VYPR

CVEs

102,398 total · page 1143 of 2,048

  • CVE-2021-35076HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.01

    Possible null pointer dereference due to improper validation of RRC connection reconfiguration message in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-35073HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.01

    Possible assertion due to improper validation of rank restriction field in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-35072HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible buffer overflow due to improper validation of array index while processing external DIAG command in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-30350HigJun 14, 2022
    risk 0.55cvss 8.4epss 0.00

    Lack of MBN header size verification against input buffer can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

  • CVE-2021-30349HigJun 14, 2022
    risk 0.53cvss 8.2epss 0.00

    Improper access control sequence for AC database after memory allocation can lead to possible memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables,…

  • CVE-2021-30344HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper authorization of a replayed LTE security mode command can lead to a denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-30340HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.01

    Reachable assertion due to improper validation of coreset in PDCCH configuration in SA mode in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-30338HigJun 14, 2022
    risk 0.46cvss 7.1epss 0.00

    Improper input validation in TrustZone memory transfer interface can lead to information disclosure in Snapdragon Compute

  • CVE-2021-30334HigJun 14, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible use after free due to lack of null check of DRM file status after file structure is freed in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-30327HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.00

    Buffer overflow in sahara protocol while processing commands leads to overwrite of secure configuration data in Snapdragon Mobile, Snapdragon Compute, Snapdragon Auto, Snapdragon IOT, Snapdragon Connectivity, Snapdragon Voice & Music

  • CVE-2021-30281HigJun 14, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible unauthorized access to secure space due to improper check of data allowed while flashing the no access control device configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice &…

  • CVE-2022-29925HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.01

    Access of uninitialized pointer vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image…

  • CVE-2022-29524HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds write vulnerability exists in V-Server v4.0.11.0 and earlier and V-Server Lite v4.0.13.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

  • CVE-2022-29522HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.01

    Use after free vulnerability exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

  • CVE-2022-29509HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.03

    Directory traversal vulnerability in T&D Data Server (Japanese Edition) Ver.2.22 and earlier, T&D Data Server (English Edition) Ver.2.30 and earlier, THERMO RECORDER DATA SERVER (Japanese Edition) Ver.2.13 and earlier, and THERMO RECORDER DATA SERVER (English Edition) Ver.2.13…

  • CVE-2022-29506HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds read vulnerability exist in the simulator module contained in the graphic editor 'V-SFT' v6.1.3.0 and earlier, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

  • CVE-2022-27176HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.01

    Incomplete filtering of special elements vulnerability exists in RevoWorks SCVX using 'File Sanitization Library' 1.043 and prior versions, RevoWorks Browser 2.2.67 and prior versions (when using 'File Sanitization Option'), and RevoWorks Desktop 2.1.84 and prior versions (when…

  • CVE-2022-26302HigJun 14, 2022
    risk 0.51cvss 7.8epss 0.01

    Heap-based buffer overflow exists in the simulator module contained in the graphic editor 'V-SFT' versions prior to v6.1.6.0, which may allow an attacker to obtain information and/or execute arbitrary code by having a user to open a specially crafted image file.

  • CVE-2022-31447HigJun 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An XML external entity (XXE) injection vulnerability in Magicpin v3.4 allows attackers to access sensitive database information via a crafted SVG file.

  • CVE-2022-32565HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Couchbase Server before 7.0.4. The Backup Service log leaks unredacted usernames and document ids.

  • CVE-2022-32562HigJun 13, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission.

  • CVE-2022-32192HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Couchbase Server 5.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.

  • CVE-2022-32278HigJun 13, 2022
    risk 0.00cvss 8.8epss 0.02

    XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.

  • CVE-2022-32564HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Couchbase Server before 7.0.4. In couchbase-cli, server-eshell leaks the Cluster Manager cookie.

  • CVE-2022-32560HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.

  • CVE-2022-32558HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Couchbase Server before 7.0.4. Sample bucket loading may leak internal user passwords during a failure.

  • CVE-2022-31054HigJun 13, 2022
    risk 0.42cvss 7.5epss 0.01

    Argo Events is an event-driven workflow automation framework for Kubernetes. Prior to version 1.7.1, several `HandleRoute` endpoints make use of the deprecated `ioutil.ReadAll()`. `ioutil.ReadAll()` reads all the data into memory. As such, an attacker who sends a large request…

  • CVE-2022-29798HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a denial of service vulnerability in CV81-WDM FW versions 01.70.49.29.46. Successful exploitation could cause denial of service.

  • CVE-2022-31761HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality.

  • CVE-2022-31757HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The setting module has a vulnerability of improper use of APIs. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-31754HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Logical defects in code implementation in some products. Successful exploitation of this vulnerability may affect the availability of some features.

  • CVE-2022-31753HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The voice wakeup module has a vulnerability of using externally-controlled format strings. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2022-31055HigJun 13, 2022
    risk 0.00cvss 7.5epss 0.01

    kCTF is a Kubernetes-based infrastructure for capture the flag (CTF) competitions. Prior to version 1.6.0, the kctf cluster set-src-ip-ranges was broken and allowed traffic from any IP. The problem has been patched in v1.6.0. As a workaround, those who want to test challenges…

  • CVE-2021-46813HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Vulnerability of residual files not being deleted after an update in the ChinaDRM module. Successful exploitation of this vulnerability may affect availability.

  • CVE-2021-46812HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The Device Manager has a vulnerability in multi-device interaction. Successful exploitation of this vulnerability may affect data integrity.

  • CVE-2022-31762HigJun 13, 2022
    risk 0.51cvss 7.8epss 0.00

    The AMS module has a vulnerability in input validation. Successful exploitation of this vulnerability may cause privilege escalation.

  • CVE-2021-46814HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The video framework has an out-of-bounds memory read/write vulnerability. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2022-29244HigJun 13, 2022
    risk 0.42cvss 7.5epss 0.03

    npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively,…

  • CVE-2022-24077HigJun 13, 2022
    risk 0.51cvss 7.8epss 0.00

    Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.

  • CVE-2022-1969HigJun 13, 2022
    risk 0.57cvss 8.8epss 0.01

    The Mobile browser color select plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing or incorrect nonce validation on the admin_update_data() function. This makes it possible for unauthenticated…

  • CVE-2022-1749HigJun 13, 2022
    risk 0.57cvss 8.8epss 0.01

    The WPMK Ajax Finder WordPress plugin is vulnerable to Cross-Site Request Forgery via the createplugin_atf_admin_setting_page() function found in the ~/inc/config/create-plugin-config.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts,…

  • CVE-2022-1657HigJun 13, 2022
    risk 0.57cvss 8.8epss 0.02

    Vulnerable versions of the Jupiter (<= 6.10.1) and JupiterX (<= 2.0.6) Themes allow logged-in users, including subscriber-level users, to perform Path Traversal and Local File inclusion. In the JupiterX theme, the jupiterx_cp_load_pane_action AJAX action present in the…

  • CVE-2022-1654HigJun 13, 2022
    risk 0.57cvss 8.8epss 0.01

    Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 allow any authenticated attacker, including a subscriber or customer-level attacker, to gain administrative privileges via the "abb_uninstall_template" (both) and "jupiterx_core_cp_uninstall_template" (JupiterX Core Only)…

  • CVE-2022-31041HigJun 13, 2022
    risk 0.00cvss 7.6epss 0.01

    Open Forms is an application for creating and publishing smart forms. Open Forms supports file uploads as one of the form field types. These fields can be configured to allow only certain file extensions to be uploaded by end users (e.g. only PDF / Excel / ...). The input…

  • CVE-2022-1918HigJun 13, 2022
    risk 0.57cvss 8.8epss 0.01

    The ToolBar to Share plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0. This is due to missing nonce validation on the plugin_toolbar_comparte page. This makes it possible for unauthenticated attackers to update the plugins…

  • CVE-2022-1900HigJun 13, 2022
    risk 0.57cvss 8.8epss 0.01

    The Copify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.0. This is due to missing nonce validation on the CopifySettings page. This makes it possible for unauthenticated attackers to update the plugins settings and inject…

  • CVE-2022-1800HigJun 13, 2022
    risk 0.47cvss 7.2epss 0.01

    The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exporting post data before using it in a database query, leading to an SQL injection vulnerability.

  • CVE-2022-1791HigJun 13, 2022
    risk 0.53cvss 8.1epss 0.01

    The One Click Plugin Updater WordPress plugin through 2.4.14 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and disable / hide the badge of the available updates and the related…

  • CVE-2022-1779HigJun 13, 2022
    risk 0.53cvss 8.1epss 0.01

    The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and delete specific posts, categories and attachments at once.

  • CVE-2022-1777HigJun 13, 2022
    risk 0.57cvss 8.8epss 0.01

    The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to be called by any authenticated users, such as subscriber. They are are protected with a nonce, however the nonce is leaked on the dashboard. This could allow…