VYPR

CVEs

102,398 total · page 1140 of 2,048

  • CVE-2022-32376HigJun 15, 2022
    risk 0.47cvss 7.2epss 0.01

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_events.php?event_id=.

  • CVE-2022-32375HigJun 15, 2022
    risk 0.47cvss 7.2epss 0.01

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_timetable.php?id=.

  • CVE-2022-31219HigJun 15, 2022
    risk 0.47cvss 7.3epss 0.00

    Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a…

  • CVE-2022-31218HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a…

  • CVE-2022-31217HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a…

  • CVE-2022-31216HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a…

  • CVE-2022-31044HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not enabled correctly in Rundeck 4.2.0 and 4.2.1, resulting in use of the encryption layer for Key Storage possibly not working. Any…

  • CVE-2021-43756HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires…

  • CVE-2021-43754HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.01

    Adobe Prelude version 22.1.1 (and earlier) is affected by an Out-of-bounds Write vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2022-20817HigJun 15, 2022
    risk 0.48cvss 7.4epss 0.01

    A vulnerability in Cisco Unified IP Phones could allow an unauthenticated, remote attacker to impersonate another user's phone if the Cisco Unified Communications Manager (CUCM) is in secure mode. This vulnerability is due to improper key generation during the manufacturing…

  • CVE-2022-20664HigJun 15, 2022
    risk 0.50cvss 7.7epss 0.01

    A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an authenticated, remote attacker to retrieve sensitive information from a Lightweight…

  • CVE-2022-32992HigJun 15, 2022
    risk 0.47cvss 7.2epss 0.01

    Online Tours And Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the tname parameter at /admin/operations/tax.php.

  • CVE-2022-32991HigJun 15, 2022
    risk 0.57cvss 8.8epss 0.01

    Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the eid parameter at welcome.php.

  • CVE-2022-32302HigJun 15, 2022
    risk 0.57cvss 8.8epss 0.01

    Theme Park Ticketing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edit_ticket.php.

  • CVE-2022-32300HigJun 15, 2022
    risk 0.57cvss 8.8epss 0.01

    YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the MailSendID parameter at /App/Lib/Action/Admin/MailAction.class.php.

  • CVE-2022-32299HigJun 15, 2022
    risk 0.57cvss 8.8epss 0.01

    YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the id parameter at /App/Lib/Action/Admin/SiteAction.class.php.

  • CVE-2022-32157HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Splunk Enterprise deployment servers in versions before 9.0 allow unauthenticated downloading of forwarder bundles. Remediation requires you to update the deployment server to version 9.0 and Configure authentication for deployment servers and clients…

  • CVE-2022-32156HigJun 15, 2022
    risk 0.53cvss 8.1epss 0.01

    In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default. After updating to version 9.0, see Configure TLS host name validation…

  • CVE-2022-32155HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.02

    In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential exposure, but it is not a vulnerability. If exposed, we recommend each customer assess the potential severity specific to your…

  • CVE-2022-32153HigJun 15, 2022
    risk 0.53cvss 8.1epss 0.01

    Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properly with valid certificates…

  • CVE-2022-32152HigJun 15, 2022
    risk 0.53cvss 8.1epss 0.01

    Splunk Enterprise peers in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203 did not validate the TLS certificates during Splunk-to-Splunk communications by default. Splunk peer communications configured properly with valid certificates…

  • CVE-2022-32151HigJun 15, 2022
    risk 0.48cvss 7.4epss 0.01

    The httplib and urllib Python libraries that Splunk shipped with Splunk Enterprise did not validate certificates using the certificate authority (CA) certificate stores by default in Splunk Enterprise versions before 9.0 and Splunk Cloud Platform versions before 8.2.2203. Python…

  • CVE-2021-42732HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.02

    Access of Memory Location After End of Buffer (CWE-788)

  • CVE-2021-40727HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.01

    Access of Memory Location After End of Buffer (CWE-788

  • CVE-2021-39820HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.04

    Adobe InDesign versions 16.3 (and earlier), and 16.3.1 (and earlier) is affected by an Out-of-bounds Write vulnerability due to insecure handling of a malicious TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is…

  • CVE-2022-33140HigJun 15, 2022
    risk 0.57cvss 8.8epss 0.04

    The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutralize arguments for group resolution commands, allowing injection of operating system commands on Linux and macOS platforms. The ShellUserGroupProvider is…

  • CVE-2021-33036HigJun 15, 2022
    risk 0.50cvss 8.8epss 0.04

    In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

  • CVE-2022-20209HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.01

    In hme_add_new_node_to_a_sorted_array of hme_utils.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20207HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    In static definitions of GattServiceConfig.java, there is a possible permission bypass due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20204HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug reports due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…

  • CVE-2022-20197HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    In recycle of Parcel.java, there is a possible way to start foreground activity from background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20194HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    In onCreate of ChooseLockGeneric.java, there is a possible permission bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID:…

  • CVE-2022-20193HigJun 15, 2022
    risk 0.47cvss 7.3epss 0.00

    In getUniqueUsagesWithLabels of PermissionUsageHelper.java, there is a possible incorrect permission attribution due to a logic error in the code. This could lead to local escalation of privilege by conflating apps with User execution privileges needed. User interaction is…

  • CVE-2022-20192HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    In grantEmbeddedWindowFocus of WindowManagerService.java, there is a possible way to change an input channel for embedded hierarchy due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is…

  • CVE-2022-20190HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-208744915References: N/A

  • CVE-2022-20188HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-207254598References: N/A

  • CVE-2022-20186HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.01

    In kbase_mem_alias of mali_kbase_mem_linux.c, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20184HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-209153114References: N/A

  • CVE-2022-20181HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-210936609References: N/A

  • CVE-2022-20179HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-211683760References: N/A

  • CVE-2022-20177HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-209906686References: N/A

  • CVE-2022-20175HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-209252491References: N/A

  • CVE-2022-20169HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-211162353References: N/A

  • CVE-2022-20168HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-210594998References: N/A

  • CVE-2022-20156HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    In unflatten of GraphicBuffer.cpp, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20155HigJun 15, 2022
    risk 0.46cvss 7.0epss 0.00

    In ipu_core_jqs_msg_transport_kernel_write_sync of ipu-core-jqs-msg-transport.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20151HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-210712565References: N/A

  • CVE-2022-20149HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-211685939References: N/A

  • CVE-2022-20147HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    In nfa_dm_check_set_config of nfa_dm_main.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20144HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    In multiple functions of AvatarPhotoController.java, there is a possible access to content owned by system content providers due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed…