VYPR

CVEs

102,253 total · page 1149 of 2,046

  • CVE-2022-29333HigMay 24, 2022
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in CyberLink Power Director v14 allows attackers to escalate privileges via a crafted .exe file.

  • CVE-2022-23050HigMay 24, 2022
    risk 0.47cvss 7.2epss 0.05

    ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality.

  • CVE-2022-22977HigMay 24, 2022
    risk 0.46cvss 7.1epss 0.01

    VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is installed, may exploit this issue leading to a…

  • CVE-2021-42614HigMay 24, 2022
    risk 0.51cvss 7.8epss 0.01

    A use after free in info_width_internal in bk_info.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have unspecified other impact via a crafted text document.

  • CVE-2021-42613HigMay 24, 2022
    risk 0.51cvss 7.8epss 0.01

    A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly have other unspecified impact via a crafted text document.

  • CVE-2021-42612HigMay 24, 2022
    risk 0.51cvss 7.8epss 0.01

    A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have other unspecified impact via a crafted text document.

  • CVE-2021-3717HigMay 24, 2022
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, integrity, and availability. This…

  • CVE-2021-32969HigMay 24, 2022
    risk 0.51cvss 7.8epss 0.01

    Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to an out-of-bounds write condition, which may result in a system crash or allow an attacker to remotely execute arbitrary code.

  • CVE-2021-32965HigMay 24, 2022
    risk 0.51cvss 7.8epss 0.01

    Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2021-32962HigMay 24, 2022
    risk 0.53cvss 8.2epss 0.01

    The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2022-22495HigMay 24, 2022
    risk 0.57cvss 8.8epss 0.02

    IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941.

  • CVE-2022-29249HigMay 24, 2022
    risk 0.42cvss 7.5epss 0.01

    JavaEZ is a library that adds new functions to make Java easier. A weakness in JavaEZ 1.6 allows force decryption of locked text by unauthorized actors. The issue is NOT critical for non-secure applications, however may be critical in a situation where the highest levels of…

  • CVE-2014-125001HigMay 24, 2022
    risk 0.53cvss 8.1epss 0.04

    A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3. Affected is the file /cardo/api of the Cardo-Updater. Unauthenticated remote code execution with root permissions is possible. Firewalling or disabling the service is recommended.

  • CVE-2022-31261HigMay 24, 2022
    risk 0.49cvss 7.5epss 0.01

    An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML identity provider to be configured. In order to exploit the vulnerability, the attacker must know the unique SAML callback ID of the configured identity source. A…

  • CVE-2022-30843HigMay 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Room-rent-portal-site v1.0 is vulnerable to SQL Injection via /rrps/classes/Master.php?f=delete_category, id.

  • CVE-2022-29223HigMay 24, 2022
    risk 0.49cvss 7.5epss 0.01

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. In versions prior to 6.1.10, an attacker can cause a buffer overflow by providing the Azure RTOS USBX host stack a HUB descriptor with `bNbPorts` set to a value greater than `UX_MAX_TT` which defaults to…

  • CVE-2022-29221HigMay 24, 2022
    risk 0.51cvss 8.8epss 0.05

    Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or {include} file name. Sites that cannot fully…

  • CVE-2022-29219HigMay 24, 2022
    risk 0.42cvss 7.5epss 0.01

    Lodestar is a TypeScript implementation of the Ethereum Consensus specification. Prior to version 0.36.0, there is a possible consensus split given maliciously-crafted `AttesterSlashing` or `ProposerSlashing` being included on-chain. Because the developers represent `uint64`…

  • CVE-2022-29217HigMay 24, 2022
    risk 0.41cvss 7.4epss 0.01

    PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what algorithms are supported.…

  • CVE-2022-1850HigMay 24, 2022
    risk 0.46cvss 8.1epss 0.01

    Path Traversal in GitHub repository filegator/filegator prior to 7.8.0.

  • CVE-2022-30463HigMay 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Automotive Shop Management System v1.0 is vulnerable to SQL Injection via /asms/classes/Master.php?f=delete_product.

  • CVE-2022-30459HigMay 24, 2022
    risk 0.57cvss 8.8epss 0.01

    ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to SQL Injection via /simple_chat_bot/classes/Master.php?f=delete_response, id.

  • CVE-2021-42655HigMay 24, 2022
    risk 0.57cvss 8.8epss 0.01

    SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.

  • CVE-2022-26532HigMay 24, 2022
    risk 0.51cvss 7.8epss 0.05

    A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through…

  • CVE-2022-29309HigMay 24, 2022
    risk 0.49cvss 7.5epss 0.01

    mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery.

  • CVE-2022-29305HigMay 24, 2022
    risk 0.53cvss 8.1epss 0.01

    imgurl v2.31 was discovered to contain a Blind SQL injection vulnerability via /upload/localhost.

  • CVE-2022-29377HigMay 24, 2022
    risk 0.49cvss 7.5epss 0.01

    Totolink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a stacker overflow in the fread function at infostat.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via the parameter CONTENT_LENGTH.

  • CVE-2022-29376HigMay 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory.

  • CVE-2022-29002HigMay 23, 2022
    risk 0.57cvss 8.8epss 0.00

    A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add.

  • CVE-2022-28999HigMay 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Insecure permissions in the install directories and binaries of Dev-CPP v4.9.9.2 allows attackers to execute arbitrary code via overwriting the binary devcpp.exe.

  • CVE-2022-31489HigMay 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Inout Blockchain AltExchanger 1.2.1 allows index.php/home/about inoutio_language cookie SQL injection.

  • CVE-2022-31488HigMay 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Inout Blockchain AltExchanger 1.2.1 allows index.php/coins/update_marketboxslider marketcurrency SQL injection.

  • CVE-2022-31487HigMay 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Inout Blockchain AltExchanger 1.2.1 and Inout Blockchain FiatExchanger 2.2.1 allow Chart/TradingView/chart_content/master.php symbol SQL injection.

  • CVE-2022-1467HigMay 23, 2022
    risk 0.48cvss 7.4epss 0.01

    Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is…

  • CVE-2022-31467HigMay 23, 2022
    risk 0.51cvss 7.9epss 0.00

    A DLL hijacking vulnerability in the installed for Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, leading to execution of arbitrary code, via the installer not restricting the search path for required DLLs and then not…

  • CVE-2022-31466HigMay 23, 2022
    risk 0.51cvss 7.9epss 0.00

    Time of Check - Time of Use (TOCTOU) vulnerability in Quick Heal Total Security prior to 12.1.1.27 allows a local attacker to achieve privilege escalation, potentially leading to deletion of system files. This is achieved through exploiting the time between detecting a file as…

  • CVE-2021-32935HigMay 23, 2022
    risk 0.57cvss 8.8epss 0.02

    The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which could allow a remote attacker access to system level permission commands and local privilege escalation.

  • CVE-2022-28944HigMay 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan…

  • CVE-2022-30016HigMay 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Rescue Dispatch Management System 1.0 is vulnerable to Incorrect Access Control via http://localhost/rdms/admin/?page=system_info.

  • CVE-2022-30014HigMay 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account.

  • CVE-2021-41714HigMay 23, 2022
    risk 0.00cvss 7.7epss 0.01

    In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading attachments, a registered user can download arbitrary files on the Tipask server such as .env, /etc/passwd, laravel.log, causing infomation leakage.

  • CVE-2022-28998HigMay 23, 2022
    risk 0.53cvss 8.1epss 0.02

    Xlight FTP v3.9.3.2 was discovered to contain a stack-based buffer overflow which allows attackers to leak sensitive information via crafted code.

  • CVE-2022-28997HigMay 23, 2022
    risk 0.49cvss 7.5epss 0.02

    CSZCMS v1.3.0 allows attackers to execute a Server-Side Request Forgery (SSRF) which can be leveraged to leak sensitive data via a local file inclusion at /admin/filemanager/connector/.

  • CVE-2021-42586HigMay 23, 2022
    risk 0.57cvss 8.8epss 0.01

    A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.

  • CVE-2021-42585HigMay 23, 2022
    risk 0.57cvss 8.8epss 0.01

    A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.

  • CVE-2022-1809HigMay 21, 2022
    risk 0.00cvss 7.8epss 0.01

    Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to 5.7.0.

  • CVE-2022-31268HigMay 21, 2022
    risk 0.50cvss 7.5epss 0.10

    A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).

  • CVE-2022-31264HigMay 21, 2022
    risk 0.42cvss 7.5epss 0.01

    Solana solana_rbpf before 0.2.29 has an addition integer overflow via invalid ELF program headers. elf.rs has a panic via a malformed eBPF program.

  • CVE-2022-1752HigMay 21, 2022
    risk 0.00cvss 8.0epss 0.02

    Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.2.

  • CVE-2022-29216HigMay 21, 2022
    risk 0.44cvss 7.8epss 0.01

    TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is vulnerable to a code injection. This can be used to open a reverse shell. This code path was maintained for compatibility reasons…