VYPR

CVEs

102,253 total · page 1155 of 2,046

  • CVE-2022-21809HigMay 12, 2022
    risk 0.53cvss 8.1epss 0.02

    A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability.

  • CVE-2022-21182HigMay 12, 2022
    risk 0.57cvss 8.8epss 0.02

    A privilege escalation vulnerability exists in the router configuration import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-21128HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Insufficient control flow management in the Intel(R) Advisor software before version 7.6.0.37 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-40399HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.01

    An exploitable use-after-free vulnerability exists in WPS Spreadsheets ( ET ) as part of WPS Office, version 11.2.0.10351. A specially-crafted XLS file can cause a use-after-free condition, resulting in remote code execution. An attacker needs to provide a malformed file to the…

  • CVE-2021-33123HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper access control in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

  • CVE-2021-33122HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

  • CVE-2021-26258HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.01

    Improper access control for the Intel(R) Killer(TM) Control Center software before version 2.4.3337.0 may allow an authorized user to potentially enable escalation of privilege via local access.

  • CVE-2021-0194HigMay 12, 2022
    risk 0.47cvss 7.2epss 0.01

    Improper access control in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via network access.

  • CVE-2021-0193HigMay 12, 2022
    risk 0.47cvss 7.2epss 0.01

    Improper authentication in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via network access.

  • CVE-2021-0190HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Uncaught exception in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

  • CVE-2021-0189HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Use of out-of-range pointer offset in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

  • CVE-2021-0188HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Return of pointer value outside of expected range in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

  • CVE-2021-0159HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

  • CVE-2021-0154HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

  • CVE-2021-0153HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

  • CVE-2021-0126HigMay 12, 2022
    risk 0.52cvss 8.0epss 0.00

    Improper input validation for the Intel(R) Manageability Commander before version 2.2 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

  • CVE-2022-30002HigMay 12, 2022
    risk 0.47cvss 7.2epss 0.01

    Insurance Management System 1.0 is vulnerable to SQL Injection via /insurance/editNominee.php?nominee_id=.

  • CVE-2022-29298HigMay 12, 2022
    risk 0.55cvss 7.5epss 0.47

    SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.

  • CVE-2022-1699HigMay 12, 2022
    risk 0.00cvss 7.5epss 0.01

    Uncontrolled Resource Consumption in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

  • CVE-2022-1698HigMay 12, 2022
    risk 0.00cvss 7.5epss 0.01

    Allowing long password leads to denial of service in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

  • CVE-2022-30279HigMay 12, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. An attacker could exploit this vulnerability via forged sofbus lacbus…

  • CVE-2022-1650HigMay 12, 2022
    risk 0.46cvss 8.1epss 0.02

    Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.

  • CVE-2022-29930HigMay 12, 2022
    risk 0.00cvss 8.7epss 0.01

    SHA1 implementation in JetBrains Ktor Native 2.0.0 was returning the same value. The issue was fixed in Ktor version 2.0.1.

  • CVE-2022-29885HigMay 12, 2022
    risk 0.02cvss 7.5epss 0.73

    The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor…

  • CVE-2022-1681HigMay 12, 2022
    risk 0.00cvss 7.2epss 0.02

    Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions

  • CVE-2022-30594HigMay 12, 2022
    risk 0.00cvss 7.8epss 0.01

    The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.

  • CVE-2022-30557HigMay 11, 2022
    risk 0.49cvss 7.5epss 0.04

    Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mishandling during JavaScript execution.

  • CVE-2022-30451HigMay 11, 2022
    risk 0.57cvss 8.8epss 0.02

    An authenticated user could execute code via a SQLi vulnerability in waimairenCMS before version 9.1.

  • CVE-2022-30452HigMay 11, 2022
    risk 0.47cvss 7.2epss 0.01

    ShopWind <= v3.4.2 has a Sql injection vulnerability in Database.php

  • CVE-2022-30060HigMay 11, 2022
    risk 0.57cvss 8.8epss 0.01

    ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Write via admin/controllers/tp.php

  • CVE-2022-30040HigMay 11, 2022
    risk 0.49cvss 7.5epss 0.02

    Tenda AX1803 v1.0.0.1_2890 is vulnerable to Buffer Overflow. The vulnerability lies in rootfs_ In / goform / setsystimecfg of / bin / tdhttpd in ubif file system, attackers can access http://ip/goform/SetSysTimeCfg, and by setting the ntpserve parameter, the stack buffer…

  • CVE-2022-29847HigMay 11, 2022
    risk 0.56cvss 7.5epss 0.57

    In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that would allow them to relay encrypted WhatsUp Gold user credentials to an arbitrary host.

  • CVE-2022-28838HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.03

    Acrobat Acrobat Pro DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2022-28243HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.11

    Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An…

  • CVE-2022-28242HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.04

    Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…

  • CVE-2022-28241HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.03

    Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An…

  • CVE-2022-28240HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.13

    Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…

  • CVE-2022-28239HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.03

    Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An…

  • CVE-2022-28238HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.12

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context of the current user.…

  • CVE-2022-28237HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.04

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context of the current user.…

  • CVE-2022-28236HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.12

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2022-28235HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.04

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the acroform event that could result in arbitrary code execution in the context of the current…

  • CVE-2022-28234HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.05

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a heap-based buffer overflow vulnerability due to insecure handling of a crafted .pdf file, potentially resulting in arbitrary code execution in the…

  • CVE-2022-28233HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.13

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context of the current user.…

  • CVE-2022-28232HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.13

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the collab object that could result in arbitrary code execution in the context of the current…

  • CVE-2022-28231HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.03

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by an out-of-bounds read vulnerability when processing a doc object, which could result in a read past the end of an allocated memory structure. An…

  • CVE-2022-28230HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.13

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the acroform event that could result in arbitrary code execution in the context of the current…

  • CVE-2022-27802HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.04

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context of the current user.…

  • CVE-2022-27801HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.04

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context of the current user.…

  • CVE-2022-27800HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.04

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context of the current user.…