VYPR

CVEs

102,253 total · page 1154 of 2,046

  • CVE-2022-28821HigMay 13, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Framemaker versions 2029u8 (and earlier) and 2020u4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-22261HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The HiAIserver has a vulnerability in verifying the validity of the weight used in the model.Successful exploitation of this vulnerability will affect AI services.

  • CVE-2022-1714HigMay 13, 2022
    risk 0.00cvss 7.1epss 0.00

    Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

  • CVE-2021-46789HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Configuration defects in the secure OS module. Successful exploitation of this vulnerability can affect availability.

  • CVE-2021-46788HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of this vulnerability may cause system pop-up window may be covered to mislead users to perform incorrect operations.

  • CVE-2021-46787HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may cause non-system application processes to crash.

  • CVE-2021-22275HigMay 13, 2022
    risk 0.56cvss 8.6epss 0.01

    Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based attacker to stop the cyclic program on the device and cause a denial of service.

  • CVE-2022-30379HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=user/manage_user&id=.

  • CVE-2022-30378HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=posts/view_post&id=.

  • CVE-2022-30376HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/members/view_member.php?id=.

  • CVE-2022-30374HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/?page=transactions/manage_transaction&id=.

  • CVE-2022-30373HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/manage_cargo_type.php?id=.

  • CVE-2022-30372HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo.

  • CVE-2022-30371HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/view_cargo_type.php?id=.

  • CVE-2020-22983HigMay 13, 2022
    risk 0.53cvss 8.1epss 0.02

    A Server-Side Request Forgery (SSRF) vulnerability exists in MicroStrategy Web SDK 11.1 and earlier, allows remote unauthenticated attackers to conduct a server-side request forgery (SSRF) attack via the srcURL parameter to the shortURL task.

  • CVE-2021-42969HigMay 13, 2022
    risk 0.57cvss 8.8epss 0.02

    Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the user opens the terminal or activates Anaconda, the command will be executed.

  • CVE-2022-25762HigMay 13, 2022
    risk 0.57cvss 8.6epss 0.08

    If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The…

  • CVE-2022-29218HigMay 13, 2022
    risk 0.50cvss 7.7epss 0.01

    RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allowed some gems (with platforms ending in numbers, like `arm64-darwin-21`) to be temporarily replaced in the CDN cache by a…

  • CVE-2022-27134HigMay 13, 2022
    risk 0.49cvss 7.5epss 0.02

    EOSIO batdappboomx v327c04cf has an Access-control vulnerability in the `transfer` function of the smart contract which allows remote attackers to win the cryptocurrency without paying ticket fee via the `std::string memo` parameter.

  • CVE-2021-27777HigMay 12, 2022
    risk 0.49cvss 7.5epss 0.01

    XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validation. Attackers can exploit this vulnerability to manipulate XML content and inject malicious external entity references.

  • CVE-2021-27772HigMay 12, 2022
    risk 0.46cvss 7.1epss 0.01

    Users are able to read group conversations without actively taking part in them. Next to one to one conversations, users are able to start group conversations with multiple users. It was found possible to obtain the contents of these group conversations without being part of it.…

  • CVE-2021-27771HigMay 12, 2022
    risk 0.53cvss 8.2epss 0.01

    User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containing their session ID (SID). This value is also used when…

  • CVE-2022-23742HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.04

    Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or…

  • CVE-2022-23139HigMay 12, 2022
    risk 0.57cvss 8.8epss 0.01

    ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder permission viewed by sftp is 666, which is inconsistent with the actual permission. It’s easy for?users to?ignore the modification?of?the file permission configuration, so that…

  • CVE-2022-22796HigMay 12, 2022
    risk 0.46cvss 7.0epss 0.01

    Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, then click on the login button, and it will redirect you to /home.jsp without any authentication.

  • CVE-2021-27500HigMay 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition.

  • CVE-2021-27498HigMay 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition.

  • CVE-2021-27482HigMay 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may allow the attacker to read arbitrary data.

  • CVE-2021-27478HigMay 12, 2022
    risk 0.53cvss 8.2epss 0.01

    A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may cause a denial-of-service condition.

  • CVE-2022-29369HigMay 12, 2022
    risk 0.00cvss 7.5epss 0.01

    Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njs_lvlhsh_bucket_find at njs_lvlhsh.c.

  • CVE-2022-29368HigMay 12, 2022
    risk 0.00cvss 7.1epss 0.01

    Moddable commit before 135aa9a4a6a9b49b60aa730ebc3bcc6247d75c45 was discovered to contain an out-of-bounds read via the function fxUint8Getter at /moddable/xs/sources/xsDataView.c.

  • CVE-2022-28819HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.03

    Adobe Character Animator versions 4.4.2 (and earlier) and 22.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2021-26386HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.00

    A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call to the Stage 2 Bootloader potentially leading to corrupt memory and code execution.

  • CVE-2021-26317HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution.

  • CVE-2021-26369HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.00

    A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.

  • CVE-2021-26366HigMay 12, 2022
    risk 0.46cvss 7.1epss 0.00

    An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of system integrity.

  • CVE-2021-26362HigMay 12, 2022
    risk 0.46cvss 7.1epss 0.00

    A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call which results in mapping sensitive System Management Network (SMN) registers leading to a loss of integrity and availability.

  • CVE-2022-27172HigMay 12, 2022
    risk 0.57cvss 8.8epss 0.01

    A hard-coded password vulnerability exists in the console infactory functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted network request can lead to privileged operation execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2022-26782HigMay 12, 2022
    risk 0.57cvss 8.8epss 0.03

    Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An…

  • CVE-2022-26781HigMay 12, 2022
    risk 0.57cvss 8.8epss 0.03

    Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An…

  • CVE-2022-26780HigMay 12, 2022
    risk 0.57cvss 8.8epss 0.03

    Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An…

  • CVE-2022-26518HigMay 12, 2022
    risk 0.58cvss 8.8epss 0.05

    An OS command injection vulnerability exists in the console infactory_net functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this…

  • CVE-2022-26420HigMay 12, 2022
    risk 0.58cvss 8.8epss 0.06

    An OS command injection vulnerability exists in the console infactory_port functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this…

  • CVE-2022-26085HigMay 12, 2022
    risk 0.58cvss 8.8epss 0.13

    An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2022-26075HigMay 12, 2022
    risk 0.58cvss 8.8epss 0.06

    An OS command injection vulnerability exists in the console infactory_wlan functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this…

  • CVE-2022-26042HigMay 12, 2022
    risk 0.58cvss 8.8epss 0.09

    An OS command injection vulnerability exists in the daretools binary functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2022-26007HigMay 12, 2022
    risk 0.47cvss 7.2epss 0.06

    An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2022-26002HigMay 12, 2022
    risk 0.47cvss 7.2epss 0.03

    A stack-based buffer overflow vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of malicious packets to trigger this…

  • CVE-2022-25995HigMay 12, 2022
    risk 0.57cvss 8.8epss 0.03

    A command execution vulnerability exists in the console inhand functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2022-22139HigMay 12, 2022
    risk 0.47cvss 7.3epss 0.00

    Uncontrolled search path in the Intel(R) XTU software before version 7.3.0.33 may allow an authenticated user to potentially enable escalation of privilege via local access.