VYPR

CVEs

102,253 total · page 1152 of 2,046

  • CVE-2022-24391HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in Fidelis Network and Deception CommandPost enables SQL injection through the web interface by an attacker with user level access. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address…

  • CVE-2022-24390HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in rconfig “remote_text_file” enables an attacker with user level access to the CLI to inject user level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as neighboring Fidelis components. The…

  • CVE-2022-24389HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in rconfig “cert_utils” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as neighboring Fidelis components. The vulnerability is…

  • CVE-2022-24388HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in rconfig “date” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as neighboring Fidelis components. The vulnerability is…

  • CVE-2022-1118HigMay 17, 2022
    risk 0.57cvss 8.6epss 0.11

    Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and prior (for Trusted Controllers)) do not limit the objects that can be deserialized. This allows attackers to craft a malicious…

  • CVE-2022-30688HigMay 17, 2022
    risk 0.00cvss 7.8epss 0.00

    needrestart 0.8 through 3.5 before 3.6 is prone to local privilege escalation. Regexes to detect the Perl, Python, and Ruby interpreters are not anchored, allowing a local user to escalate privileges when needrestart tries to detect if interpreters are using old source files.

  • CVE-2022-29429HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.01

    Remote Code Execution (RCE) in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site Request Forgery.

  • CVE-2022-1735HigMay 17, 2022
    risk 0.00cvss 7.8epss 0.01

    Classic Buffer Overflow in GitHub repository vim/vim prior to 8.2.4969.

  • CVE-2022-23673HigMay 17, 2022
    risk 0.47cvss 7.2epss 0.02

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security…

  • CVE-2022-23672HigMay 17, 2022
    risk 0.47cvss 7.2epss 0.02

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security…

  • CVE-2022-23671HigMay 17, 2022
    risk 0.49cvss 7.5epss 0.01

    A remote authenticated information disclosure vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security…

  • CVE-2022-23669HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.01

    A remote authorization bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

  • CVE-2022-22775HigMay 17, 2022
    risk 0.53cvss 8.1epss 0.01

    The Workspace client component of TIBCO Software Inc.'s TIBCO BPM Enterprise and TIBCO BPM Enterprise Distribution for TIBCO Silver Fabric contains difficult to exploit Reflected Cross Site Scripting (XSS) vulnerabilities that allow low privileged attackers with network access…

  • CVE-2022-22773HigMay 17, 2022
    risk 0.50cvss 7.7epss 0.01

    The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO…

  • CVE-2022-29581HigMay 17, 2022
    risk 0.00cvss 7.8epss 0.01

    Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions.

  • CVE-2022-1769HigMay 17, 2022
    risk 0.00cvss 7.8epss 0.00

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974.

  • CVE-2022-1733HigMay 17, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968.

  • CVE-2022-1116HigMay 17, 2022
    risk 0.00cvss 7.8epss 0.01

    Integer Overflow or Wraparound vulnerability in io_uring of Linux Kernel allows local attacker to cause memory corruption and escalate privileges to root. This issue affects: Linux Kernel versions prior to 5.4.189; version 5.4.24 and later versions.

  • CVE-2021-38872HigMay 17, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM DataPower Gateway 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a denial of service by consuming resources with multiple requests. IBM X-Force ID: 208348.

  • CVE-2020-4994HigMay 17, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM DataPower Gateway 10.0.1.0 through 10.0.1.4 and 2018.4.1.0 through 2018.4.1.17 could allow a remote user to cause a temporary denial of service by sending invalid HTTP requests. IBM X-Force ID: 192906.

  • CVE-2022-30007HigMay 17, 2022
    risk 0.47cvss 7.2epss 0.01

    GXCMS V1.5 has a file upload vulnerability in the background. The vulnerability is the template management page. You can edit any template content and then rename to PHP suffix file, after calling PHP file can control the server.

  • CVE-2022-30972HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Storable Configs Plugin 1.0 and earlier allows attackers to have Jenkins parse a local XML file (e.g., archived artifacts) that uses external entities for extraction of secrets from the Jenkins controller or…

  • CVE-2022-30971HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.01

    Jenkins Storable Configs Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-30969HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Autocomplete Parameter Plugin 1.1 and earlier allows attackers to execute arbitrary code without sandbox protection if the victim is an administrator.

  • CVE-2022-30958HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins SSH Plugin 2.6.1 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2022-30951HigMay 17, 2022
    risk 0.50cvss 8.8epss 0.01

    Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access control, potentially allowing users to start processes even if they're not allowed to log in.

  • CVE-2022-30950HigMay 17, 2022
    risk 0.50cvss 8.8epss 0.02

    Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library which has a buffer overflow vulnerability that may allow users able to connect to a named pipe to execute commands on the Windows agent machine.

  • CVE-2022-30948HigMay 17, 2022
    risk 0.42cvss 7.5epss 0.01

    Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.

  • CVE-2022-30947HigMay 17, 2022
    risk 0.42cvss 7.5epss 0.01

    Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories stored on the Jenkins controller's file system using local paths as SCM URLs, obtaining limited information about other projects' SCM contents.

  • CVE-2022-30945HigMay 17, 2022
    risk 0.48cvss 8.5epss 0.01

    Jenkins Pipeline: Groovy Plugin 2689.v434009a_31b_f1 and earlier allows loading any Groovy source files on the classpath of Jenkins and Jenkins plugins in sandboxed pipelines.

  • CVE-2022-1711HigMay 17, 2022
    risk 0.00cvss 7.5epss 0.06

    Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.5.

  • CVE-2021-42643HigMay 17, 2022
    risk 0.57cvss 8.8epss 0.02

    cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website server, and accessing this file can lead to a code execution vulnerability.

  • CVE-2022-1723HigMay 17, 2022
    risk 0.00cvss 7.5epss 0.02

    Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6.

  • CVE-2022-26650HigMay 17, 2022
    risk 0.49cvss 7.5epss 0.03

    In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions and characters…

  • CVE-2022-23667HigMay 16, 2022
    risk 0.47cvss 7.2epss 0.01

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security…

  • CVE-2022-30697HigMay 16, 2022
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 3640

  • CVE-2022-30696HigMay 16, 2022
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 3640

  • CVE-2022-30695HigMay 16, 2022
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Snap Deploy (Windows) before build 3640

  • CVE-2022-1679HigMay 16, 2022
    risk 0.51cvss 7.8epss 0.01

    A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system.

  • CVE-2021-23267HigMay 16, 2022
    risk 0.49cvss 7.6epss 0.01

    Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker static methods.

  • CVE-2022-30523HigMay 16, 2022
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow a low privileged local attacker to delete the contents of an arbitrary folder as SYSTEM which can then be used for privilege…

  • CVE-2022-1721HigMay 16, 2022
    risk 0.00cvss 7.5epss 0.02

    Path Traversal in WellKnownServlet in GitHub repository jgraph/drawio prior to 18.0.5. Read local files of the web application.

  • CVE-2022-1713HigMay 16, 2022
    risk 0.01cvss 7.5epss 0.09

    SSRF on /proxy in GitHub repository jgraph/drawio prior to 18.0.4. An attacker can make a request as the server and read its contents. This can lead to a leak of sensitive information.

  • CVE-2022-1409HigMay 16, 2022
    risk 0.47cvss 7.2epss 0.01

    The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as administrators to upload PHP files disguised as images and containing malicious PHP code

  • CVE-2022-1182HigMay 16, 2022
    risk 0.57cvss 8.8epss 0.01

    The Visual Slide Box Builder WordPress plugin through 3.2.9 does not sanitise and escape various parameters before using them in SQL statements via some of its AJAX actions available to any authenticated users (such as subscriber), leading to SQL Injections

  • CVE-2022-1103HigMay 16, 2022
    risk 0.61cvss 8.8epss 0.16

    The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE

  • CVE-2022-0573HigMay 16, 2022
    risk 0.57cvss 8.8epss 0.02

    JFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege Escalation and Remote Code Execution when a specially crafted request is sent by a low privileged authenticated user due to insufficient…

  • CVE-2021-25119HigMay 16, 2022
    risk 0.47cvss 7.2epss 0.01

    The AGIL WordPress plugin through 1.0 accepts all zip files and automatically extracts the zip file without validating the extracted file type. Allowing high privilege users such as admin to upload an arbitrary file like PHP, leading to RCE

  • CVE-2022-29623HigMay 16, 2022
    risk 0.44cvss 7.8epss 0.01

    An arbitrary file upload vulnerability in the file upload module of Express Connect-Multiparty 2.2.0 allows attackers to execute arbitrary code via a crafted PDF file. NOTE: the Supplier has not verified this vulnerability report.

  • CVE-2021-42870HigMay 16, 2022
    risk 0.49cvss 7.5epss 0.01

    ACCEL-PPP 1.12.0 has an out-of-bounds read in post_msg when processing a call_clear_request.