VYPR

CVEs

102,398 total · page 1135 of 2,048

  • CVE-2022-32400HigJun 24, 2022
    risk 0.47cvss 7.2epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/user/manage_user.php:4.

  • CVE-2022-32399HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/view_crime.php:4

  • CVE-2022-32398HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/manage_cell.php:4

  • CVE-2022-32397HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/view_visit.php:4

  • CVE-2022-32396HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/manage_visit.php:4

  • CVE-2022-32395HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/manage_crime.php:4

  • CVE-2022-32394HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/view_inmate.php:3

  • CVE-2022-32393HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/view_cell.php:4

  • CVE-2022-32392HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/manage_action.php:4

  • CVE-2022-32391HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/view_action.php:4

  • CVE-2022-2183HigJun 23, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-2182HigJun 23, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-34300HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.01

    In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData.

  • CVE-2022-34299HigJun 23, 2022
    risk 0.00cvss 8.1epss 0.01

    There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.

  • CVE-2022-34296HigJun 23, 2022
    risk 0.42cvss 7.5epss 0.01

    In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request.

  • CVE-2022-34203HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to connect to an attacker-specified HTTP server.

  • CVE-2022-34200HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers to connect to an attacker-specified URL.

  • CVE-2022-34180HigJun 23, 2022
    risk 0.42cvss 7.5epss 0.01

    Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any permissions to obtain the build status badge icon for any…

  • CVE-2022-34179HigJun 23, 2022
    risk 0.42cvss 7.5epss 0.02

    Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to choose a different SVG image style without restricting possible values, resulting in a relative path traversal vulnerability that allows attackers without…

  • CVE-2022-34177HigJun 23, 2022
    risk 0.42cvss 7.5epss 0.01

    Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the controller as part of build metadata, using the parameter name without sanitization as a relative path inside a build-related…

  • CVE-2022-34175HigJun 23, 2022
    risk 0.42cvss 7.5epss 0.01

    Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby directly accessing some view fragments containing sensitive information, bypassing any permission checks in the corresponding view.

  • CVE-2022-34174HigJun 23, 2022
    risk 0.42cvss 7.5epss 0.01

    In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows distinguishing between login attempts with an invalid username, and login attempts with a valid username and wrong password, when using the Jenkins user database…

  • CVE-2022-33114HigJun 23, 2022
    risk 0.47cvss 7.2epss 0.01

    Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list.

  • CVE-2022-33105HigJun 23, 2022
    risk 0.00cvss 7.5epss 0.03

    Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID.

  • CVE-2022-33097HigJun 23, 2022
    risk 0.49cvss 7.5epss 0.01

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job.

  • CVE-2022-33096HigJun 23, 2022
    risk 0.49cvss 7.5epss 0.01

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index.

  • CVE-2022-33095HigJun 23, 2022
    risk 0.49cvss 7.5epss 0.01

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.

  • CVE-2022-33094HigJun 23, 2022
    risk 0.49cvss 7.5epss 0.01

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map.

  • CVE-2022-33093HigJun 23, 2022
    risk 0.49cvss 7.5epss 0.01

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list.

  • CVE-2022-33092HigJun 23, 2022
    risk 0.49cvss 7.5epss 0.01

    74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index.

  • CVE-2022-33034HigJun 23, 2022
    risk 0.51cvss 7.8epss 0.01

    LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c.

  • CVE-2022-33033HigJun 23, 2022
    risk 0.51cvss 7.8epss 0.01

    LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.

  • CVE-2022-33032HigJun 23, 2022
    risk 0.51cvss 7.8epss 0.01

    LibreDWG v0.12.4.4608 was discovered to contain a heap-buffer-overflow via the function decode_preR13_section_hdr at decode_r11.c.

  • CVE-2022-33028HigJun 23, 2022
    risk 0.51cvss 7.8epss 0.01

    LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function dwg_add_object at decode.c.

  • CVE-2022-33027HigJun 23, 2022
    risk 0.51cvss 7.8epss 0.01

    LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function dwg_add_handleref at dwg.c.

  • CVE-2022-33026HigJun 23, 2022
    risk 0.51cvss 7.8epss 0.01

    LibreDWG v0.12.4.4608 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.

  • CVE-2022-33025HigJun 23, 2022
    risk 0.51cvss 7.8epss 0.01

    LibreDWG v0.12.4.4608 was discovered to contain a heap-use-after-free via the function decode_preR13_section at decode_r11.c.

  • CVE-2022-33024HigJun 23, 2022
    risk 0.49cvss 7.5epss 0.01

    There is an Assertion `int decode_preR13_entities(BITCODE_RL, BITCODE_RL, unsigned int, BITCODE_RL, BITCODE_RL, Bit_Chain *, Dwg_Data *' failed at dwg2dxf: decode.c:5801 in libredwg v0.12.4.4608.

  • CVE-2022-32553HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB…

  • CVE-2022-32552HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB…

  • CVE-2022-32536HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.01

    The user access rights validation in the web server of the Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 was insufficient. This would allow a non-administrator user to obtain administrator user access rights.

  • CVE-2022-32534HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.02

    The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface. This allows execution of shell commands.

  • CVE-2022-31395HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.03

    Algo Communication Products Ltd. 8373 IP Zone Paging Adapter Firmware 1.7.6 allows attackers to perform a directory traversal via a web request sent to /fm-data.lua.

  • CVE-2022-31362HigJun 23, 2022
    risk 0.59cvss 8.8epss 0.18

    Docebo Community Edition v4.0.5 and below was discovered to contain an arbitrary file upload vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

  • CVE-2022-22967HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in SaltStack Salt in versions before 3002.9, 3003.5, 3004.2. PAM auth fails to reject locked accounts, which allows a previously authorized user whose account is locked still run Salt commands when their account is locked. This affects both local shell…

  • CVE-2021-40956HigJun 23, 2022
    risk 0.49cvss 7.5epss 0.01

    LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained.

  • CVE-2021-40955HigJun 23, 2022
    risk 0.47cvss 7.2epss 0.01

    SQL injection exists in LaiKetui v3.5.0 the background administrator list.

  • CVE-2021-26638HigJun 23, 2022
    risk 0.48cvss 7.3epss 0.03

    Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and information exposure. Remote attackers can use this vulerability to take control of the home environment including indoor control.

  • CVE-2021-26637HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.02

    There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.

  • CVE-2021-26636HigJun 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to information exposure and privilege escalation.