VYPR

CVEs

102,398 total · page 1134 of 2,048

  • CVE-2021-33650HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    When performing the inference shape operation of the SparseToDense operator, if the number of inputs is less than three, it will access data outside of bounds of inputs which allocated from heap buffers.

  • CVE-2021-33649HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    When performing the inference shape operation of the Transpose operator, if the value in the perm element is greater than or equal to the size of the input_shape, it will access data outside of bounds of input_shape which allocated from heap buffers.

  • CVE-2021-33648HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    When performing the inference shape operation of Affine, Concat, MatMul, ArgMinMax, EmbeddingLookup, and Gather operators, if the input shape size is 0, it will access data outside of bounds of shape which allocated from heap buffers.

  • CVE-2021-33647HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    When performing the inference shape operation of the Tile operator, if the input data type is not int or int32, it will access data outside of bounds of heap allocated buffers.

  • CVE-2022-2210HigJun 27, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

  • CVE-2021-40901HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scniro-validator v1.0.1 when validating crafted invalid emails.

  • CVE-2021-40900HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in regexfn v1.0.5 when validating crafted invalid emails.

  • CVE-2022-2207HigJun 27, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-0722HigJun 27, 2022
    risk 0.42cvss 7.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository ionicabizau/parse-url prior to 7.0.0.

  • CVE-2021-40899HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in repo-git-downloader v0.1.1 when downloading crafted invalid git repositories.

  • CVE-2021-40898HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scaffold-helper v1.2.0 when copying crafted invalid files.

  • CVE-2021-40897HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in split-html-to-chars v1.0.5 when splitting crafted invalid htmls.

  • CVE-2021-40896HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in that-value v0.1.3 when validating crafted invalid emails.

  • CVE-2021-40895HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in todo-regex v0.1.1 when matching crafted invalid TODO statements.

  • CVE-2022-1977HigJun 27, 2022
    risk 0.47cvss 7.2epss 0.01

    The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the file to be imported via an URL before making an HTTP request to it, which could allow high privilege users such as admin to perform Blind SSRF attacks

  • CVE-2022-1903HigJun 27, 2022
    risk 0.53cvss 8.1epss 0.09

    The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their…

  • CVE-2022-1572HigJun 27, 2022
    risk 0.53cvss 8.1epss 0.01

    The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file

  • CVE-2022-33202HigJun 27, 2022
    risk 0.53cvss 8.1epss 0.00

    Authentication bypass vulnerability in the setup screen of L2Blocker(on-premise) Ver4.8.5 and earlier and L2Blocker(Cloud) Ver4.8.5 and earlier allows an adjacent attacker to perform an unauthorized login and obtain the stored information or cause a malfunction of the device by…

  • CVE-2022-2206HigJun 26, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-24893HigJun 25, 2022
    risk 0.49cvss 7.5epss 0.01

    ESP-IDF is the official development framework for Espressif SoCs. In Espressif’s Bluetooth Mesh SDK (`ESP-BLE-MESH`), a memory corruption vulnerability can be triggered during provisioning, because there is no check for the `SegN` field of the Transaction Start PDU. This can…

  • CVE-2021-40894HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in underscore-99xp v1.7.2 when the deepValueSearch function is called.

  • CVE-2022-33121HigJun 24, 2022
    risk 0.53cvss 8.1epss 0.00

    A Cross-Site Request Forgery (CSRF) in MiniCMS v1.11 allows attackers to arbitrarily delete local .dat files via clicking on a malicious link.

  • CVE-2022-21231HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7715](https://security.snyk.io/vuln/SNYK-JS-DEEPGETSET-598666)

  • CVE-2022-22390HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure caused by improper privilege management when table function is used. IBM X-Force ID: 221973.

  • CVE-2021-40893HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-data v0.1.1 when validating crafted invalid emails.

  • CVE-2020-21046HigJun 24, 2022
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation vulnerability was identified within the "luminati_net_updater_win_eagleget_com" service in EagleGet Downloader version 2.1.5.20 Stable. This issue allows authenticated non-administrative user to escalate their privilege and conduct code execution as…

  • CVE-2022-2121HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    OFFIS DCMTK's (All versions prior to 3.6.7) has a NULL pointer dereference vulnerability while processing DICOM files, which may result in a denial-of-service condition.

  • CVE-2022-2120HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.03

    OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.

  • CVE-2022-2119HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.03

    OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.

  • CVE-2022-28619HigJun 24, 2022
    risk 0.51cvss 7.8epss 0.00

    A potential security vulnerability has been identified in the installer of HPE Version Control Repository Manager. The vulnerability could allow local escalation of privilege. HPE has made the following software update to resolve the vulnerability in HPE Version Control…

  • CVE-2022-1746HigJun 24, 2022
    risk 0.49cvss 7.6epss 0.00

    The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Systems ImageCast X can expose cryptographic secrets used to protect election information. An attacker could leverage this vulnerability to gain access to sensitive…

  • CVE-2022-1667HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the browser console) or by loading the corresponding, browser accessible PHP script

  • CVE-2022-1524HigJun 24, 2022
    risk 0.48cvss 7.4epss 0.00

    LRM version 2.4 and lower does not implement TLS encryption. A malicious actor can MITM attack sensitive data in-transit, including credentials.

  • CVE-2013-1916HigJun 24, 2022
    risk 0.54cvss 8.8epss 0.12

    In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upload a backdoor on the server hosting WordPress. This backdoor can be called (executed) even if the photo has not been yet approved.

  • CVE-2021-40892HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-color v2.1.0 when handling crafted invalid rgb(a) strings.

  • CVE-2021-41638HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.02

    The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by using a valid username.

  • CVE-2021-41637HigJun 24, 2022
    risk 0.46cvss 7.1epss 0.00

    Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.

  • CVE-2021-41635HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.02

    When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative access over the entire host system.

  • CVE-2022-32143HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    In multiple CODESYS products, file download and upload function allows access to internal files in the working directory e.g. firmware files of the PLC. All requests are processed on the controller only if no level 1 password is configured on the controller or if remote attacker…

  • CVE-2022-32142HigJun 24, 2022
    risk 0.53cvss 8.1epss 0.01

    Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft a request with invalid offset, which can cause an out-of-bounds read or write access, resulting in denial-of-service condition or local memory overwrite, which…

  • CVE-2022-32138HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    In multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected sign extension, resulting in a denial-of-service condition or memory overwrite.

  • CVE-2022-32137HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    In multiple CODESYS products, a low privileged remote attacker may craft a request, which may cause a heap-based buffer overflow, resulting in a denial-of-service condition or memory overwrite. User interaction is not required.

  • CVE-2022-31805HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    In the CODESYS Development System multiple components in multiple versions transmit the passwords for the communication between clients and servers unprotected.

  • CVE-2022-31804HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    The CODESYS Gateway Server V2 does not verifiy that the size of a request is within expected limits. An unauthenticated attacker may allocate an arbitrary amount of memory, which may lead to a crash of the Gateway due to an out-of-memory condition.

  • CVE-2022-1965HigJun 24, 2022
    risk 0.53cvss 8.1epss 0.01

    Multiple products of CODESYS implement a improper error handling. A low privilege remote attacker may craft a request, which is not properly processed by the error handling. In consequence, the file referenced by the request could be deleted. User interaction is not required.

  • CVE-2022-32405HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/view_prison.php:4

  • CVE-2022-32404HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_inmate.php:3

  • CVE-2022-32403HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_record.php:4

  • CVE-2022-32402HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/manage_prison.php:4

  • CVE-2022-32401HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_privilege.php:4