VYPR

CVEs

103,466 total · page 1130 of 2,070

  • CVE-2022-1748HigAug 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Softing OPC UA C++ Server SDK, Secure Integration Server, edgeConnector, edgeAggregator, OPC Suite, and uaGate are affected by a NULL pointer dereference vulnerability.

  • CVE-2022-1373HigAug 17, 2022
    risk 0.51cvss 7.2epss 0.11

    The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration"…

  • CVE-2022-1069HigAug 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A crafted HTTP packet with a large content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22.

  • CVE-2021-26639HigAug 17, 2022
    risk 0.53cvss 8.1epss 0.00

    This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system.

  • CVE-2022-36216HigAug 17, 2022
    risk 0.47cvss 7.2epss 0.02

    DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php.

  • CVE-2022-36215HigAug 17, 2022
    risk 0.47cvss 7.2epss 0.02

    DedeBIZ v6 was discovered to contain a remote code execution vulnerability in sys_info.php.

  • CVE-2022-2862HigAug 17, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.0221.

  • CVE-2022-2849HigAug 17, 2022
    risk 0.00cvss 7.8epss 0.00

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220.

  • CVE-2022-38149HigAug 17, 2022
    risk 0.42cvss 7.5epss 0.01

    HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorrectly. Fixed in 0.27.3, 0.28.3, and 0.29.2.

  • CVE-2022-36186HigAug 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_property_full () at filter_core/filter_pid.c:5250,which causes a Denial of Service (DoS). This vulnerability was fixed in commit b43f9d1.

  • CVE-2022-31262HigAug 17, 2022
    risk 0.51cvss 7.8epss 0.00

    An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissions, an attacker can hijack the %ProgramData%\GOG.com folder structure and change the GalaxyCommunication service executable to a malicious file, resulting in…

  • CVE-2022-30262HigAug 17, 2022
    risk 0.51cvss 7.8epss 0.00

    The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containing a binary firmware image. In all cases, firmware images…

  • CVE-2022-2845HigAug 17, 2022
    risk 0.00cvss 7.8epss 0.01

    Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.

  • CVE-2022-37459HigAug 17, 2022
    risk 0.51cvss 7.8epss 0.00

    Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions for return addresses and potentially hijack code flow to execute arbitrary code via a side-channel attack, aka a "Retbleed" issue.

  • CVE-2021-45454HigAug 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Ampere Altra before SRP 1.08b and Altra Max​ before SRP 2.05 allow information disclosure of power telemetry via HWmon.

  • CVE-2022-1410HigAug 17, 2022
    risk 0.52cvss 8.0epss 0.01

    OS Command Injection vulnerability in the db_optimize component of Device42 Asset Management Appliance allows an authenticated attacker to execute remote code on the device. This issue affects: Device42 CMDB version 18.01.00 and prior versions.

  • CVE-2022-1400HigAug 17, 2022
    risk 0.46cvss 7.1epss 0.01

    Use of Hard-coded Cryptographic Key vulnerability in the WebReportsApi.dll of Exago Web Reports, as used in the Device42 Asset Management Appliance, allows an attacker to leak session IDs and elevate privileges. This issue affects: Device42 CMDB versions prior to 18.01.00.

  • CVE-2021-42052HigAug 16, 2022
    risk 0.49cvss 7.5epss 0.01

    IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEResource.res path and the R query parameter.

  • CVE-2022-38238HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::lookChar() at /xpdf/Stream.cc.

  • CVE-2022-38237HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readScan() at /xpdf/Stream.cc.

  • CVE-2022-38236HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    XPDF commit ffaf11c was discovered to contain a global-buffer overflow via Lexer::getObj(Object*) at /xpdf/Lexer.cc.

  • CVE-2022-38231HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::getChar() at /xpdf/Stream.cc.

  • CVE-2022-38229HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc.

  • CVE-2022-38228HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    XPDF commit ffaf11c was discovered to contain a heap-buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc.

  • CVE-2022-38227HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    XPDF commit ffaf11c was discovered to contain a stack overflow via __asan_memcpy at asan_interceptors_memintrinsics.cpp.

  • CVE-2022-37781HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    fdkaac v1.0.3 was discovered to contain a heap buffer overflow via __interceptor_memcpy.part.46 at /sanitizer_common/sanitizer_common_interceptors.inc.

  • CVE-2022-37437HigAug 16, 2022
    risk 0.48cvss 7.4epss 0.00

    When using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is not correctly performed and tested for the destination. The vulnerability only affects connections between Splunk Enterprise and…

  • CVE-2022-36144HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    SWFMill commit 53d7690 was discovered to contain a heap-buffer overflow via base64_encode.

  • CVE-2022-36143HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    SWFMill commit 53d7690 was discovered to contain a heap-buffer overflow via __interceptor_strlen.part at /sanitizer_common/sanitizer_common_interceptors.inc.

  • CVE-2022-36142HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    SWFMill commit 53d7690 was discovered to contain a heap-buffer overflow via SWF::Reader::getU30().

  • CVE-2022-36139HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    SWFMill commit 53d7690 was discovered to contain a heap-buffer overflow via SWF::Writer::writeByte(unsigned char).

  • CVE-2022-35011HigAug 16, 2022
    risk 0.57cvss 8.8epss 0.01

    PNGDec commit 8abf6be was discovered to contain a global buffer overflow via inflate_fast at /src/inffast.c.

  • CVE-2022-35003HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    JPEGDEC commit be4843c was discovered to contain a global buffer overflow via ucDitherBuffer at /src/jpeg.inl.

  • CVE-2022-34998HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    JPEGDEC commit be4843c was discovered to contain a global buffer overflow via JPEGDecodeMCU at /src/jpeg.inl.

  • CVE-2022-34256HigAug 16, 2022
    risk 0.42cvss 7.5epss 0.02

    Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to access other user's data.…

  • CVE-2022-34255HigAug 16, 2022
    risk 0.50cvss 8.8epss 0.02

    Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An attacker with a low privilege account could leverage this vulnerability to…

  • CVE-2022-34254HigAug 16, 2022
    risk 0.50cvss 8.8epss 0.02

    Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could be abused by an attacker to inject malicious scripts into the…

  • CVE-2022-34253HigAug 16, 2022
    risk 0.40cvss 7.2epss 0.04

    Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML Injection vulnerability in the Widgets Module. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.…

  • CVE-2022-2833HigAug 16, 2022
    risk 0.49cvss 7.5epss 0.01

    Endless Infinite loop in Blender-thumnailing due to logical bugs.

  • CVE-2022-2832HigAug 16, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Blender 3.3.0. A null pointer dereference exists in source/blender/gpu/opengl/gl_backend.cc that may lead to loss of confidentiality and integrity.

  • CVE-2022-2831HigAug 16, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendthumb/src/blendthumb_extract.cc may lead to program crash or memory corruption.

  • CVE-2020-1756HigAug 16, 2022
    risk 0.47cvss 7.2epss 0.01

    In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.

  • CVE-2020-14322HigAug 16, 2022
    risk 0.49cvss 7.5epss 0.01

    In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, yui_combo needed to limit the amount of files it can load to help mitigate the risk of denial of service.

  • CVE-2020-14321HigAug 16, 2022
    risk 0.55cvss 8.8epss 0.17

    In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role within that course.

  • CVE-2020-10728HigAug 16, 2022
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in automationbroker/apb container in versions up to and including 2.0.4-1. This container grants all users sudoer permissions allowing an unauthorized user with access to the running container the ability to escalate their own privileges. The highest threat from…

  • CVE-2022-37393HigAug 16, 2022
    risk 0.47cvss 7.8epss 0.02

    Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as…

  • CVE-2022-38184HigAug 16, 2022
    risk 0.49cvss 7.5epss 0.01

    There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.

  • CVE-2022-30576HigAug 16, 2022
    risk 0.57cvss 8.7epss 0.00

    The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute…

  • CVE-2022-30575HigAug 16, 2022
    risk 0.47cvss 7.3epss 0.01

    The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - Estore Edition, and TIBCO Statistica Trial contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged…

  • CVE-2022-38362HigAug 16, 2022
    risk 0.57cvss 8.8epss 0.02

    Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host.