VYPR

CVEs

102,398 total · page 1136 of 2,048

  • CVE-2022-2175HigJun 23, 2022
    risk 0.00cvss 7.8epss 0.01

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-21952HigJun 22, 2022
    risk 0.49cvss 7.5epss 0.01

    A Missing Authentication for Critical Function vulnerability in spacewalk-java of SUSE Manager Server 4.1, SUSE Manager Server 4.2 allows remote attackers to easily exhaust available disk resources leading to DoS. This issue affects: SUSE Manager Server 4.1 spacewalk-java…

  • CVE-2021-40511HigJun 21, 2022
    risk 0.49cvss 7.5epss 0.01

    OBDA systems’ Mastro 1.0 is vulnerable to XML Entity Expansion (aka “billion laughs”) attack allowing denial of service.

  • CVE-2021-40510HigJun 21, 2022
    risk 0.49cvss 7.5epss 0.01

    XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.

  • CVE-2022-34008HigJun 21, 2022
    risk 0.51cvss 7.8epss 0.01

    Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privileged attacker can use an NTFS directory junction to restore a malicious DLL from quarantine into the System32 folder.

  • CVE-2022-33995HigJun 21, 2022
    risk 0.49cvss 7.5epss 0.02

    A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an arbitrary location.

  • CVE-2022-32973HigJun 21, 2022
    risk 0.57cvss 8.8epss 0.01

    An authenticated attacker could create an audit file that bypasses PowerShell cmdlet checks and executes commands with administrator privileges.

  • CVE-2022-2068HigJun 21, 2022
    risk 0.48cvss 7.3epss 0.96

    In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not…

  • CVE-2022-27872HigJun 21, 2022
    risk 0.51cvss 7.8epss 0.01

    A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022. The vulnerability exists because the application fails to handle a crafted PDF file, which causes an unhandled exception. An…

  • CVE-2022-27871HigJun 21, 2022
    risk 0.51cvss 7.8epss 0.01

    Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may be used to write beyond the allocated buffer while parsing PDF files. This vulnerability may be exploited to execute arbitrary code.

  • CVE-2022-27870HigJun 21, 2022
    risk 0.51cvss 7.8epss 0.01

    A maliciously crafted TGA file in Autodesk AutoCAD 2023 may be used to write beyond the allocated buffer while parsing TGA file. This vulnerability may be exploited to execute arbitrary code.

  • CVE-2022-27869HigJun 21, 2022
    risk 0.51cvss 7.8epss 0.01

    A maliciously crafted TIFF file in Autodesk AutoCAD 2023 can be forced to read and write beyond allocated boundaries when parsing the TIFF file. This vulnerability can be exploited to execute arbitrary code.

  • CVE-2022-27868HigJun 21, 2022
    risk 0.51cvss 7.8epss 0.01

    A maliciously crafted CAT file in Autodesk AutoCAD 2023 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.

  • CVE-2022-27867HigJun 21, 2022
    risk 0.51cvss 7.8epss 0.01

    A maliciously crafted JT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.

  • CVE-2022-22979HigJun 21, 2022
    risk 0.49cvss 7.5epss 0.01

    In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condition due to the caching issue in the Function Catalog component of the framework.

  • CVE-2022-1833HigJun 21, 2022
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where the AMQ Operator is deployed has access to clusterwide edit rights by checking the secrets. The service account used for building…

  • CVE-2022-1665HigJun 21, 2022
    risk 0.53cvss 8.2epss 0.00

    A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even though it shouldn't. These kernel builds don't have the secure boot lockdown patches applied to it and can bypass the secure boot…

  • CVE-2022-33056HigJun 21, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/schedules/manage_schedule.php.

  • CVE-2022-33055HigJun 21, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/trains/manage_train.php.

  • CVE-2022-33049HigJun 21, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/?page=user/manage_user.

  • CVE-2022-33048HigJun 21, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Railway Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /orrs/admin/reservations/view_details.php.

  • CVE-2017-20067HigJun 21, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Hindu Matrimonial Script. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/. The manipulation of the argument username/password with the input 'or''=' leads to sql injection. The attack…

  • CVE-2022-33913HigJun 20, 2022
    risk 0.49cvss 7.5epss 0.01

    In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.

  • CVE-2022-1720HigJun 20, 2022
    risk 0.00cvss 7.8epss 0.02

    Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

  • CVE-2021-41683HigJun 20, 2022
    risk 0.51cvss 7.8epss 0.01

    There is a stack-overflow at ecma-helpers.c:326 in ecma_get_lex_env_type in JerryScript 2.4.0

  • CVE-2021-41682HigJun 20, 2022
    risk 0.51cvss 7.8epss 0.01

    There is a heap-use-after-free at ecma-helpers-string.c:1940 in ecma_compare_ecma_non_direct_strings in JerryScript 2.4.0

  • CVE-2022-1939HigJun 20, 2022
    risk 0.47cvss 7.2epss 0.01

    The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privilege users such as admin to upload PHP files even when they are not allowed to

  • CVE-2022-1824HigJun 20, 2022
    risk 0.51cvss 7.9epss 0.00

    An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a specific file name. This could result in the user gaining elevated permissions and being able to…

  • CVE-2022-1823HigJun 20, 2022
    risk 0.51cvss 7.9epss 0.00

    Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and…

  • CVE-2022-1801HigJun 20, 2022
    risk 0.49cvss 7.5epss 0.01

    The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the page a likely target for…

  • CVE-2022-1614HigJun 20, 2022
    risk 0.49cvss 7.5epss 0.01

    The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based anti-spamming restrictions.

  • CVE-2022-1472HigJun 20, 2022
    risk 0.47cvss 7.2epss 0.01

    The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection

  • CVE-2022-26669HigJun 20, 2022
    risk 0.57cvss 8.8epss 0.01

    ASUS Control Center is vulnerable to SQL injection. An authenticated remote attacker with general user privilege can inject SQL command to specific API parameters to acquire database schema or access data.

  • CVE-2022-26668HigJun 20, 2022
    risk 0.48cvss 7.3epss 0.01

    ASUS Control Center API has a broken access control vulnerability. An unauthenticated remote attacker can call privileged API functions to perform partial system operations or cause partial disrupt of service.

  • CVE-2021-45918HigJun 20, 2022
    risk 0.49cvss 7.5epss 0.01

    NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved for the program, in order to terminate…

  • CVE-2022-34006HigJun 19, 2022
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. When installing, Microsoft SQL Express 2019 installs by default with an SQL instance running as SYSTEM with BUILTIN\Users as sysadmin, thus enabling unprivileged Windows users to execute commands…

  • CVE-2022-2129HigJun 19, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-2126HigJun 19, 2022
    risk 0.00cvss 7.8epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-2125HigJun 19, 2022
    risk 0.00cvss 7.8epss 0.02

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-2124HigJun 19, 2022
    risk 0.00cvss 7.8epss 0.01

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.

  • CVE-2014-125024HigJun 19, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in FFmpeg 2.0. It has been rated as critical. Affected by this issue is the function lag_decode_frame. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch to fix this issue.

  • CVE-2014-125020HigJun 19, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in FFmpeg 2.0 and classified as critical. This vulnerability affects the function decode_update_thread_context. The manipulation leads to memory corruption. The attack can be initiated remotely. It is recommended to apply a patch to fix this issue.

  • CVE-2014-125017HigJun 18, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in FFmpeg 2.0. This vulnerability affects the function rpza_decode_stream. The manipulation leads to memory corruption. The attack can be initiated remotely. The name of the patch is Fixes Invalid Writes. It is recommended to…

  • CVE-2014-125015HigJun 18, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in FFmpeg 2.0. Affected is the function read_var_block_data. The manipulation leads to memory corruption. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.

  • CVE-2022-25856HigJun 17, 2022
    risk 0.42cvss 7.5epss 0.02

    The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifactReader is provided a pathname containing a symbolic link…

  • CVE-2022-25852HigJun 17, 2022
    risk 0.00cvss 7.5epss 0.01

    All versions of package pg-native; all versions of package libpq are vulnerable to Denial of Service (DoS) when the addons attempt to cast the second argument to an array and fail. This happens for every non-array argument passed. **Note:** pg-native is a mere binding to npm's…

  • CVE-2022-25345HigJun 17, 2022
    risk 0.42cvss 7.5epss 0.01

    All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.

  • CVE-2022-22138HigJun 17, 2022
    risk 0.49cvss 7.5epss 0.01

    All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation.

  • CVE-2022-21213HigJun 17, 2022
    risk 0.42cvss 7.5epss 0.02

    This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both cases, the key used to access the target…

  • CVE-2022-31083HigJun 17, 2022
    risk 0.49cvss 8.6epss 0.01

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 4.10.11 and 5.2.2, the certificate in the Parse Server Apple Game Center auth adapter not validated. As a result, authentication could potentially be…