VYPR

CVEs

102,253 total · page 1160 of 2,046

  • CVE-2022-25946HigMay 5, 2022
    risk 0.57cvss 8.7epss 0.00

    On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, when running in Appliance mode, an authenticated attacker with Administrator role privilege may be…

  • CVE-2021-44057HigMay 5, 2022
    risk 0.46cvss 7.1epss 0.01

    An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Photo…

  • CVE-2021-44056HigMay 5, 2022
    risk 0.46cvss 7.1epss 0.01

    An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Video…

  • CVE-2021-44051HigMay 5, 2022
    risk 0.57cvss 8.8epss 0.02

    A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploited, this vulnerability allows remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS…

  • CVE-2021-43547HigMay 5, 2022
    risk 0.49cvss 7.5epss 0.02

    TwinOaks Computing CoreDX DDS versions prior to 5.9.1 are susceptible to exploitation when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure.

  • CVE-2021-38487HigMay 5, 2022
    risk 0.54cvss 8.2epss 0.03

    RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic. This may result in a denial-of-service condition and information exposure.

  • CVE-2021-38447HigMay 5, 2022
    risk 0.56cvss 8.6epss 0.02

    OCI OpenDDS versions prior to 3.18.1 are vulnerable when an attacker sends a specially crafted packet to flood target devices with unwanted traffic, which may result in a denial-of-service condition.

  • CVE-2021-38445HigMay 5, 2022
    risk 0.46cvss 7.0epss 0.03

    OCI OpenDDS versions prior to 3.18.1 do not handle a length parameter consistent with the actual length of the associated data, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2021-38439HigMay 5, 2022
    risk 0.56cvss 8.6epss 0.03

    All versions of GurumDDS are vulnerable to heap-based buffer overflow, which may cause a denial-of-service condition or remotely execute arbitrary code.

  • CVE-2021-38425HigMay 5, 2022
    risk 0.49cvss 7.5epss 0.05

    eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitation when an attacker sends a specially crafted packet to flood a target device with unwanted traffic, which may result in a denial-of-service condition and information exposure.

  • CVE-2022-22433HigMay 5, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP…

  • CVE-2021-42183HigMay 5, 2022
    risk 0.49cvss 7.5epss 0.05

    MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/.

  • CVE-2022-29340HigMay 5, 2022
    risk 0.00cvss 7.5epss 0.01

    GPAC 2.1-DEV-rev87-g053aae8-master. has a Null Pointer Dereference vulnerability in gf_isom_parse_movie_boxes_internal due to improper return value handling of GF_SKIP_BOX, which causes a Denial of Service. This vulnerability was fixed in commit 37592ad.

  • CVE-2022-29339HigMay 5, 2022
    risk 0.00cvss 7.5epss 0.01

    In GPAC 2.1-DEV-rev87-g053aae8-master, function BS_ReadByte() in utils/bitstream.c has a failed assertion, which causes a Denial of Service. This vulnerability was fixed in commit 9ea93a2.

  • CVE-2022-28462HigMay 5, 2022
    risk 0.49cvss 7.5epss 0.01

    novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.

  • CVE-2022-29938HigMay 5, 2022
    risk 0.57cvss 8.8epss 0.01

    In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection.

  • CVE-2022-1592HigMay 5, 2022
    risk 0.46cvss 8.2epss 0.01

    Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make the application perform arbitrary requests to fishing steal cookie, request to private area, or lead to xss...

  • CVE-2022-30288HigMay 4, 2022
    risk 0.49cvss 7.5epss 0.02

    Agoo before 2.14.3 does not reject GraphQL fragment spreads that form cycles, leading to an application crash. NOTE: the vendor has disputed this on the grounds that it is not the server's responsibility to "enforce all the various ways a developer could write code with logic…

  • CVE-2022-20785HigMay 4, 2022
    risk 0.49cvss 7.5epss 0.07

    On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in HTML file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior…

  • CVE-2022-20771HigMay 4, 2022
    risk 0.49cvss 7.5epss 0.06

    On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in the TIFF file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior…

  • CVE-2022-20770HigMay 4, 2022
    risk 0.56cvss 8.6epss 0.07

    On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in CHM file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior…

  • CVE-2022-28940HigMay 4, 2022
    risk 0.49cvss 7.5epss 0.01

    In H3C MagicR100 <=V100R005, the / Ajax / ajaxget interface can be accessed without authorization. It sends a large amount of data through ajaxmsg to carry out DOS attack.

  • CVE-2022-28556HigMay 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin is vulnerable to Buffer Overflow. The stack overflow vulnerability lies in the /goform/setpptpservercfg interface of the web. The sent post data startip and endip are copied to the stack using the sanf function, resulting in…

  • CVE-2022-23443HigMay 4, 2022
    risk 0.49cvss 7.5epss 0.01

    An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests.

  • CVE-2021-41020HigMay 4, 2022
    risk 0.57cvss 8.8epss 0.01

    An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated, non privileged attacker to regenerate the CA certificate via the regeneration URL.

  • CVE-2021-20051HigMay 4, 2022
    risk 0.51cvss 7.8epss 0.01

    SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability in one of the installer components. Successful exploitation via a local attacker could result in command execution in the target system.

  • CVE-2022-28806HigMay 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on certain Fujitsu LIEFBOOK devices (A3510, U9310, U7511/U7411/U7311, U9311, E5510/E5410, U7510/U7410/U7310, E459/E449) with BIOS versions before v1.09 (A3510), v2.17 (U9310), v2.30 (U7511/U7411/U7311), v2.33 (U9311), v2.23 (E5510), v2.19 (U7510/U7410),…

  • CVE-2022-28552HigMay 4, 2022
    risk 0.57cvss 8.8epss 0.01

    Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.

  • CVE-2022-28488HigMay 4, 2022
    risk 0.49cvss 7.5epss 0.01

    The function wav_format_write in libwav.c in libwav through 2017-04-20 has an Use of Uninitialized Variable vulnerability.

  • CVE-2022-28487HigMay 4, 2022
    risk 0.00cvss 7.5epss 0.02

    Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality.

  • CVE-2022-28099HigMay 4, 2022
    risk 0.57cvss 8.8epss 0.02

    Poultry Farm Management System v1.0 was discovered to contain a SQL injection vulnerability via the Item parameter at /farm/store.php.

  • CVE-2022-28076HigMay 4, 2022
    risk 0.47cvss 7.2epss 0.02

    Seacms v11.6 was discovered to contain a remote command execution (RCE) vulnerability via the Mail Server Settings.

  • CVE-2022-28067HigMay 4, 2022
    risk 0.56cvss 8.6epss 0.01

    An incorrect access control issue in Sandboxie Classic v5.55.13 allows attackers to cause a Denial of Service (DoS) in the Sandbox via a crafted executable.

  • CVE-2022-27903HigMay 4, 2022
    risk 0.57cvss 8.8epss 0.03

    An OS Command Injection vulnerability in the configuration parser of Eve-NG Professional through 4.0.1-65 and Eve-NG Community through 2.0.3-112 allows a remote authenticated attacker to execute commands as root by editing virtualization command parameters of imported UNL files.

  • CVE-2022-25787HigMay 4, 2022
    risk 0.49cvss 7.5epss 0.00

    Information Exposure Through Query Strings in GET Request vulnerability in LMM API of Secomea GateManager allows system administrator to hijack connection. This issue affects: Secomea GateManager all versions prior to 9.7.

  • CVE-2022-28096HigMay 4, 2022
    risk 0.48cvss 7.2epss 0.21

    Skycaiji v2.4 was discovered to contain a remote code execution (RCE) vulnerability via /SkycaijiApp/admin/controller/Develop.php.

  • CVE-2021-42192HigMay 4, 2022
    risk 0.01cvss 8.8epss 0.10

    Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted request can lead to privilege escalation.

  • CVE-2022-27470HigMay 4, 2022
    risk 0.00cvss 7.8epss 0.01

    SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). This vulnerability is triggered via a crafted TTF file.

  • CVE-2022-24901HigMay 4, 2022
    risk 0.42cvss 7.5epss 0.01

    Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to bypass authentication, making the server vulnerable to DoS attacks. The vulnerability has been fixed by improving the URL validation and adding additional checks…

  • CVE-2021-43164HigMay 4, 2022
    risk 0.63cvss 8.8epss 0.35

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the updateVersion function in /cgi-bin/luci/api/wireless.

  • CVE-2021-43162HigMay 4, 2022
    risk 0.57cvss 8.8epss 0.02

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the runPackDiagnose function in /cgi-bin/luci/api/diagnose.

  • CVE-2021-43161HigMay 4, 2022
    risk 0.57cvss 8.8epss 0.02

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the doSwitchApi function in /cgi-bin/luci/api/switch.

  • CVE-2021-43160HigMay 4, 2022
    risk 0.57cvss 8.8epss 0.02

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the switchFastDhcp function in /cgi-bin/luci/api/diagnose.

  • CVE-2021-43159HigMay 4, 2022
    risk 0.57cvss 8.8epss 0.02

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the setSessionTime function in /cgi-bin/luci/api/common..

  • CVE-2022-21743HigMay 3, 2022
    risk 0.51cvss 7.8epss 0.00

    In ion, there is a possible use after free due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06371108; Issue ID: ALPS06371108.

  • CVE-2022-20111HigMay 3, 2022
    risk 0.55cvss 8.4epss 0.00

    In ion, there is a possible use after free due to incorrect error handling. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06366069; Issue ID: ALPS06366069.

  • CVE-2021-27439HigMay 3, 2022
    risk 0.48cvss 7.3epss 0.01

    TencentOS-tiny version 3.1.0 is vulnerable to integer wrap-around in function 'tos_mmheap_alloc incorrect calculation of effective memory allocation size. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or…

  • CVE-2021-27435HigMay 3, 2022
    risk 0.00cvss 7.3epss 0.02

    ARM mbed product Version 6.3.0 is vulnerable to integer wrap-around in malloc_wrapper function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.

  • CVE-2021-27433HigMay 3, 2022
    risk 0.00cvss 7.3epss 0.02

    ARM mbed-ualloc memory library version 1.3.0 is vulnerable to integer wrap-around in function mbed_krbs, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.

  • CVE-2021-27431HigMay 3, 2022
    risk 0.48cvss 7.3epss 0.01

    ARM CMSIS RTOS2 versions prior to 2.1.3 are vulnerable to integer wrap-around inosRtxMemoryAlloc (local malloc equivalent) function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or injected code execution.