VYPR

CVEs

102,401 total · page 1131 of 2,049

  • CVE-2022-2304HigJul 5, 2022
    risk 0.00cvss 7.8epss 0.01

    Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-26365HigJul 5, 2022
    risk 0.46cvss 7.1epss 0.00

    Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend…

  • CVE-2022-2309HigJul 5, 2022
    risk 0.42cvss 7.5epss 0.02

    NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data,…

  • CVE-2022-2306HigJul 5, 2022
    risk 0.42cvss 7.5epss 0.01

    Old session tokens can be used to authenticate to the application and send authenticated requests.

  • CVE-2022-34918HigJul 4, 2022
    risk 0.03cvss 7.8epss 0.06

    An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buffer overflow) could be used by a local attacker to escalate privileges, a different vulnerability than CVE-2022-32250. (The attacker can obtain root access, but…

  • CVE-2022-34829HigJul 4, 2022
    risk 0.49cvss 7.5epss 0.04

    Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment API.

  • CVE-2022-31600HigJul 4, 2022
    risk 0.49cvss 7.5epss 0.00

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmmCore, where a user with high privileges can chain another vulnerability to this vulnerability, causing an integer overflow, possibly leading to code execution, escalation of privileges, denial of service, compromised…

  • CVE-2022-31599HigJul 4, 2022
    risk 0.53cvss 8.2epss 0.00

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the Ofbd, where a local user with elevated privileges can cause access to an uninitialized pointer, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact…

  • CVE-2022-2268HigJul 4, 2022
    risk 0.47cvss 7.2epss 0.01

    The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE

  • CVE-2022-29484HigJul 4, 2022
    risk 0.53cvss 8.1epss 0.01

    Operation restriction bypass vulnerability in Space of Cybozu Garoon 4.0.0 to 5.9.0 allows a remote authenticated attacker to delete the data of Space.

  • CVE-2022-34151HigJul 4, 2022
    risk 0.53cvss 8.1epss 0.01

    Use of hard-coded credentials vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, Automation…

  • CVE-2022-33971HigJul 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Authentication bypass by capture-replay vulnerability exists in Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier, and Machine automation controller NJ series all models V 1.48 and…

  • CVE-2022-33948HigJul 4, 2022
    risk 0.57cvss 8.8epss 0.01

    HOME SPOT CUBE2 V102 contains an OS command injection vulnerability due to improper processing of data received from DHCP server. An adjacent attacker may execute an arbitrary OS command on the product if a malicious DHCP server is placed on the WAN side of the product.

  • CVE-2022-33208HigJul 4, 2022
    risk 0.53cvss 8.1epss 0.02

    Authentication bypass by capture-replay vulnerability exists in Machine automation controller NJ series all models V 1.48 and earlier, Machine automation controller NX7 series all models V1.28 and earlier, Machine automation controller NX1 series all models V1.48 and earlier,…

  • CVE-2022-32284HigJul 4, 2022
    risk 0.49cvss 7.5epss 0.03

    Use of insufficiently random values vulnerability exists in Vnet/IP communication module VI461 of YOKOGAWA Wide Area Communication Router (WAC Router) AW810D, which may allow a remote attacker to cause denial-of-service (DoS) condition by sending a specially crafted packet.

  • CVE-2022-2289HigJul 3, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2288HigJul 3, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2287HigJul 2, 2022
    risk 0.00cvss 7.1epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2286HigJul 2, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2285HigJul 2, 2022
    risk 0.00cvss 7.8epss 0.01

    Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-2284HigJul 2, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-28200HigJul 2, 2022
    risk 0.53cvss 8.2epss 0.00

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the BiosCfgTool, where a local user with elevated privileges can read and write beyond intended bounds in SMRAM, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The…

  • CVE-2022-32551HigJul 2, 2022
    risk 0.49cvss 7.5epss 0.03

    Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml).

  • CVE-2022-32412HigJul 1, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell.

  • CVE-2022-32411HigJul 1, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue in the languages config file of HongCMS v3.0 allows attackers to getshell.

  • CVE-2022-32420HigJul 1, 2022
    risk 0.59cvss 8.8epss 0.19

    College Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /College/admin/teacher.php. This vulnerability is exploited via a crafted PHP file.

  • CVE-2022-32384HigJul 1, 2022
    risk 0.57cvss 8.8epss 0.01

    Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the security_5g parameter in the function formWifiBasicSet.

  • CVE-2022-32091HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.

  • CVE-2022-32089HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.

  • CVE-2022-32088HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.

  • CVE-2022-32087HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args.

  • CVE-2022-32086HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field.

  • CVE-2022-32085HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.

  • CVE-2022-32084HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.

  • CVE-2022-32083HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.

  • CVE-2022-32082HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.

  • CVE-2022-32081HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc.

  • CVE-2022-25900HigJul 1, 2022
    risk 0.46cvss 8.1epss 0.03

    All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git.

  • CVE-2022-25898HigJul 1, 2022
    risk 0.43cvss 7.7epss 0.01

    The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT signature with non Base64URL encoding special characters or number escaped characters may be validated as valid by mistake. Workaround: Validate JWS or JWT…

  • CVE-2022-32053HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041621c.

  • CVE-2022-32052HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_004137a4.

  • CVE-2022-32051HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc, week, sTime, eTime parameters in the function FUN_004133c4.

  • CVE-2022-32050HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the cloneMac parameter in the function FUN_0041af40.

  • CVE-2022-32049HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the url parameter in the function FUN_00418540.

  • CVE-2022-32048HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the command parameter in the function FUN_0041cc88.

  • CVE-2022-32047HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00412ef4.

  • CVE-2022-32046HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_0041880c.

  • CVE-2022-32045HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the desc parameter in the function FUN_00413be4.

  • CVE-2022-32044HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK T6 V4.1.9cu.5179_B20201015 was discovered to contain a stack overflow via the password parameter in the function FUN_00413f80.

  • CVE-2022-32043HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAccessCodeInfo.