VYPR

CVEs

102,253 total · page 1158 of 2,046

  • CVE-2021-26353HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.00

    Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state potentially resulting in loss of memory integrity.

  • CVE-2021-26332HigMay 10, 2022
    risk 0.46cvss 7.1epss 0.00

    Failure to verify SEV-ES TMR is not in MMIO space, SEV-ES FW could result in a potential loss of integrity or availability.

  • CVE-2021-26324HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.00

    A bug with the SEV-ES TMR may lead to a potential loss of memory integrity for SNP-active VMs.

  • CVE-2022-22774HigMay 10, 2022
    risk 0.56cvss 8.6epss 0.01

    The DOM XML parser and SAX XML parser components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Internet Server, and TIBCO Managed File Transfer Internet Server contains an easily…

  • CVE-2022-22454HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.00

    IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.

  • CVE-2022-26988HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.01

    TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution.

  • CVE-2022-26987HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.01

    TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.

  • CVE-2022-1629HigMay 10, 2022
    risk 0.00cvss 7.8epss 0.02

    Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution

  • CVE-2022-1621HigMay 10, 2022
    risk 0.00cvss 7.8epss 0.02

    Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

  • CVE-2022-1537HigMay 10, 2022
    risk 0.39cvss 7.0epss 0.00

    file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if…

  • CVE-2022-1397HigMay 10, 2022
    risk 0.50cvss 8.8epss 0.01

    API Privilege Escalation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. Full system takeover.

  • CVE-2021-41545HigMay 10, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). When the controller receives a specific BACnet…

  • CVE-2022-23705HigMay 9, 2022
    risk 0.49cvss 7.5epss 0.01

    A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays, and HPE Nimble Storage Secondary Flash Arrays which could potentially allow the upload, but not execution, of unauthorized update binaries to the array.…

  • CVE-2022-23704HigMay 9, 2022
    risk 0.49cvss 7.5epss 0.02

    A potential security vulnerability has been identified in Integrated Lights-Out 4 (iLO 4). The vulnerability could allow remote Denial of Service. The vulnerability is resolved in Integrated Lights-Out 4 (iLO 4) 2.80 and later.

  • CVE-2022-30524HigMay 9, 2022
    risk 0.51cvss 7.8epss 0.02

    There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mishandles characters at large y coordinates. It can be triggered by (for example) sending a crafted pdf file to the pdftotext binary, which allows a remote…

  • CVE-2022-30240HigMay 9, 2022
    risk 0.51cvss 7.8epss 0.00

    An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift JDBC Driver 1.2.40 through 1.2.55 may allow a local user to execute code. NOTE: this is different from CVE-2022-29972.

  • CVE-2022-30239HigMay 9, 2022
    risk 0.51cvss 7.8epss 0.00

    An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena JDBC Driver 2.0.25 through 2.0.28 may allow a local user to execute code. NOTE: this is different from CVE-2022-29971.

  • CVE-2022-29972HigMay 9, 2022
    risk 0.51cvss 7.8epss 0.04

    An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver (1.4.14 through 1.4.21.1001 and 1.4.22 through 1.4.x before 1.4.52) may allow a local user to execute arbitrary code.

  • CVE-2022-29971HigMay 9, 2022
    risk 0.51cvss 7.8epss 0.00

    An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena ODBC Driver 1.1.1 through 1.1.x before 1.1.17 may allow a local user to execute arbitrary code.

  • CVE-2022-29933HigMay 9, 2022
    risk 0.58cvss 8.8epss 0.05

    Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the password reset functionality. Specifically,…

  • CVE-2022-28739HigMay 9, 2022
    risk 0.49cvss 7.5epss 0.04

    There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occurs in String-to-Float conversion, including Kernel#Float and String#to_f.

  • CVE-2021-20479HigMay 9, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197498.

  • CVE-2022-27224HigMay 9, 2022
    risk 0.47cvss 7.2epss 0.05

    An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated attacker can perform command injection as root via shell metacharacters within the Network Tools section of the web-management interface. All three networking tools are affected…

  • CVE-2022-23332HigMay 9, 2022
    risk 0.58cvss 8.8epss 0.05

    Command injection vulnerability in Manual Ping Form (Web UI) in Shenzhen Ejoin Information Technology Co., Ltd. ACOM508/ACOM516/ACOM532 609-915-041-100-020 allows a remote attacker to inject arbitrary code via the field.

  • CVE-2022-1631HigMay 9, 2022
    risk 0.54cvss 8.8epss 0.09

    Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application using the Victim’s Email. This allows…

  • CVE-2022-30286HigMay 9, 2022
    risk 0.53cvss 7.5epss 0.14

    pyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code.

  • CVE-2022-30333HigKEVMay 9, 2022
    risk 0.78cvss 7.5epss 0.99

    RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

  • CVE-2022-28463HigMay 8, 2022
    risk 0.00cvss 7.8epss 0.02

    ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow.

  • CVE-2022-1620HigMay 8, 2022
    risk 0.00cvss 7.5epss 0.02

    NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 in GitHub repository vim/vim prior to 8.2.4901. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 allows attackers to cause a denial of service (application crash) via a crafted input.

  • CVE-2022-1619HigMay 8, 2022
    risk 0.00cvss 7.8epss 0.03

    Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution

  • CVE-2018-25033HigMay 8, 2022
    risk 0.53cvss 8.1epss 0.01

    ADMesh through 0.98.4 has a heap-based buffer over-read in stl_update_connects_remove_1 (called from stl_remove_degenerate) in connect.c in libadmesh.a.

  • CVE-2022-1616HigMay 7, 2022
    risk 0.00cvss 7.8epss 0.03

    Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

  • CVE-2022-25324HigMay 6, 2022
    risk 0.49cvss 7.5epss 0.01

    All versions of package bignum are vulnerable to Denial of Service (DoS) due to a type-check exception in V8, when verifying the type of the second argument to the .powm function, V8 will crash regardless of Node try/catch blocks.

  • CVE-2021-23792HigMay 6, 2022
    risk 0.41cvss 7.3epss 0.01

    The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initialized XML parser for reading XMP Metadata. An attacker can exploit this vulnerability if they are able to supply a file (e.g. when…

  • CVE-2021-23592HigMay 6, 2022
    risk 0.43cvss 7.7epss 0.02

    The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.

  • CVE-2022-28279HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.03

    Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open…

  • CVE-2022-28278HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-28277HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.03

    Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-28276HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-28275HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-28274HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.03

    Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to…

  • CVE-2022-28273HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-28272HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-28271HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.03

    Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open…

  • CVE-2022-28270HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-27784HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.04

    Adobe After Effects versions 22.2.1 (and earlier) and 18.4.5 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user…

  • CVE-2022-27783HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.04

    Adobe After Effects versions 22.2.1 (and earlier) and 18.4.5 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user…

  • CVE-2022-24105HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must…

  • CVE-2022-24098HigMay 6, 2022
    risk 0.51cvss 7.8epss 0.03

    Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an improper input validation vulnerability when parsing a PCX file that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…

  • CVE-2022-23802HigMay 6, 2022
    risk 0.49cvss 7.5epss 0.01

    Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). The component is: Access to private information and components, possibility to view other users' information. Information disclosure Access to private…