VYPR

CVEs

102,398 total · page 1137 of 2,048

  • CVE-2022-33915HigJun 17, 2022
    risk 0.46cvss 7.0epss 0.00

    Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3.5 are affected by a race condition that could lead to a local privilege escalation. This Hotpatch package is not a replacement for updating to a log4j version that mitigates…

  • CVE-2022-33912HigJun 17, 2022
    risk 0.51cvss 7.8epss 0.00

    A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected. Using the shipped version of the agents, the maintainer scripts located at /var/lib/dpkg/info/…

  • CVE-2022-32276HigJun 17, 2022
    risk 0.49cvss 7.5epss 0.03

    Grafana 8.4.3 allows unauthenticated access via (for example) a /dashboard/snapshot/*?orgId=0 URI. NOTE: the vendor considers this a UI bug, not a vulnerability

  • CVE-2022-2112HigJun 17, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository inventree/inventree prior to 0.7.2.

  • CVE-2022-2111HigJun 17, 2022
    risk 0.50cvss 8.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository inventree/inventree prior to 0.7.2.

  • CVE-2021-45025HigJun 17, 2022
    risk 0.49cvss 7.5epss 0.01

    ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie.

  • CVE-2021-41490HigJun 17, 2022
    risk 0.49cvss 7.5epss 0.01

    Memory leaks in LazyPRM.cpp of OMPL v1.5.0 can cause unexpected behavior.

  • CVE-2020-36549HigJun 17, 2022
    risk 0.57cvss 8.8epss 0.00

    A vulnerability classified as critical was found in GE Voluson S8. Affected is the underlying Windows XP operating system. Missing patches might introduce an excessive attack surface. Access to the local network is required for this attack to succeed.

  • CVE-2019-12359HigJun 17, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/ztliuyan_sendmail.php (when the attacker has admin authority) via the id parameter.

  • CVE-2019-12358HigJun 17, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendsms.php (when the attacker has dls_print authority) via a dlid cookie.

  • CVE-2019-12357HigJun 17, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/deluser.php (when the attacker has admin authority) via the id parameter.

  • CVE-2019-12356HigJun 17, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_download.php (when the attacker has dls_download authority) via the id parameter.

  • CVE-2019-12355HigJun 17, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /user/dls_print.php (when the attacker has dls_print authority) via the id parameter.

  • CVE-2019-12354HigJun 17, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/showbad.php (when the attacker has admin authority) via the id parameter.

  • CVE-2019-12353HigJun 17, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /admin/dl_sendmail.php (when the attacker has admin authority) via the id parameter.

  • CVE-2019-12352HigJun 17, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in zzcms 2019. There is a SQL injection Vulnerability in /dl/dl_sendmail.php (when the attacker has dls_print authority) via a dlid cookie.

  • CVE-2022-30325HigJun 16, 2022
    risk 0.57cvss 8.8epss 0.00

    An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. The default pre-shared key for the Wi-Fi networks is the same for every router except for the last four digits. The device default pre-shared key for both 2.4 GHz and 5 GHz networks can be guessed or…

  • CVE-2022-33756HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    CA Automic Automation 12.2 and 12.3 contain an entropy weakness vulnerability in the Automic AutomationEngine that could allow a remote attacker to potentially access sensitive data.

  • CVE-2022-33753HigJun 16, 2022
    risk 0.57cvss 8.8epss 0.01

    CA Automic Automation 12.2 and 12.3 contain an insecure file creation and handling vulnerability in the Automic agent that could allow a user to potentially elevate privileges.

  • CVE-2022-33751HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    CA Automic Automation 12.2 and 12.3 contain an insecure memory handling vulnerability in the Automic agent that could allow a remote attacker to potentially access sensitive data.

  • CVE-2022-33739HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    CA Clarity 15.8 and below and 15.9.0 contain an insecure XML parsing vulnerability that could allow a remote attacker to potentially view the contents of any file on the system.

  • CVE-2022-26173HigJun 16, 2022
    risk 0.57cvss 8.8epss 0.01

    JForum v2.8.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via http://target_host:port/jforum-2.8.0/jforum.page, which allows attackers to arbitrarily add admin accounts.

  • CVE-2018-18907HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on D-Link DIR-850L 1.21WW devices. A partially completed WPA handshake is sufficient for obtaining full access to the wireless network. A client can access the network by sending packets on Data Frames to the AP without encryption.

  • CVE-2021-46820HigJun 16, 2022
    risk 0.53cvss 8.1epss 0.01

    Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/categories.php

  • CVE-2021-37764HigJun 16, 2022
    risk 0.53cvss 8.1epss 0.01

    Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /shop/admin/manufacturers.php.

  • CVE-2020-28865HigJun 16, 2022
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save.

  • CVE-2020-25459HigJun 16, 2022
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in function sync_tree in hetero_decision_tree_guest.py in WeBank FATE (Federated AI Technology Enabler) 0.1 through 1.4.2 allows attackers to read sensitive information during the training process of machine learning joint modeling.

  • CVE-2022-31295HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated attackers to arbitrarily delete posts.

  • CVE-2022-31464HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.00

    Insecure permissions configuration in Adaware Protect v1.2.439.4251 allows attackers to escalate privileges via changing the service binary path.

  • CVE-2022-27511HigJun 16, 2022
    risk 0.54cvss 8.1epss 0.12

    Corruption of the system by a remote, unauthenticated user. The impact of this can include the reset of the administrator password at the next device reboot, allowing an attacker with ssh access to connect with the default administrator credentials after the device has rebooted.

  • CVE-2020-35597HigJun 16, 2022
    risk 0.57cvss 8.8epss 0.01

    Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post.php, u_id parameter of admin_edit_user.php, and edit parameter of admin_update_categories.php.

  • CVE-2022-32547HigJun 16, 2022
    risk 0.00cvss 7.8epss 0.01

    In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact…

  • CVE-2022-32546HigJun 16, 2022
    risk 0.00cvss 7.8epss 0.01

    A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to…

  • CVE-2022-32545HigJun 16, 2022
    risk 0.00cvss 7.8epss 0.01

    A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to…

  • CVE-2022-30664HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Animate version 22.0.5 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2022-30657HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2022-30656HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2022-30655HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2022-30654HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.06

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-30653HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2022-30652HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2022-30651HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute…

  • CVE-2022-30650HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.06

    Adobe InCopy versions 17.2 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-29866HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.02

    OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to exhaust the memory resources of a server via a crafted request that triggers Uncontrolled Resource Consumption.

  • CVE-2022-29864HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.02

    OPC UA .NET Standard Stack 1.04.368 allows a remote attacker to cause a server to crash via a large number of messages that trigger Uncontrolled Resource Consumption.

  • CVE-2022-29863HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    OPC UA .NET Standard Stack 1.04.368 allows remote attacker to cause a crash via a crafted message that triggers excessive memory allocation.

  • CVE-2022-30670HigJun 16, 2022
    risk 0.57cvss 8.8epss 0.01

    RoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalation. An authenticated attacker could leverage this vulnerability to achieve full administrator privileges. Exploitation of this…

  • CVE-2022-30665HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2022-30663HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2022-30662HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…