VYPR

CVEs

102,253 total · page 1150 of 2,046

  • CVE-2022-29215HigMay 21, 2022
    risk 0.00cvss 7.5epss 0.01

    RegionProtect is a plugin that allows users to manage certain events in certain regions of the world. Versions prior to 1.1.0 contain a YAML injection vulnerability that can cause an instant server crash if the passed arguments are not matched. Version 1.1.0 contains a patch for…

  • CVE-2022-29190HigMay 21, 2022
    risk 0.42cvss 7.5epss 0.02

    Pion DTLS is a Go implementation of Datagram Transport Layer Security. Prior to version 2.1.4, an attacker can send packets that sends Pion DTLS into an infinite loop when processing. Version 2.1.4 contains a patch for this issue. There are currently no known workarounds…

  • CVE-2022-31258HigMay 20, 2022
    risk 0.53cvss 8.2epss 0.00

    In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink.

  • CVE-2022-29208HigMay 20, 2022
    risk 0.39cvss 7.1epss 0.00

    TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implementation of `tf.raw_ops.EditDistance` has incomplete validation. Users can pass negative values to cause a segmentation fault based denial of service. In…

  • CVE-2022-22973HigMay 20, 2022
    risk 0.51cvss 7.8epss 0.02

    VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'.

  • CVE-2022-29184HigMay 20, 2022
    risk 0.00cvss 8.8epss 0.04

    GoCD is a continuous delivery server. In GoCD versions prior to 22.1.0, it is possible for existing authenticated users who have permissions to edit or create pipeline materials or pipeline configuration repositories to get remote code execution capability on the GoCD server via…

  • CVE-2022-24434HigMay 20, 2022
    risk 0.42cvss 7.5epss 0.03

    This affects all versions of package dicer. A malicious attacker can send a modified form to server, and crash the nodejs service. An attacker could sent the payload again and again so that the service continuously crashes.

  • CVE-2022-29181HigMay 20, 2022
    risk 0.47cvss 8.2epss 0.03

    Nokogiri is an open source XML and HTML library for Ruby. Nokogiri prior to version 1.13.6 does not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated…

  • CVE-2022-29179HigMay 20, 2022
    risk 0.42cvss 7.5epss 0.00

    Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Prior to versions 1.9.16, 1.10.11, and 1.11.15, if an attacker is able to perform a container escape of a container running as root on a host where…

  • CVE-2022-29178HigMay 20, 2022
    risk 0.50cvss 8.8epss 0.00

    Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Cilium prior to versions 1.9.16, 1.10.11, and 1.11.15 contains an incorrect default permissions vulnerability. Operating Systems with users belonging…

  • CVE-2022-28990HigMay 20, 2022
    risk 0.44cvss 7.8epss 0.00

    WASM3 v0.5.0 was discovered to contain a heap overflow via the component /wabt/bin/poc.wasm.

  • CVE-2022-1770HigMay 20, 2022
    risk 0.00cvss 8.8epss 0.02

    Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.

  • CVE-2022-31245HigMay 20, 2022
    risk 0.58cvss 8.8epss 0.06

    mailcow before 2022-05d allows a remote authenticated user to inject OS commands and escalate privileges to domain admin via the --debug option in conjunction with the ---PIPEMESS option in Sync Jobs.

  • CVE-2021-30028HigMay 20, 2022
    risk 0.47cvss 7.2epss 0.01

    SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) to access the TELNET service, allowing attackers to erase/read/write the firmware remotely.

  • CVE-2022-29882HigMay 20, 2022
    risk 0.46cvss 7.1epss 0.01

    A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not handle uploaded files correctly. An unauthenticated attacker could take advantage of this situation to store an XSS attack, which could - when a legitimate user accesses the error logs…

  • CVE-2022-29878HigMay 20, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices use a limited range for challenges that are sent during the unencrypted challenge-response communication. An unauthenticated attacker could capture a valid challenge-response pair generated by…

  • CVE-2022-29876HigMay 20, 2022
    risk 0.46cvss 7.1epss 0.01

    A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not properly handle the input of a GET request parameter. The provided argument is directly reflected in the web server response. This could allow an unauthenticated attacker to perform…

  • CVE-2022-29874HigMay 20, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not encrypt web traffic with clients but communicate in cleartext via HTTP. This could allow an unauthenticated attacker to capture the traffic and interfere with the functionality of the…

  • CVE-2022-29872HigMay 20, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not properly validate parameters of POST requests. This could allow an authenticated attacker to set the device to a denial of service state or to control the program counter and, thus,…

  • CVE-2022-29801HigMay 20, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server…

  • CVE-2022-29320HigMay 20, 2022
    risk 0.51cvss 7.8epss 0.00

    MiniTool Partition Wizard v12.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

  • CVE-2022-29033HigMay 20, 2022
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The CGM_NIST_Loader.dll library is vulnerable to uninitialized pointer free while…

  • CVE-2022-29032HigMay 20, 2022
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The CGM_NIST_Loader.dll library contains a double free vulnerability while parsing…

  • CVE-2022-28992HigMay 20, 2022
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) in Online Banquet Booking System v1.0 allows attackers to change admin credentials via a crafted POST request.

  • CVE-2022-28991HigMay 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Multi Store Inventory Management System v1.0 was discovered to contain an information disclosure vulnerability which allows attackers to access sensitive files.

  • CVE-2022-27653HigMay 20, 2022
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in Simcenter Femap (All versions < V2022.2). The affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted .NEU files. This could allow an attacker to execute code in the…

  • CVE-2022-27095HigMay 20, 2022
    risk 0.51cvss 7.8epss 0.00

    BattlEye v0.9 contains an unquoted service path which allows attackers to escalate privileges to the system level.

  • CVE-2022-26634HigMay 20, 2022
    risk 0.51cvss 7.8epss 0.00

    HMA VPN v5.3.5913.0 contains an unquoted service path which allows attackers to escalate privileges to the system level.

  • CVE-2022-24290HigMay 20, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9), Teamcenter V13.1 (All versions), Teamcenter V13.2 (All versions < V13.2.0.8), Teamcenter V13.3 (All versions < V13.3.0.3), Teamcenter V14.0 (All…

  • CVE-2022-24287HigMay 20, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC06), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1 UC01), SIMATIC WinCC Runtime Professional V16 and earlier (All versions), SIMATIC WinCC Runtime Professional…

  • CVE-2022-24044HigMay 20, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The login functionality of the application does…

  • CVE-2022-1784HigMay 20, 2022
    risk 0.00cvss 7.5epss 0.02

    Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.8.

  • CVE-2022-30551HigMay 20, 2022
    risk 0.49cvss 7.5epss 0.02

    OPC UA Legacy Java Stack 2022-04-01 allows a remote attacker to cause a server to stop processing messages by sending crafted messages that exhaust available resources.

  • CVE-2022-25227HigMay 20, 2022
    risk 0.57cvss 8.8epss 0.01

    Thinfinity VNC v4.0.0.1 contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can trick a user into browse malicious site, to obtain an 'ID' that can be used to send websocket requests and achieve RCE.

  • CVE-2022-28964HigMay 20, 2022
    risk 0.46cvss 7.1epss 0.00

    An arbitrary file write vulnerability in Avast Premium Security before v21.11.2500 (build 21.11.6809.528) allows attackers to cause a Denial of Service (DoS) via a crafted DLL file.

  • CVE-2022-21500HigMay 20, 2022
    risk 0.54cvss 7.5epss 0.71

    Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite. Successful attacks of this…

  • CVE-2020-4107HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.00

    HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalation of privileges, denial of service, or information disclosure.

  • CVE-2022-29304HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.01

    Online Sports Complex Booking System 1.0 is vulnerable to SQL Injection via /classes/master.php?f=delete_ Facility.

  • CVE-2022-28961HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.02

    Spip Web Framework v3.1.13 and below was discovered to contain multiple SQL injection vulnerabilities at /ecrire via the lier_trad and where parameters.

  • CVE-2022-28960HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.02

    A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire.

  • CVE-2022-28948HigMay 19, 2022
    risk 0.42cvss 7.5epss 0.04

    An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.

  • CVE-2022-28946HigMay 19, 2022
    risk 0.42cvss 7.5epss 0.01

    An issue in the component ast/parser.go of Open Policy Agent v0.39.0 causes the application to incorrectly interpret every expression, causing a Denial of Service (DoS) via triggering out-of-range memory access.

  • CVE-2022-30618HigMay 19, 2022
    risk 0.49cvss 7.5epss 0.01

    An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for API users if content types accessible to the authenticated user contain relationships to API users (from:users-permissions). There are…

  • CVE-2022-30617HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.01

    An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for other admin panel users that have a relationship (e.g., created by, updated by) with content accessible to the authenticated user. For…

  • CVE-2022-1423HigMay 19, 2022
    risk 0.46cvss 7.1epss 0.01

    Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache…

  • CVE-2020-16231HigMay 19, 2022
    risk 0.47cvss 7.2epss 0.01

    The affected Bachmann Electronic M-Base Controllers of version MSYS v1.06.14 and later use weak cryptography to protect device passwords. Affected controllers that are actively supported include MX207, MX213, MX220, MC206, MC212, MC220, and MH230 hardware controllers, and…

  • CVE-2020-14496HigMay 19, 2022
    risk 0.54cvss 8.3epss 0.01

    Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and…

  • CVE-2022-1796HigMay 19, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 8.2.4979.

  • CVE-2021-26631HigMay 19, 2022
    risk 0.52cvss 8.0epss 0.01

    Improper input validation vulnerability in Mangboard commerce package could lead to occur for abnormal request. A remote attacker can exploit this vulnerability to manipulate the total order amount into a negative number and then pay for the order.

  • CVE-2021-26630HigMay 19, 2022
    risk 0.51cvss 7.8epss 0.01

    Improper input validation vulnerability in HANDY Groupware’s ActiveX moudle allows attackers to download or execute arbitrary files. This vulnerability can be exploited by using the file download or execution path as the parameter value of the vulnerable function.