VYPR

CVEs

102,253 total · page 1156 of 2,046

  • CVE-2022-27799HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.18

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the acroform event that could result in arbitrary code execution in the context of the current…

  • CVE-2022-27798HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.03

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2022-27797HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.04

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context of the current user.…

  • CVE-2022-27796HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.13

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the acroform event that could result in arbitrary code execution in the context of the current…

  • CVE-2022-27795HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.04

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the acroform event that could result in arbitrary code execution in the context of the current…

  • CVE-2022-27794HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.15

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by the use of a variable that has not been initialized when processing of embedded fonts, potentially resulting in arbitrary code execution in the context…

  • CVE-2022-27793HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.10

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2022-27792HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.10

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2022-27791HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.18

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a stack-based buffer overflow vulnerability due to insecure processing of a font, potentially resulting in arbitrary code execution in the context of…

  • CVE-2022-27790HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.12

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of fonts that could result in arbitrary code execution in the context of the current user.…

  • CVE-2022-27789HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.04

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the acroform event that could result in arbitrary code execution in the context of the current…

  • CVE-2022-27788HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.03

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2022-27787HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.11

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2022-27786HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.12

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of fonts that could result in arbitrary code execution in the context of the current user.…

  • CVE-2022-27785HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.13

    Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of fonts that could result in arbitrary code execution in the context of the current user.…

  • CVE-2022-24104HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.11

    Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…

  • CVE-2022-24103HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.03

    Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…

  • CVE-2022-24102HigMay 11, 2022
    risk 0.52cvss 7.8epss 0.13

    Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…

  • CVE-2021-33317HigMay 11, 2022
    risk 0.49cvss 7.5epss 0.01

    The TRENDnet TI-PG1284i switch(hw v2.0R) prior to version 2.0.2.S0 suffers from a null pointer dereference vulnerability. This vulnerability exists in its lldp related component. Due to fail to check if ChassisID TLV is contained in the packet, by sending a crafted lldp packet…

  • CVE-2022-0024HigMay 11, 2022
    risk 0.47cvss 7.2epss 0.02

    A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated network-based PAN-OS administrator to upload a specifically created configuration that disrupts system processes and potentially execute arbitrary code with root privileges when the…

  • CVE-2022-29616HigMay 11, 2022
    risk 0.49cvss 7.5epss 0.01

    SAP Host Agent, SAP NetWeaver and ABAP Platform allow an attacker to leverage logical errors in memory management to cause a memory corruption.

  • CVE-2022-23743HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.00

    Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permissions in the ProgramData\CheckPoint\ZoneAlarm\Data\Updates directory allow a local attacker the ability to execute an arbitrary…

  • CVE-2021-43066HigMay 11, 2022
    risk 0.55cvss 8.4epss 0.00

    A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below, version 6.2.9 and below, version 6.0.10 and below allows attacker to escalate privilege via the MSI installer.

  • CVE-2022-29611HigMay 11, 2022
    risk 0.57cvss 8.8epss 0.01

    SAP NetWeaver Application Server for ABAP and ABAP Platform do not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

  • CVE-2022-28214HigMay 11, 2022
    risk 0.51cvss 7.8epss 0.00

    During an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed in Sysmon event logs. This Information Disclosure could cause a high impact on systems’ Confidentiality, Integrity, and…

  • CVE-2021-42651HigMay 11, 2022
    risk 0.00cvss 8.8epss 0.02

    A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated remote attacker to execute arbitrary code through /project/PROJECTNAME/reports/.

  • CVE-2021-37851HigMay 11, 2022
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the installer to run malicious code with higher privileges. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus 11.2 versions prior to 15.1.12.0.…

  • CVE-2021-34606HigMay 11, 2022
    risk 0.47cvss 7.3epss 0.00

    A vulnerability exists in XINJE XD/E Series PLC Program Tool in versions up to v3.5.1 that can allow an authenticated, local attacker to load a malicious DLL. Local access is required to successfully exploit this vulnerability. This means the potential attacker must have access…

  • CVE-2021-34605HigMay 11, 2022
    risk 0.48cvss 7.3epss 0.02

    A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vulnerability can be triggered by manually opening an infected project file, or by…

  • CVE-2022-29932HigMay 11, 2022
    risk 0.49cvss 7.5epss 0.03

    The HTTP Server in PRIMEUR SPAZIO 2.5.1.954 (File Transfer) allows an unauthenticated attacker to obtain sensitive data (related to the content of transferred files) via a crafted HTTP request.

  • CVE-2022-29655HigMay 11, 2022
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-29318HigMay 11, 2022
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in the New Entry module of Car Rental Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2021-3254HigMay 11, 2022
    risk 0.49cvss 7.5epss 0.02

    Asus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to cause a Denial of Service (DoS) via a TCP SYN scan using nmap.

  • CVE-2020-19228HigMay 11, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was found in bludit v3.13.0, unsafe implementation of the backup plugin allows attackers to upload arbitrary files.

  • CVE-2022-26116HigMay 11, 2022
    risk 0.47cvss 7.2epss 0.01

    Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerability [CWE-89] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.2 and below may allow…

  • CVE-2022-30129HigMay 10, 2022
    risk 0.54cvss 8.8epss 0.41

    Visual Studio Code Remote Code Execution Vulnerability

  • CVE-2022-29151HigMay 10, 2022
    risk 0.46cvss 7.0epss 0.01

    Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability

  • CVE-2022-29150HigMay 10, 2022
    risk 0.46cvss 7.0epss 0.01

    Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability

  • CVE-2022-29148HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.03

    Visual Studio Remote Code Execution Vulnerability

  • CVE-2022-29145HigMay 10, 2022
    risk 0.49cvss 7.5epss 0.05

    .NET and Visual Studio Denial of Service Vulnerability

  • CVE-2022-29142HigMay 10, 2022
    risk 0.46cvss 7.0epss 0.05

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2022-29141HigMay 10, 2022
    risk 0.57cvss 8.8epss 0.03

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

  • CVE-2022-29139HigMay 10, 2022
    risk 0.57cvss 8.8epss 0.02

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

  • CVE-2022-29138HigMay 10, 2022
    risk 0.46cvss 7.0epss 0.01

    Windows Clustered Shared Volume Elevation of Privilege Vulnerability

  • CVE-2022-29137HigMay 10, 2022
    risk 0.57cvss 8.8epss 0.02

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

  • CVE-2022-29135HigMay 10, 2022
    risk 0.46cvss 7.0epss 0.01

    Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability

  • CVE-2022-29133HigMay 10, 2022
    risk 0.57cvss 8.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2022-29132HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows Print Spooler Elevation of Privilege Vulnerability

  • CVE-2022-29131HigMay 10, 2022
    risk 0.57cvss 8.8epss 0.03

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

  • CVE-2022-29129HigMay 10, 2022
    risk 0.57cvss 8.8epss 0.03

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability