VYPR

CVEs

102,398 total · page 1138 of 2,048

  • CVE-2022-30661HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.06

    Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2022-30660HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2022-30659HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2022-30658HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.06

    Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2022-29865HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    OPC UA .NET Standard Stack allows a remote attacker to bypass the application authentication check via crafted fake credentials.

  • CVE-2022-29862HigJun 16, 2022
    risk 0.49cvss 7.5epss 0.01

    An infinite loop in OPC UA .NET Standard Stack 1.04.368 allows a remote attackers to cause the application to hang via a crafted message.

  • CVE-2022-1642HigJun 16, 2022
    risk 0.42cvss 7.5epss 0.01

    A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JSON document containing a type mismatch. This vulnerability is caused by the interaction between a deserialization mechanism offered by the…

  • CVE-2022-31291HigJun 16, 2022
    risk 0.00cvss 7.5epss 0.01

    An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows attackers to cause a double free via crafted TCP packets.

  • CVE-2022-27532HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.01

    A maliciously crafted TIF file in Autodesk 3ds Max 2022 and 2021 can be used to write beyond the allocated buffer while parsing TIF files. This vulnerability in conjunction with other vulnerabilities could lead to arbitrary code execution.

  • CVE-2022-27531HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.01

    A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max 2022, and 2021 when parsing the TIF files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

  • CVE-2022-31912HigJun 16, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Tutor Portal Site v1.0 is vulnerable to SQL Injection via /otps/classes/Master.php?f=delete_team.

  • CVE-2022-31911HigJun 16, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Discussion Forum Site v1.0 is vulnerable to SQL Injection via /odfs/classes/Master.php?f=delete_team.

  • CVE-2022-31908HigJun 16, 2022
    risk 0.47cvss 7.2epss 0.01

    Student Registration and Fee Payment System v1.0 is vulnerable to SQL Injection via /scms/student.php.

  • CVE-2022-31849HigJun 16, 2022
    risk 0.57cvss 8.8epss 0.02

    MERCURY MIPC451-4 1.0.22 Build 220105 Rel.55642n was discovered to contain a remote code execution (RCE) vulnerability which is exploitable via a crafted POST request.

  • CVE-2022-31277HigJun 16, 2022
    risk 0.57cvss 8.8epss 0.01

    Xiaomi Lamp 1 v2.0.4_0066 was discovered to be vulnerable to replay attacks. This allows attackers to to bypass the expected access restrictions and gain control of the switch and other functions via a crafted POST request.

  • CVE-2022-30023HigJun 16, 2022
    risk 0.61cvss 8.8epss 0.42

    Tenda ONT GPON AC1200 Dual band WiFi HG9 v1.0.1 is vulnerable to Command Injection via the Ping function.

  • CVE-2022-31372HigJun 16, 2022
    risk 0.00cvss 7.5epss 0.01

    Wiris Mathtype v7.28.0 was discovered to contain a path traversal vulnerability in the resourceFile parameter. This vulnerability is exploited via a crafted request to the resource handler.

  • CVE-2021-41402HigJun 16, 2022
    risk 0.57cvss 8.8epss 0.01

    flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code.

  • CVE-2022-31626HigJun 16, 2022
    risk 0.53cvss 7.5epss 0.58

    In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect to and the password for the connection, password of excessive length can trigger a buffer overflow…

  • CVE-2022-31625HigJun 16, 2022
    risk 0.53cvss 8.1epss 0.03

    In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE…

  • CVE-2022-30549HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read vulnerability exists in V-Server v4.0.11.0 and earlier and V-Server Lite v4.0.13.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

  • CVE-2022-30546HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

  • CVE-2022-30538HigJun 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds write vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

  • CVE-2022-30193HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.02

    AV1 Video Extension Remote Code Execution Vulnerability

  • CVE-2022-30188HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.03

    HEVC Video Extensions Remote Code Execution Vulnerability

  • CVE-2022-30180HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.02

    Azure RTOS GUIX Studio Information Disclosure Vulnerability

  • CVE-2022-30179HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.02

    Azure RTOS GUIX Studio Remote Code Execution Vulnerability

  • CVE-2022-30178HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.02

    Azure RTOS GUIX Studio Remote Code Execution Vulnerability

  • CVE-2022-30177HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.02

    Azure RTOS GUIX Studio Remote Code Execution Vulnerability

  • CVE-2022-30174HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.03

    Microsoft Office Remote Code Execution Vulnerability

  • CVE-2022-30173HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.02

    Microsoft Excel Remote Code Execution Vulnerability

  • CVE-2022-30168HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.02

    Microsoft Photos App Remote Code Execution Vulnerability

  • CVE-2022-30167HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.02

    AV1 Video Extension Remote Code Execution Vulnerability

  • CVE-2022-30166HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.01

    Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

  • CVE-2022-30165HigJun 15, 2022
    risk 0.58cvss 8.8epss 0.04

    Windows Kerberos Elevation of Privilege Vulnerability

  • CVE-2022-30164HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.01

    Kerberos AppContainer Security Feature Bypass Vulnerability

  • CVE-2022-30163HigJun 15, 2022
    risk 0.55cvss 8.5epss 0.02

    Windows Hyper-V Remote Code Execution Vulnerability

  • CVE-2022-30161HigJun 15, 2022
    risk 0.57cvss 8.8epss 0.02

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

  • CVE-2022-30160HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.06

    Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability

  • CVE-2022-30158HigJun 15, 2022
    risk 0.57cvss 8.8epss 0.03

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2022-30157HigJun 15, 2022
    risk 0.58cvss 8.8epss 0.07

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2022-30153HigJun 15, 2022
    risk 0.57cvss 8.8epss 0.02

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

  • CVE-2022-30152HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.03

    Windows Network Address Translation (NAT) Denial of Service Vulnerability

  • CVE-2022-30151HigJun 15, 2022
    risk 0.46cvss 7.0epss 0.01

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

  • CVE-2022-30150HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.03

    Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability

  • CVE-2022-30149HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.02

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

  • CVE-2022-30147HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.05

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2022-30146HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.02

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

  • CVE-2022-30145HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.02

    Windows Encrypting File System (EFS) Remote Code Execution Vulnerability

  • CVE-2022-30143HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.02

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability