VYPR

CVEs

102,253 total · page 1151 of 2,046

  • CVE-2022-30018HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.01

    Mobotix Control Center (MxCC) through 2.5.4.5 has Insufficiently Protected Credentials, Storing Passwords in a Recoverable Format via the MxCC.ini config file. The credential storage method in this software enables an attacker/user of the machine to gain admin access to the…

  • CVE-2021-41938HigMay 19, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulnerability in three locations.

  • CVE-2022-1785HigMay 19, 2022
    risk 0.00cvss 7.8epss 0.00

    Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.

  • CVE-2022-1183HigMay 19, 2022
    risk 0.49cvss 7.5epss 0.06

    On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and…

  • CVE-2022-1670HigMay 19, 2022
    risk 0.49cvss 7.5epss 0.01

    When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to bypass this restriction of validity to create extra user accounts above the initial number of invited users.

  • CVE-2022-30138HigMay 18, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows Print Spooler Elevation of Privilege Vulnerability

  • CVE-2022-30994HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 29240

  • CVE-2022-30993HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240

  • CVE-2022-30990HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Linux) before build 29240, Acronis Agent (Linux) before build 28037

  • CVE-2022-30033HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda TX9 Pro V22.03.02.10 is vulnerable to Buffer Overflow via the functtion setIPv6Status() in httpd module.

  • CVE-2022-25161HigMay 18, 2022
    risk 0.56cvss 8.6epss 0.04

    Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 17X**** or later and versions prior to 1.270, Mitsubishi Electric Mitsubishi Electric MELSEC iQ-F series FX5U-xMy/z(x=32,64,80,…

  • CVE-2022-22778HigMay 18, 2022
    risk 0.57cvss 8.8epss 0.00

    The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute Cross-Site Request Forgery (CSRF) on the affected system. A…

  • CVE-2022-22776HigMay 18, 2022
    risk 0.52cvss 8.0epss 0.01

    The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable vulnerabilities that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A…

  • CVE-2022-1734HigMay 18, 2022
    risk 0.00cvss 7.0epss 0.01

    A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine.

  • CVE-2022-0883HigMay 18, 2022
    risk 0.47cvss 7.3epss 0.00

    SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched.

  • CVE-2021-42704HigMay 18, 2022
    risk 0.51cvss 7.8epss 0.01

    Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code.

  • CVE-2022-28917HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.10

    Tenda AX12 v22.03.01.21_cn was discovered to contain a stack overflow via the lanIp parameter in /goform/AdvSetLanIp.

  • CVE-2022-22786HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.02

    The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update process. This issue could be used in a more sophisticated attack to trick a…

  • CVE-2022-22784HigMay 18, 2022
    risk 0.53cvss 8.1epss 0.04

    The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0 failed to properly parse XML stanzas in XMPP messages. This can allow a malicious user to break out of the current XMPP message context and create a new message context to have the…

  • CVE-2022-1767HigMay 18, 2022
    risk 0.00cvss 7.5epss 0.02

    Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.7.

  • CVE-2021-42852HigMay 18, 2022
    risk 0.52cvss 8.0epss 0.01

    A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device.

  • CVE-2021-42850HigMay 18, 2022
    risk 0.57cvss 8.8epss 0.00

    A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.

  • CVE-2021-3969HigMay 18, 2022
    risk 0.51cvss 7.8epss 0.02

    A Time of Check Time of Use (TOCTOU) vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3that could allow a local attacker to elevate privileges.

  • CVE-2021-3922HigMay 18, 2022
    risk 0.51cvss 7.8epss 0.02

    A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3 that could allow a local attacker to connect and interact with the IMController child process' named pipe.

  • CVE-2022-30065HigMay 18, 2022
    risk 0.51cvss 7.8epss 0.01

    A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.

  • CVE-2022-29518HigMay 18, 2022
    risk 0.46cvss 7.0epss 0.00

    Screen Creator Advance2, HMI GC-A2 series, and Real time remote monitoring and control tool Screen Creator Advance2 versions prior to Ver.0.1.1.3 Build01, HMI GC-A2 series(GC-A22W-CW, GC-A24W-C(W), GC-A26W-C(W), GC-A24, GC-A24-M, GC-A25, GC-A26, and GC-A26-J2), and Real time…

  • CVE-2022-27632HigMay 18, 2022
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Rebooter(WATCH BOOT nino RPC-M2C [End of Sale] all firmware versions, WATCH BOOT light RPC-M5C [End of Sale] all firmware versions, WATCH BOOT L-zero RPC-M4L [End of Sale] all firmware versions, WATCH BOOT mini RPC-M4H [End of…

  • CVE-2022-23067HigMay 18, 2022
    risk 0.00cvss 8.8epss 0.01

    ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer…

  • CVE-2022-1727HigMay 18, 2022
    risk 0.00cvss 8.8epss 0.01

    Improper Input Validation in GitHub repository jgraph/drawio prior to 18.0.6.

  • CVE-2022-1430HigMay 18, 2022
    risk 0.42cvss 7.5epss 0.01

    Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0.

  • CVE-2022-29643HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the macAddress parameter in the function setMacQos. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2022-29642HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the url parameter in the function setUrlFilterRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2022-29641HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the startTime and endTime parameters in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST…

  • CVE-2022-29640HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the comment parameter in the function setPortForwardRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2022-29639HigMay 18, 2022
    risk 0.53cvss 8.1epss 0.02

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a command injection vulnerability via the magicid parameter in the function uci_cloudupdate_config.

  • CVE-2022-29638HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the comment parameter in the function setIpQosRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2022-28955HigMay 18, 2022
    risk 0.52cvss 7.5epss 0.40

    An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php and category_view.php.

  • CVE-2022-30976HigMay 18, 2022
    risk 0.46cvss 7.1epss 0.01

    GPAC 2.0.0 misuses a certain Unicode utf8_wcslen (renamed gf_utf8_wcslen) function in utils/utf.c, resulting in a heap-based buffer over-read, as demonstrated by MP4Box.

  • CVE-2019-25061HigMay 18, 2022
    risk 0.49cvss 7.5epss 0.02

    The random_password_generator (aka RandomPasswordGenerator) gem through 1.0.0 for Ruby uses Kernel#rand to generate passwords, which, due to its cyclic nature, can facilitate password prediction.

  • CVE-2022-29174HigMay 17, 2022
    risk 0.00cvss 8.1epss 0.01

    countly-server is the server-side part of Countly, a product analytics solution. Prior to versions 22.03.7 and 21.11.4, a malicious actor who knows an account email address/username and full name specified in the database is capable of guessing the password reset token. The…

  • CVE-2022-1361HigMay 17, 2022
    risk 0.48cvss 7.4epss 0.01

    The affected On-Premise cnMaestro is vulnerable to a pre-auth data exfiltration through improper neutralization of special elements used in an SQL command. This could allow an attacker to exfiltrate data about other user’s accounts and devices.

  • CVE-2022-1360HigMay 17, 2022
    risk 0.53cvss 8.2epss 0.02

    The affected On-Premise cnMaestro is vulnerable to execution of code on the cnMaestro hosting server. This could allow a remote attacker to change server configuration settings.

  • CVE-2022-1356HigMay 17, 2022
    risk 0.46cvss 7.1epss 0.00

    cnMaestro is vulnerable to a local privilege escalation. By default, a user does not have root privileges. However, a user can run scripts as sudo, which could allow an attacker to gain root privileges when running user scripts outside allowed commands.

  • CVE-2022-28184HigMay 17, 2022
    risk 0.46cvss 7.1epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can access administrator- privileged registers, which may lead to denial of service, information…

  • CVE-2022-28183HigMay 17, 2022
    risk 0.50cvss 7.7epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause an out-of-bounds read, which may lead to denial of service and information disclosure.

  • CVE-2022-28182HigMay 17, 2022
    risk 0.55cvss 8.5epss 0.02

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the DirectX11 user mode driver (nvwgf2um/x.dll), where an unauthorized attacker on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution to cause denial…

  • CVE-2022-28181HigMay 17, 2022
    risk 0.55cvss 8.5epss 0.01

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution, denial of service,…

  • CVE-2022-24394HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.03

    Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “update_checkfile” value for the “filename” parameter. The vulnerability could allow a specially crafted HTTP request to execute system…

  • CVE-2022-24393HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.03

    Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica_upgrade” value for the “cpIp” parameter. The vulnerability could allow a specially crafted HTTP request to execute system…

  • CVE-2022-24392HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.03

    Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “feed_comm_test” value for the “feed” parameter. The vulnerability could allow a specially crafted HTTP request to execute system…