VYPR

CVEs

102,398 total · page 1132 of 2,048

  • CVE-2022-32037HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAPCfg.

  • CVE-2022-32036HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain multiple stack overflow vulnerabilities via the ssidList, storeName, and trademark parameters in the function formSetStoreWeb.

  • CVE-2022-32035HigJul 1, 2022
    risk 0.50cvss 7.5epss 0.14

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formMasterMng.

  • CVE-2022-32034HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the items parameter in the function formdelMasteraclist.

  • CVE-2022-32033HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the function formSetVirtualSer.

  • CVE-2022-32031HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function fromSetRouteStatic.

  • CVE-2022-32030HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetQosBand.

  • CVE-2022-2229HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    An improper authorization issue in GitLab CE/EE affecting all versions from 13.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to extract the value of an unprotected variable they know the name of in public projects or private projects…

  • CVE-2022-2235HigJul 1, 2022
    risk 0.57cvss 8.7epss 0.01

    Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to perform cross-site scripting when a victim clicks on a maliciously crafted ZenTao link

  • CVE-2022-2230HigJul 1, 2022
    risk 0.57cvss 8.1epss 0.56

    A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.

  • CVE-2014-3648HigJul 1, 2022
    risk 0.49cvss 7.5epss 0.01

    The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is user controlled. If a bogus applications is registered with bad deviceTokens, one can generate endless exceptions when those…

  • CVE-2022-33103HigJul 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir().

  • CVE-2022-33099HigJul 1, 2022
    risk 0.00cvss 7.5epss 0.03

    An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.

  • CVE-2022-2264HigJul 1, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-27904HigJul 1, 2022
    risk 0.46cvss 7.0epss 0.00

    Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack during the agent install process.

  • CVE-2022-33087HigJun 30, 2022
    risk 0.49cvss 7.5epss 0.02

    A stack overflow in the function DM_ In fillobjbystr() of TP-Link Archer C50&A5(US)_V5_200407 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

  • CVE-2022-33085HigJun 30, 2022
    risk 0.47cvss 7.2epss 0.02

    ESPCMS P8 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the fetch_filename function at \espcms_public\espcms_templates\ESPCMS_Templates.

  • CVE-2022-33082HigJun 30, 2022
    risk 0.42cvss 7.5epss 0.02

    An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2022-31115HigJun 30, 2022
    risk 0.50cvss 8.8epss 0.02

    opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used instead of `YAML.safe_load`. As a result opensearch-ruby 2.0.0 and prior can lead to unsafe deserialization using YAML.load if the…

  • CVE-2022-2257HigJun 30, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

  • CVE-2022-23725HigJun 30, 2022
    risk 0.50cvss 7.7epss 0.00

    PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensitive API keys under some circumstances.

  • CVE-2022-23720HigJun 30, 2022
    risk 0.49cvss 7.5epss 0.00

    PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions PingID properties file. An IT administrator could mistakenly deploy administrator privileged PingID API credentials, such as those typically used by…

  • CVE-2022-23719HigJun 30, 2022
    risk 0.47cvss 7.2epss 0.00

    PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security key requests. An attacker with the ability to execute code on the target machine maybe able to exploit and spoof the local Java service using multiple attack…

  • CVE-2022-23718HigJun 30, 2022
    risk 0.50cvss 7.6epss 0.02

    PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker capable of achieving a sophisticated man-in-the-middle position, or to compromise Ping Identity web servers, could deliver malicious code that would be executed…

  • CVE-2021-41995HigJun 30, 2022
    risk 0.50cvss 7.7epss 0.01

    A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.

  • CVE-2022-34793HigJun 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-34792HigJun 30, 2022
    risk 0.52cvss 8.0epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML.

  • CVE-2022-31112HigJun 30, 2022
    risk 0.46cvss 8.2epss 0.01

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected versions parse Server LiveQuery does not remove protected fields in classes, passing them to the client. The LiveQueryController now removes protected fields from…

  • CVE-2022-22474HigJun 30, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Protect 8.1.0.0 through 8.1.14.0 dsmcad, dsmc, and dsmcsvc processes incorrectly handle certain read operations on TCP/IP sockets. This can result in a denial of service for IBM Spectrum Protect client operations. IBM X-Force ID: 225348.

  • CVE-2022-22472HigJun 30, 2022
    risk 0.57cvss 8.8epss 0.01

    IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role based access control restrictions, caused by improper…

  • CVE-2021-38941HigJun 30, 2022
    risk 0.53cvss 8.1epss 0.01

    IBM CloudPak for Multicloud Monitoring 2.0 and 2.3 has a few containers running in privileged mode which is vulnerable to host information leakage or destruction if unauthorized access to these containers could execute arbitrary commands. IBM X-Force ID: 211048.

  • CVE-2021-37770HigJun 30, 2022
    risk 0.47cvss 7.2epss 0.01

    Nucleus CMS v3.71 is affected by a file upload vulnerability. In this vulnerability, we can use upload to change the upload path to the path without the Htaccess file. Upload an Htaccess file and write it to AddType application / x-httpd-php.jpg. In this way, an attacker can…

  • CVE-2017-20123HigJun 30, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to untrusted search path. It is possible to initiate the attack remotely. The exploit has been disclosed to the…

  • CVE-2017-20121HigJun 30, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in Teradici Management Console 2.2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Database Management. The manipulation leads to improper privilege management. It is possible to launch…

  • CVE-2022-33061HigJun 29, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_service.

  • CVE-2022-33060HigJun 29, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule.

  • CVE-2022-33059HigJun 29, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_train.

  • CVE-2022-33058HigJun 29, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_message.

  • CVE-2022-33057HigJun 29, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_reservation.

  • CVE-2022-2073HigJun 29, 2022
    risk 0.41cvss 7.2epss 0.10

    Code Injection in GitHub repository getgrav/grav prior to 1.7.34.

  • CVE-2022-31058HigJun 29, 2022
    risk 0.47cvss 7.2epss 0.01

    Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior to 13.9.99.95 Tuleap does not sanitize properly user inputs when constructing the SQL query to retrieve data for the tracker reports. An attacker with the…

  • CVE-2022-33639HigJun 29, 2022
    risk 0.54cvss 8.3epss 0.03

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2022-33638HigJun 29, 2022
    risk 0.54cvss 8.3epss 0.02

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2022-33042HigJun 29, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/inquiries/view_details.php.

  • CVE-2022-30192HigJun 29, 2022
    risk 0.54cvss 8.3epss 0.03

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2022-34043HigJun 29, 2022
    risk 0.47cvss 7.3epss 0.00

    Incorrect permissions for the folder C:\ProgramData\NoMachine\var\uninstall of Nomachine v7.9.2 allows attackers to perform a DLL hijacking attack and execute arbitrary code.

  • CVE-2022-33037HigJun 29, 2022
    risk 0.51cvss 7.8epss 0.00

    A binary hijack in Orwell-Dev-Cpp v5.11 allows attackers to execute arbitrary code via a crafted .exe file.

  • CVE-2022-33036HigJun 29, 2022
    risk 0.51cvss 7.8epss 0.00

    A binary hijack in Embarcadero Dev-CPP v6.3 allows attackers to execute arbitrary code via a crafted .exe file.

  • CVE-2022-33035HigJun 29, 2022
    risk 0.51cvss 7.8epss 0.00

    XLPD v7.0.0094 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.

  • CVE-2022-33023HigJun 29, 2022
    risk 0.49cvss 7.5epss 0.01

    CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong.