bots creating using py-cord version 2.0.0 are vulnerable to remote shutdown if they are added to the server with the `application.commands` scope without the `bot` scope. Currently, it appears that all public bots that…

  • CVE-2022-37025HigAug 18, 2022
    risk 0.51cvss 7.8epss 0.00

    An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and being…

  • CVE-2022-29549HigAug 18, 2022
    risk 0.47cvss 7.3epss 0.00

    An issue was discovered in Qualys Cloud Agent 4.8.0-49. It executes programs at various full pathnames without first making ownership and permission checks (e.g., to help ensure that a program was installed by root) and without integrity checks (e.g., a checksum comparison…

  • CVE-2022-35198HigAug 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Contract Management System v2.0 contains a weak default password which gives attackers to access database connection information.

  • CVE-2022-35173HigAug 18, 2022
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in Nginx NJS v0.7.5. The JUMP offset for a break instruction was not set to a correct offset during code generation, leading to a segmentation violation.

  • CVE-2021-30070HigAug 18, 2022
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in HestiaCP before v1.3.5. Attackers are able to arbitrarily install packages due to values taken from the pgk [] parameter in the update request being transmitted to the operating system's package manager.

  • CVE-2022-28752HigAug 17, 2022
    risk 0.57cvss 8.8epss 0.00

    Zoom Rooms for Conference Rooms for Windows versions before 5.11.0 are susceptible to a Local Privilege Escalation vulnerability. A local low-privileged malicious user could exploit this vulnerability to escalate their privileges to the SYSTEM user.

  • CVE-2022-28751HigAug 17, 2022
    risk 0.57cvss 8.8epss 0.00

    The Zoom Client for Meetings for MacOS (Standard and for IT Admin) before version 5.11.3 contains a vulnerability in the package signature validation during the update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

  • CVE-2022-2547HigAug 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A crafted HTTP packet without a content-type header can create a denial-of-service condition in Softing Secure Integration Server V1.22.

  • CVE-2022-2337HigAug 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A crafted HTTP packet with a missing HTTP URI can create a denial-of-service condition in Softing Secure Integration Server V1.22.

  • CVE-2022-2335HigAug 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A crafted HTTP packet with a -1 content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22.

  • CVE-2022-2334HigAug 17, 2022
    risk 0.51cvss 7.2epss 0.10

    The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targeted Softing Secure Integration Server V1.22.

  • CVE-2022-23765HigAug 17, 2022
    risk 0.52cvss 8.0epss 0.00

    This vulnerability occured by sending a malicious POST request to a specific page while logged in random user from some family of IPTIME NAS. Remote attackers can steal root privileges by changing the password of the root through a POST request.

  • CVE-2022-23764HigAug 17, 2022
    risk 0.57cvss 8.8epss 0.01

    The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update. Remote attackers can bypass this verification logic to update both digitally signed and unauthorized files, enabling remote code execution.