VYPR

CVEs

102,398 total · page 1145 of 2,048

  • CVE-2022-30522HigJun 9, 2022
    risk 0.56cvss 7.5epss 0.90

    If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.

  • CVE-2022-2037HigJun 9, 2022
    risk 0.00cvss 8.0epss 0.01

    Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0.

  • CVE-2022-2027HigJun 9, 2022
    risk 0.00cvss 8.0epss 0.01

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.

  • CVE-2022-29404HigJun 9, 2022
    risk 0.49cvss 7.5epss 0.06

    In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.

  • CVE-2022-26377HigJun 9, 2022
    risk 0.50cvss 7.5epss 0.20

    Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version…

  • CVE-2022-25153HigJun 9, 2022
    risk 0.51cvss 7.8epss 0.00

    The ITarian Endpoint Manage Communication Client, prior to version 6.43.41148.21120, is compiled using insecure OpenSSL settings. Due to this setting, a malicious actor with low privileges access to a system can escalate his privileges to SYSTEM abusing an insecure openssl.conf…

  • CVE-2022-25151HigJun 9, 2022
    risk 0.49cvss 7.5epss 0.01

    Within the Service Desk module of the ITarian platform (SAAS and on-premise), a remote attacker can obtain sensitive information, caused by the failure to set the HTTP Only flag. A remote attacker could exploit this vulnerability to gain access to the management interface by…

  • CVE-2022-1993HigJun 9, 2022
    risk 0.50cvss 8.1epss 0.52

    Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.

  • CVE-2016-15002HigJun 9, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in MONyog Ultimate 6.63. This affects an unknown part of the component Cookie Handler. The manipulation of the argument HasServerEdit/IsAdmin leads to privilege escalation. It is possible to initiate the attack…

  • CVE-2022-31214HigJun 9, 2022
    risk 0.51cvss 7.8epss 0.00

    A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container that is accepted by the Firejail setuid-root program as a join target, a local attacker can enter an environment in which the Linux user namespace is still the…

  • CVE-2022-2019HigJun 9, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in SourceCodester Prison Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Users.php?f=save of the component New User Creation. The manipulation leads to improper authorization.…

  • CVE-2022-2000HigJun 9, 2022
    risk 0.00cvss 7.8epss 0.02

    Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-23138HigJun 9, 2022
    risk 0.49cvss 7.5epss 0.01

    ZTE's MF297D product has cryptographic issues vulnerability. Due to the use of weak random values, the security of the device is reduced, and it may face the risk of attack.

  • CVE-2022-1998HigJun 9, 2022
    risk 0.00cvss 7.8epss 0.00

    A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system.

  • CVE-2021-40961HigJun 9, 2022
    risk 0.57cvss 8.8epss 0.02

    CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inject arbitrary SQL language without using the '.

  • CVE-2022-31019HigJun 9, 2022
    risk 0.42cvss 7.5epss 0.02

    Vapor is a server-side Swift HTTP web framework. When using automatic content decoding an attacker can craft a request body that can make the server crash with the following request: `curl -d "array[_0][0][array][_0][0][array]$(for f in $(seq 1100); do echo -n '[_0][0][array]';…

  • CVE-2021-40668HigJun 9, 2022
    risk 0.53cvss 8.1epss 0.01

    The Android application HTTP File Server (Version 1.4.1) by 'slowscript' is affected by a path traversal vulnerability that permits arbitrary directory listing, file read, and file write.

  • CVE-2022-29255HigJun 9, 2022
    risk 0.46cvss 8.2epss 0.01

    Vyper is a Pythonic Smart Contract Language for the ethereum virtual machine. In versions prior to 0.3.4 when a calling an external contract with no return value, the contract address (including side effects) could be evaluated twice. This may result in incorrect outcomes for…

  • CVE-2022-31649HigJun 9, 2022
    risk 0.49cvss 7.5epss 0.01

    ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.

  • CVE-2022-30075HigJun 9, 2022
    risk 0.63cvss 8.8epss 0.34

    In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote code execution due to improper validation.

  • CVE-2022-25806HigJun 9, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES key in the PrefDBCredentials class allows an attacker, who has discovered encrypted superuser credentials, to decrypt those credentials using a static 8-byte DES key.

  • CVE-2022-31496HigJun 9, 2022
    risk 0.57cvss 8.8epss 0.02

    LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access.

  • CVE-2022-29014HigJun 9, 2022
    risk 0.50cvss 7.5epss 0.11

    A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files.

  • CVE-2022-31325HigJun 8, 2022
    risk 0.50cvss 7.2epss 0.05

    There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm/WhyCameEditor.php.

  • CVE-2022-28382HigJun 8, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in certain Verbatim drives through 2022-03-31. Due to the use of an insecure encryption AES mode (Electronic Codebook, aka ECB), an attacker may be able to extract information even from encrypted data, for example by observing repeating byte patterns. The…

  • CVE-2022-24296HigJun 8, 2022
    risk 0.49cvss 7.5epss 0.01

    Use of a Broken or Risky Cryptographic Algorithm vulnerability in Air Conditioning System G-150AD Ver. 3.21 and prior, Air Conditioning System AG-150A-A Ver. 3.21 and prior, Air Conditioning System AG-150A-J Ver. 3.21 and prior, Air Conditioning System GB-50AD Ver. 3.21 and…

  • CVE-2021-36710HigJun 8, 2022
    risk 0.57cvss 8.8epss 0.00

    ToaruOS 1.99.2 is affected by incorrect access control via the kernel. Improper MMU management and having a low GDT address allows it to be mapped in userland. A call gate can then be written to escalate to CPL 0.

  • CVE-2020-14125HigJun 8, 2022
    risk 0.49cvss 7.5epss 0.07

    A denial of service vulnerability exists in some Xiaomi models of phones. The vulnerability is caused by out-of-bound read/write and can be exploited by attackers to make denial of service.

  • CVE-2022-30790HigJun 8, 2022
    risk 0.51cvss 7.8epss 0.01

    Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.

  • CVE-2022-1683HigJun 8, 2022
    risk 0.57cvss 8.8epss 0.02

    The amtyThumb WordPress plugin through 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement via its shortcode, leading to an SQL injection and is exploitable by any authenticated user (and not just Author+ like the original advisory mention) due to…

  • CVE-2022-1703HigJun 8, 2022
    risk 0.58cvss 8.8epss 0.12

    Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inject OS Commands which potentially leads to remote command execution vulnerability or denial of service (DoS) attack.

  • CVE-2022-24065HigJun 8, 2022
    risk 0.46cvss 8.1epss 0.04

    The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The…

  • CVE-2022-30746HigJun 7, 2022
    risk 0.49cvss 7.5epss 0.01

    Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.

  • CVE-2022-30713HigJun 7, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-30712HigJun 7, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-30711HigJun 7, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-30710HigJun 7, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-1708HigJun 7, 2022
    risk 0.42cvss 7.5epss 0.03

    A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution, and…

  • CVE-2020-36542HigJun 7, 2022
    risk 0.41cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in Demokratian. This affects an unknown part of the file install/install3.php. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…

  • CVE-2020-36541HigJun 7, 2022
    risk 0.41cvss 7.3epss 0.01

    A vulnerability was found in Demokratian. It has been rated as critical. Affected by this issue is some unknown functionality of the file basicos_php/genera_select.php. The manipulation of the argument id_provincia with the input -1%20union%20all%20select%201,2,3,4,database()…

  • CVE-2020-36529HigJun 7, 2022
    risk 0.58cvss 8.8epss 0.04

    A vulnerability classified as critical has been found in SevOne Network Management System up to 5.7.2.22. This affects the file traceroute.php of the Traceroute Handler. The manipulation leads to privilege escalation with a command injection. It is possible to initiate the…

  • CVE-2019-9972HigJun 7, 2022
    risk 0.57cvss 8.8epss 0.02

    PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges because of " followed by " mishandling.

  • CVE-2019-9971HigJun 7, 2022
    risk 0.57cvss 8.8epss 0.02

    PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tcpdump command, without a password. This occurs because the -z (aka postrotate-command) option to tcpdump can be unsafe when used…

  • CVE-2022-31028HigJun 7, 2022
    risk 0.00cvss 7.5epss 0.03

    MinIO is a multi-cloud object storage solution. Starting with version RELEASE.2019-09-25T18-25-51Z and ending with version RELEASE.2022-06-02T02-11-04Z, MinIO is vulnerable to an unending go-routine buildup while keeping connections established due to HTTP clients not closing…

  • CVE-2022-29564HigJun 7, 2022
    risk 0.49cvss 7.5epss 0.01

    Jamf Private Access before 2022-05-16 has Incorrect Access Control, in which an unauthorized user can reach a system in the internal infrastructure, aka WND-44801.

  • CVE-2021-37589HigJun 7, 2022
    risk 0.54cvss 7.5epss 0.31

    Virtua Cobranca before 12R allows SQL Injection on the login page.

  • CVE-2022-27438HigJun 6, 2022
    risk 0.53cvss 8.1epss 0.02

    Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability,…

  • CVE-2022-30469HigJun 6, 2022
    risk 0.57cvss 8.8epss 0.01

    In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman&section=get&page=grid` leads to SQL injection.

  • CVE-2022-29631HigJun 6, 2022
    risk 0.42cvss 7.5epss 0.01

    Jodd HTTP v6.0.9 was discovered to contain multiple CLRF injection vulnerabilities via the components jodd.http.HttpRequest#set and `jodd.http.HttpRequest#send. These vulnerabilities allow attackers to execute Server-Side Request Forgery (SSRF) via a crafted TCP payload.

  • CVE-2022-30587HigJun 6, 2022
    risk 0.49cvss 7.5epss 0.01

    Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure.