VYPR

CVEs

102,253 total · page 1153 of 2,046

  • CVE-2022-30012HigMay 16, 2022
    risk 0.49cvss 7.5epss 0.02

    In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple parameters, and database information can be obtained through injection.

  • CVE-2022-30782HigMay 16, 2022
    risk 0.49cvss 7.5epss 0.01

    Openmoney API through 2020-06-29 uses the JavaScript Math.random function, which does not provide cryptographically secure random numbers.

  • CVE-2022-29588HigMay 16, 2022
    risk 0.49cvss 7.5epss 0.02

    Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS and /etc/shadow files.

  • CVE-2022-29586HigMay 16, 2022
    risk 0.48cvss 7.4epss 0.00

    Konica Minolta bizhub MFP devices before 2022-04-14 allow a Sandbox Escape. An attacker must attach a keyboard to a USB port, press F12, and then escape from the kiosk mode.

  • CVE-2022-30781HigMay 16, 2022
    risk 0.52cvss 7.5epss 0.88

    Gitea before 1.16.7 does not escape git fetch remote.

  • CVE-2022-30763HigMay 16, 2022
    risk 0.49cvss 7.5epss 0.02

    Janet before 1.22.0 mishandles arrays.

  • CVE-2022-30049HigMay 15, 2022
    risk 0.49cvss 7.5epss 0.01

    A Server-Side Request Forgery (SSRF) in Rebuild v2.8.3 allows attackers to obtain the real IP address and scan Intranet information via the fileurl parameter.

  • CVE-2022-28937HigMay 15, 2022
    risk 0.49cvss 7.5epss 0.01

    FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node, via an invalid proposal with an invalid header, will cause normal nodes to stop producing new blocks and processing new clients' requests.

  • CVE-2022-28936HigMay 15, 2022
    risk 0.49cvss 7.5epss 0.01

    FISCO-BCOS release-3.0.0-rc2 was discovered to contain an issue where a malicious node can trigger an integer overflow and cause a Denial of Service (DoS) via an unusually large viewchange message packet.

  • CVE-2021-41965HigMay 15, 2022
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue an arbitrary SQL command to the database through the unsanitized EN_tyid, theID and EID fields used when an Edit action on an existing record is being…

  • CVE-2022-30708HigMay 15, 2022
    risk 0.00cvss 8.8epss 0.04

    Webmin through 1.991, when the Authentic theme is used, allows remote code execution when a user has been manually created (i.e., not created in Virtualmin or Cloudmin). This occurs because settings-editor_write.cgi does not properly restrict the file parameter.

  • CVE-2022-24831HigMay 14, 2022
    risk 0.00cvss 8.3epss 0.01

    OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). Versions prior to 3.16.1 are vulnerable to SQL injection due to the use of string concatenation to create SQL queries instead of prepared statements. No known workarounds…

  • CVE-2022-25865HigMay 13, 2022
    risk 0.46cvss 8.1epss 0.07

    The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection. When calling the fetchRemoteBranch(remote: string, remoteBranch: string, cwd: string) function, both the remote and remoteBranch parameters are passed to the git fetch…

  • CVE-2022-22281HigMay 13, 2022
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earlier versions, allows an attacker to potentially execute arbitrary code in the host windows operating system.

  • CVE-2022-21190HigMay 13, 2022
    risk 0.42cvss 7.5epss 0.04

    This affects the package convict before 6.2.3. This is a bypass of [CVE-2022-22143](https://security.snyk.io/vuln/SNYK-JS-CONVICT-2340604). The [fix](https://github.com/mozilla/node-convict/commit/3b86be087d8f14681a9c889d45da7fe3ad9cd880) introduced, relies on the startsWith…

  • CVE-2022-1701HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.05

    SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data.

  • CVE-2022-22252HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The DFX module has a UAF vulnerability.Successful exploitation of this vulnerability may affect system stability.

  • CVE-2021-33013HigMay 13, 2022
    risk 0.53cvss 8.2epss 0.01

    mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.

  • CVE-2021-33009HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.01

    mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file system.

  • CVE-2021-33005HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.02

    mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories.

  • CVE-2021-27505HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.01

    mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive directory listing information.

  • CVE-2022-30417HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via ctpms/admin/?page=user/manage_user&id=.

  • CVE-2022-30415HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/applications/update_status.php?id=.

  • CVE-2022-30414HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/?page=applications/view_application&id=.

  • CVE-2022-30412HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/individuals/update_status.php?id=.

  • CVE-2022-30411HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/admin/?page=individuals/view_individual&id=.

  • CVE-2022-30404HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    College Management System v1.0 is vulnerable to SQL Injection via /College_Management_System/admin/display-teacher.php?teacher_id=.

  • CVE-2022-30403HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=products&c=.

  • CVE-2022-30402HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_sub_category&id=.

  • CVE-2022-30401HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/?p=view_product&id=.

  • CVE-2022-30400HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/orders/view_order.php?view=user&id=.

  • CVE-2022-30399HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_category&id=.

  • CVE-2022-30398HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=orders/view_order&id=.

  • CVE-2022-30396HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=inventory/manage_inventory&id=.

  • CVE-2022-30393HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=product/manage_product&id=.

  • CVE-2022-29796HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.

  • CVE-2022-29795HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The frame scheduling module has a null pointer dereference vulnerability. Successful exploitation of this vulnerability will affect the kernel availability.

  • CVE-2022-29793HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a configuration defect in the activation lock of mobile phones.Successful exploitation of this vulnerability may affect application availability.

  • CVE-2022-29792HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The chip component has a vulnerability of disclosing CPU SNs.Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-29791HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.

  • CVE-2022-29790HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The graphics acceleration service has a vulnerability in multi-thread access to the database.Successful exploitation of this vulnerability may cause service exceptions.

  • CVE-2022-29789HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The HiAIserver has a vulnerability in verifying the validity of the properties used in the model.Successful exploitation of this vulnerability will affect AI services.

  • CVE-2022-28829HigMay 13, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-28828HigMay 13, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-28827HigMay 13, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-28826HigMay 13, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-28825HigMay 13, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-28824HigMay 13, 2022
    risk 0.51cvss 7.8epss 0.03

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by a Use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2022-28823HigMay 13, 2022
    risk 0.51cvss 7.8epss 0.03

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by a Use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2022-28822HigMay 13, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…