VYPR

CVEs

102,398 total · page 1146 of 2,048

  • CVE-2022-32275HigJun 6, 2022
    risk 0.49cvss 7.5epss 0.09

    Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign error page, not /etc/passwd…

  • CVE-2022-30586HigJun 6, 2022
    risk 0.47cvss 7.2epss 0.01

    Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to code execution.

  • CVE-2022-22396HigJun 6, 2022
    risk 0.49cvss 7.5epss 0.01

    Credentials are printed in clear text in the IBM Spectrum Protect Plus 10.1.0.0 through 10.1.9.3 virgo log file in certain cases. Credentials could be the remote vSnap, offload targets, or VADP credentials depending on the operation performed. Credentials that are using API key…

  • CVE-2022-23712HigJun 6, 2022
    risk 0.49cvss 7.5epss 0.08

    A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.

  • CVE-2022-21757HigJun 6, 2022
    risk 0.49cvss 7.5epss 0.01

    In WIFI Firmware, there is a possible system crash due to a missing count check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06468894; Issue ID: ALPS06468894.

  • CVE-2022-21745HigJun 6, 2022
    risk 0.57cvss 8.8epss 0.00

    In WIFI Firmware, there is a possible memory corruption due to a use after free. This could lead to remote escalation of privilege, when devices are connecting to the attacker-controllable Wi-Fi hotspot, with no additional execution privileges needed. User interaction is not…

  • CVE-2022-31486HigJun 6, 2022
    risk 0.57cvss 8.8epss 0.01

    An authenticated attacker can send a specially crafted route to the “edit_route.cgi” binary and have it execute shell commands. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware…

  • CVE-2022-31484HigJun 6, 2022
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to…

  • CVE-2022-31482HigJun 6, 2022
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated attacker can send a specially crafted unauthenticated HTTP request to the device that can overflow a buffer. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware…

  • CVE-2022-31480HigJun 6, 2022
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain…

  • CVE-2022-1940HigJun 6, 2022
    risk 0.51cvss 7.7epss 0.06

    A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially…

  • CVE-2021-41932HigJun 6, 2022
    risk 0.57cvss 8.8epss 0.01

    A blind SQL injection vulnerability in search form in TeamMate+ Audit version 28.0.19.0 allows any authenticated user to create malicious SQL injections, which can result in complete database compromise, gaining information about other users, unauthorized access to audit data…

  • CVE-2022-30860HigJun 6, 2022
    risk 0.49cvss 7.2epss 0.24

    FUDforum 3.1.2 is vulnerable to Remote Code Execution through Upload File feature of File Administration System in Admin Control Panel.

  • CVE-2022-32291HigJun 5, 2022
    risk 0.57cvss 8.8epss 0.02

    In Real Player through 20.1.0.312, attackers can execute arbitrary code by placing a UNC share pathname (for a DLL file) in a RAM file.

  • CVE-2022-29778HigJun 3, 2022
    risk 0.57cvss 8.8epss 0.03

    D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtualServerSettings.php

  • CVE-2021-42893HigJun 3, 2022
    risk 0.49cvss 7.5epss 0.01

    In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization through getSysStatusCfg.

  • CVE-2021-42891HigJun 3, 2022
    risk 0.49cvss 7.5epss 0.01

    In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, etc.) without authorization.

  • CVE-2021-42889HigJun 3, 2022
    risk 0.49cvss 7.5epss 0.01

    In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can obtain sensitive information (wifikey, wifiname, etc.) without authorization.

  • CVE-2021-42886HigJun 3, 2022
    risk 0.49cvss 7.5epss 0.02

    TOTOLINK EX1200T V4.1.2cu.5215 contains an information disclosure vulnerability where an attacker can get the apmib configuration file without authorization, and usernames and passwords can be found in the decoded file.

  • CVE-2022-1987HigJun 3, 2022
    risk 0.00cvss 8.1epss 0.01

    Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.

  • CVE-2022-32268HigJun 3, 2022
    risk 0.57cvss 8.8epss 0.02

    StarWind SAN and NAS v0.2 build 1914 allow remote code execution. A flaw was found in REST API in StarWind Stack. REST command, which allows changing the hostname, doesn’t check a new hostname parameter. It goes directly to bash as part of a script. An attacker with non-root…

  • CVE-2022-30238HigJun 2, 2022
    risk 0.54cvss 8.3epss 0.01

    A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when an attacker hijacks a session. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)

  • CVE-2022-30237HigJun 2, 2022
    risk 0.53cvss 8.2epss 0.00

    A CWE-311: Missing Encryption of Sensitive Data vulnerability exists that could allow authentication credentials to be recovered when an attacker breaks the encoding. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)

  • CVE-2022-30236HigJun 2, 2022
    risk 0.53cvss 8.2epss 0.01

    A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an attacker uses cross-domain attacks. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)

  • CVE-2022-30235HigJun 2, 2022
    risk 0.56cvss 8.6epss 0.01

    A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow unauthorized access when an attacker uses brute force. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)

  • CVE-2022-30232HigJun 2, 2022
    risk 0.52cvss 8.0epss 0.01

    A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and modify a request on the same network or has configuration access to an ION device on the network. Affected Products: Wiser Smart,…

  • CVE-2022-29594HigJun 2, 2022
    risk 0.51cvss 7.8epss 0.00

    eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM.

  • CVE-2022-31463HigJun 2, 2022
    risk 0.53cvss 8.2epss 0.01

    Owl Labs Meeting Owl 5.2.0.15 does not require a password for Bluetooth commands, because only client-side authentication is used.

  • CVE-2022-31461HigJun 2, 2022
    risk 0.48cvss 7.4epss 0.01

    Owl Labs Meeting Owl 5.2.0.15 allows attackers to deactivate the passcode protection mechanism via a certain c 11 message.

  • CVE-2022-31460HigJun 2, 2022
    risk 0.48cvss 7.4epss 0.03

    Owl Labs Meeting Owl 5.2.0.15 allows attackers to activate Tethering Mode with hard-coded hoothoot credentials via a certain c 150 value.

  • CVE-2022-31459HigJun 2, 2022
    risk 0.48cvss 7.4epss 0.01

    Owl Labs Meeting Owl 5.2.0.15 allows attackers to retrieve the passcode hash via a certain c 10 value over Bluetooth.

  • CVE-2022-32250HigJun 2, 2022
    risk 0.00cvss 7.8epss 0.03

    net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.

  • CVE-2022-29084HigJun 2, 2022
    risk 0.53cvss 8.1epss 0.02

    Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability to brute-force passwords and gain access to the system as…

  • CVE-2022-22557HigJun 2, 2022
    risk 0.49cvss 7.5epss 0.00

    PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker…

  • CVE-2021-42877HigJun 2, 2022
    risk 0.49cvss 7.5epss 0.02

    TOTOLINK EX1200T V4.1.2cu.5215 contains a denial of service vulnerability in function RebootSystem of the file lib/cste_modules/system which can reboot the system.

  • CVE-2021-45982HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.01

    NetScout nGeniusONE 6.3.2 allows Arbitrary File Upload by a privileged user.

  • CVE-2022-31018HigJun 2, 2022
    risk 0.42cvss 7.5epss 0.02

    Play Framework is a web framework for Java and Scala. A denial of service vulnerability has been discovered in verions 2.8.3 through 2.8.15 of Play's forms library, in both the Scala and Java APIs. This can occur when using either the `Form#bindFromRequest` method on a JSON…

  • CVE-2022-32028HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.05

    Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_user.php?id=.

  • CVE-2022-32027HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.01

    Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/index.php?page=manage_car&id=.

  • CVE-2022-32026HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.05

    Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_booking.php?id=.

  • CVE-2022-32025HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.05

    Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/view_car.php?id=.

  • CVE-2022-32024HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.05

    Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.

  • CVE-2022-32022HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.05

    Car Rental Management System v1.0 is vulnerable to SQL Injection via /ip/car-rental-management-system/admin/ajax.php?action=login.

  • CVE-2022-32021HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.01

    Car Rental Management System v1.0 is vulnerable to SQL Injection via /car-rental-management-system/admin/manage_movement.php?id=.

  • CVE-2022-32018HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.05

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=hiring&search=.

  • CVE-2022-32017HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.01

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=bytitle.

  • CVE-2022-32016HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.01

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=bycompany.

  • CVE-2022-32015HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.05

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=category&search=.

  • CVE-2022-32014HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.01

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=byfunction.

  • CVE-2022-32013HigJun 2, 2022
    risk 0.47cvss 7.2epss 0.01

    Complete Online Job Search System v1.0 is vulnerable to SQL Injection via eris/admin/category/index.php?view=edit&id=.