VYPR

CVEs

102,398 total · page 1144 of 2,048

  • CVE-2022-1765HigJun 13, 2022
    risk 0.57cvss 8.8epss 0.01

    The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache images from external domains on the server, which could lead to legal risks (due to copyright violations or licensing rules).

  • CVE-2022-1762HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The iQ Block Country WordPress plugin before 1.2.20 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers.

  • CVE-2022-1758HigJun 13, 2022
    risk 0.57cvss 8.8epss 0.01

    The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS as well as RCE when custom code is added via the…

  • CVE-2022-1412HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filenames, allowing any unauthenticated visitor to obtain potentially sensitive information like generated passwords.

  • CVE-2022-1202HigJun 13, 2022
    risk 0.51cvss 7.8epss 0.01

    The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, leading to a CSV injection vulnerability.

  • CVE-2022-0863HigJun 13, 2022
    risk 0.49cvss 7.2epss 0.23

    The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution.

  • CVE-2021-46818HigJun 13, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user…

  • CVE-2021-46817HigJun 13, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Media Encoder version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user…

  • CVE-2021-46816HigJun 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Adobe Premiere Pro version 15.4 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user…

  • CVE-2022-31040HigJun 13, 2022
    risk 0.00cvss 7.1epss 0.01

    Open Forms is an application for creating and publishing smart forms. Prior to versions 1.0.9 and 1.1.1, the cookie consent page in Open Forms contains an open redirect by injecting a `referer` querystring parameter and failing to validate the value. A malicious actor is able to…

  • CVE-2022-2064HigJun 13, 2022
    risk 0.50cvss 8.8epss 0.01

    Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+.

  • CVE-2022-2063HigJun 13, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Privilege Management in GitHub repository nocodb/nocodb prior to 0.91.7+.

  • CVE-2022-2062HigJun 13, 2022
    risk 0.42cvss 7.5epss 0.01

    Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+.

  • CVE-2017-20045HigJun 13, 2022
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Navetti PricePoint 4.6.0.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be…

  • CVE-2022-28704HigJun 13, 2022
    risk 0.47cvss 7.2epss 0.02

    Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to log in with the root privilege and perform an arbitrary operation if the product is in its default settings in which is set to accept SSH connections from the WAN…

  • CVE-2022-26834HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper access control vulnerability in Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 allows a remote attacker to obtain the information stored in the product because the product is set to accept HTTP connections from the WAN side by default.

  • CVE-2022-2013HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users would have access to the Script Console within their private space.

  • CVE-2022-2054HigJun 12, 2022
    risk 0.48cvss 8.4epss 0.01

    Code Injection in GitHub repository nuitka/nuitka prior to 0.9.

  • CVE-2021-41641HigJun 12, 2022
    risk 0.48cvss 8.4epss 0.00

    Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be used to gain access to any directory.

  • CVE-2022-30780HigJun 11, 2022
    risk 0.53cvss 7.5epss 0.56

    Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read_header_more in connections.c has a typo that disrupts use of multiple read operations on large headers.

  • CVE-2021-41738HigJun 11, 2022
    risk 0.57cvss 8.8epss 0.02

    ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execute system commands.

  • CVE-2022-32981HigJun 10, 2022
    risk 0.00cvss 7.8epss 0.01

    An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PEEKUSER and POKEUSER (aka PEEKUSR and POKEUSR) when accessing floating point registers.

  • CVE-2022-29095HigJun 10, 2022
    risk 0.54cvss 8.3epss 0.01

    Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability under specific…

  • CVE-2022-29094HigJun 10, 2022
    risk 0.46cvss 7.1epss 0.00

    Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability. Authenticated non-admin user could exploit the issue and delete or…

  • CVE-2022-29093HigJun 10, 2022
    risk 0.46cvss 7.1epss 0.00

    Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-admin user could exploit the issue and delete arbitrary files…

  • CVE-2022-29092HigJun 10, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system.

  • CVE-2022-25863HigJun 10, 2022
    risk 0.00cvss 8.1epss 0.02

    The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, due to its default configurations that are missing input sanitization. Exploiting this…

  • CVE-2022-25851HigJun 10, 2022
    risk 0.42cvss 7.5epss 0.02

    The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and never return.

  • CVE-2022-25845HigJun 10, 2022
    risk 0.47cvss 8.1epss 0.19

    The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vulnerability allows attacking remote servers. Workaround: If…

  • CVE-2022-24429HigJun 10, 2022
    risk 0.42cvss 7.5epss 0.01

    The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG file. An attacker can read arbitrary files from the file system and then show the file content as a converted PNG file.

  • CVE-2022-24376HigJun 10, 2022
    risk 0.40cvss 7.2epss 0.03

    All versions of package git-promise are vulnerable to Command Injection due to an inappropriate fix of a prior [vulnerability](https://security.snyk.io/vuln/SNYK-JS-GITPROMISE-567476) in this package. **Note:** Please note that the vulnerability will not be fixed. The README…

  • CVE-2022-24278HigJun 10, 2022
    risk 0.42cvss 7.5epss 0.02

    The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file.

  • CVE-2022-2042HigJun 10, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 8.2.

  • CVE-2018-17240HigJun 10, 2022
    risk 0.49cvss 7.5epss 0.04

    There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate sensitive information from the network configuration (e.g., username and password).

  • CVE-2022-22479HigJun 10, 2022
    risk 0.57cvss 8.8epss 0.00

    IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 225887.

  • CVE-2022-27502HigJun 10, 2022
    risk 0.51cvss 7.8epss 0.01

    RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operation executes %TEMP% files as SYSTEM.

  • CVE-2021-44582HigJun 10, 2022
    risk 0.57cvss 8.8epss 0.01

    A Privilege Escalation vulnerability exists in Sourcecodester Money Transfer Management System 1.0, which allows a remote malicious user to gain elevated privileges to the Admin role via any URL.

  • CVE-2021-44117HigJun 10, 2022
    risk 0.57cvss 8.8epss 0.01

    A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.

  • CVE-2017-20029HigJun 10, 2022
    risk 0.49cvss 7.3epss 0.20

    A vulnerability was found in PHPList 3.2.6 and classified as critical. This issue affects some unknown processing of the file /lists/index.php of the component Edit Subscription. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been…

  • CVE-2022-31043HigJun 10, 2022
    risk 0.42cvss 7.5epss 0.02

    Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, we should not forward the…

  • CVE-2022-31042HigJun 10, 2022
    risk 0.42cvss 7.5epss 0.02

    Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, or on making a request to a server…

  • CVE-2017-20025HigJun 9, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Solare Solar-Log 2.8.4-56/3.5.2-85. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Flash Memory. The manipulation leads to privilege escalation. The attack can be launched remotely.…

  • CVE-2017-20022HigJun 9, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been found in Solare Solar-Log 2.8.4-56/3.5.2-85 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to information disclosure. The attack can be initiated remotely. Upgrading to version 3.5.3-86 is able to address…

  • CVE-2022-31045HigJun 9, 2022
    risk 0.46cvss 7.0epss 0.01

    Istio is an open platform to connect, manage, and secure microservices. In affected versions ill-formed headers sent to Envoy in certain configurations can lead to unexpected memory access resulting in undefined behavior or crashing. Users are most likely at risk if they have an…

  • CVE-2022-30703HigJun 9, 2022
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an exposed dangerous method vulnerability that could allow an attacker to obtain access to leaked kernel addresses and disclose sensitive information. This vulnerability could also potentially be chained for…

  • CVE-2022-29250HigJun 9, 2022
    risk 0.53cvss 8.1epss 0.01

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to version 10.0.1 it is possible to add extra information by SQL injection on search pages. In order to exploit this…

  • CVE-2022-29228HigJun 9, 2022
    risk 0.00cvss 7.5epss 0.01

    Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter would try to invoke the remaining filters in the chain after emitting a local response, which triggers an ASSERT() in newer versions and corrupts memory on earlier versions.…

  • CVE-2022-29227HigJun 9, 2022
    risk 0.00cvss 7.5epss 0.01

    Envoy is a cloud-native high-performance edge/middle/service proxy. In versions prior to 1.22.1 if Envoy attempts to send an internal redirect of an HTTP request consisting of more than HTTP headers, there’s a lifetime bug which can be triggered. If while replaying the request…

  • CVE-2022-29225HigJun 9, 2022
    risk 0.00cvss 7.5epss 0.02

    Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 secompressors accumulate decompressed data into an intermediate buffer before overwriting the body in the decode/encodeBody. This may allow an attacker to zip bomb the decompressor by sending a small…

  • CVE-2022-30556HigJun 9, 2022
    risk 0.49cvss 7.5epss 0.05

    Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.