VYPR

CVEs

102,253 total · page 1162 of 2,046

  • CVE-2022-0952HigMay 2, 2022
    risk 0.58cvss 8.8epss 0.13

    The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options via a REST endpoint, and does not ensure that the option to be updated belongs to the plugin. As a result, unauthenticated attackers could change arbitrary blog…

  • CVE-2021-25002HigMay 2, 2022
    risk 0.49cvss 7.5epss 0.01

    The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which could allow unauthenticated users to access Orders data which could be used to retrieve the client full address, name and phone via tracking URL

  • CVE-2022-27983HigMay 2, 2022
    risk 0.49cvss 7.5epss 0.01

    RG-NBR-E Enterprise Gateway RG-NBR2100G-E was discovered to contain an arbitrary file read vulnerability via the url parameter in check.php.

  • CVE-2022-28572HigMay 2, 2022
    risk 0.57cvss 8.8epss 0.03

    Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function

  • CVE-2022-23064HigMay 2, 2022
    risk 0.50cvss 8.8epss 0.01

    In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus…

  • CVE-2022-23904HigMay 2, 2022
    risk 0.52cvss 8.0epss 0.00

    Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated user to upgrade his account to admin and gain access to the auctionworx admin control panel. This vulnerability affects AuctionWorx Enterprise and AuctionWorx:…

  • CVE-2021-46790HigMay 2, 2022
    risk 0.51cvss 7.8epss 0.01

    ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream position is that ntfsck is deprecated; however, it is shipped by some Linux distributions.

  • CVE-2021-36784HigMay 2, 2022
    risk 0.47cvss 7.2epss 0.01

    A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to full admin. This issue affects: SUSE Rancher Rancher versions prior to 2.5.13; Rancher versions prior to 2.6.4.

  • CVE-2021-36778HigMay 2, 2022
    risk 0.48cvss 7.3epss 0.01

    A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather credentials that are sent to their servers. This issue affects: SUSE Rancher Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.

  • CVE-2022-29970HigMay 2, 2022
    risk 0.42cvss 7.5epss 0.02

    Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.

  • CVE-2022-29968HigMay 2, 2022
    risk 0.00cvss 7.8epss 0.01

    An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.

  • CVE-2022-29849HigMay 2, 2022
    risk 0.51cvss 7.8epss 0.00

    In Progress OpenEdge before 11.7.14 and 12.x before 12.2.9, certain SUID binaries within the OpenEdge application were susceptible to privilege escalation. If exploited, a local attacker could elevate their privileges and compromise the affected system.

  • CVE-2022-28451HigMay 2, 2022
    risk 0.00cvss 7.5epss 0.02

    nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.

  • CVE-2021-40822HigMay 2, 2022
    risk 0.50cvss 7.5epss 0.20

    GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.

  • CVE-2022-25301HigMay 1, 2022
    risk 0.50cvss 7.7epss 0.01

    All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attributes to be altered, including their magical attributes such as proto, constructor and prototype.

  • CVE-2022-25850HigMay 1, 2022
    risk 0.42cvss 7.5epss 0.01

    The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when interceptor mode is set to proxy. It occurs when an HTTP request is made by a backend server to an untrusted URL submitted by a user. It leads to a leakage of…

  • CVE-2022-25647HigMay 1, 2022
    risk 0.44cvss 7.7epss 0.12

    The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks.

  • CVE-2022-23923HigMay 1, 2022
    risk 0.56cvss 8.6epss 0.01

    All versions of package jailed are vulnerable to Sandbox Bypass via an exported alert() method which can access the main application. Exported methods are stored in the application.remote object.

  • CVE-2022-22143HigMay 1, 2022
    risk 0.42cvss 7.5epss 0.02

    The package convict before 6.2.2 are vulnerable to Prototype Pollution via the convict function due to missing validation of parentKey. **Note:** This vulnerability derives from an incomplete fix of another [vulnerability](https://security.snyk.io/vuln/SNYK-JS-CONVICT-1062508)

  • CVE-2022-21227HigMay 1, 2022
    risk 0.42cvss 7.5epss 0.02

    The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.

  • CVE-2022-21189HigMay 1, 2022
    risk 0.41cvss 7.3epss 0.02

    The package dexie before 3.2.2, from 4.0.0-alpha.1 and before 4.0.0-alpha.3 are vulnerable to Prototype Pollution in the Dexie.setByKeyPath(obj, keyPath, value) function which does not properly check the keys being set (like __proto__ or constructor). This can allow an attacker…

  • CVE-2022-21167HigMay 1, 2022
    risk 0.49cvss 7.5epss 0.01

    All versions of package masuit.tools.core are vulnerable to Arbitrary Code Execution via the ReceiveVarData function in the SocketClient.cs component. The socket client in the package can pass in the payload via the user-controllable input after it has been established,…

  • CVE-2022-21144HigMay 1, 2022
    risk 0.42cvss 7.5epss 0.02

    This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument the V8 code will attempt invoking the .toString method of the argument. If the argument's toString value is not a Function object V8 will crash.

  • CVE-2022-1544HigMay 1, 2022
    risk 0.44cvss 7.8epss 0.02

    Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided command injection, code execution, or remote ex-filtration of…

  • CVE-2021-42001HigApr 30, 2022
    risk 0.52cvss 8.0epss 0.00

    PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may be able to successfully complete an MFA challenge via OTP.

  • CVE-2021-41992HigApr 30, 2022
    risk 0.50cvss 7.7epss 0.00

    A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass.

  • CVE-2022-28323HigApr 30, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in MediaWiki through 1.37.2. The SecurePoll extension allows a leak because sorting by timestamp is supported,

  • CVE-2022-29265HigApr 30, 2022
    risk 0.49cvss 7.5epss 0.03

    Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The following Processors…

  • CVE-2022-29967HigApr 29, 2022
    risk 0.00cvss 7.5epss 0.02

    static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal.

  • CVE-2022-1543HigApr 29, 2022
    risk 0.00cvss 8.8epss 0.01

    Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large enough the service results in a momentary outage in a production environment. That can lead to memory corruption on the server.

  • CVE-2022-29937HigApr 29, 2022
    risk 0.57cvss 8.8epss 0.01

    USU Oracle Optimization before 5.17.5 allows authenticated DataCollection users to achieve agent root access because some common OS commands are blocked but (for example) an OS command for base64 decoding is not blocked. NOTE: this is not an Oracle Corporation product.

  • CVE-2022-29936HigApr 29, 2022
    risk 0.57cvss 8.8epss 0.02

    USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/quantum/save-data-upload-big-file Java deserialization. NOTE: this is not an Oracle Corporation product.

  • CVE-2022-29935HigApr 29, 2022
    risk 0.49cvss 7.5epss 0.01

    USU Oracle Optimization before 5.17.5 allows attackers to discover the quantum credentials via an agent-installer download. NOTE: this is not an Oracle Corporation product.

  • CVE-2022-29934HigApr 29, 2022
    risk 0.51cvss 7.8epss 0.00

    USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec. NOTE: this is not an Oracle Corporation product.

  • CVE-2022-29451HigApr 29, 2022
    risk 0.57cvss 8.8epss 0.01

    Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows attackers to trick logged-in admin users into uploading dangerous files into /wp-content/uploads/ directory.

  • CVE-2022-1403HigApr 29, 2022
    risk 0.51cvss 7.8epss 0.01

    ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds write condition.

  • CVE-2022-1402HigApr 29, 2022
    risk 0.51cvss 7.8epss 0.01

    ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing a possible out-of-bounds read condition.

  • CVE-2021-4207HigApr 29, 2022
    risk 0.53cvss 8.2epss 0.00

    A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header.width` and `cursor->header.height` can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. A malicious…

  • CVE-2021-4206HigApr 29, 2022
    risk 0.53cvss 8.2epss 0.01

    A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lead to the allocation of a small cursor object followed by a subsequent heap-based buffer overflow. This flaw allows a malicious privileged guest user to crash…

  • CVE-2021-36207HigApr 29, 2022
    risk 0.57cvss 8.8epss 0.01

    Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elevate their privileges to administrator.

  • CVE-2022-29856HigApr 29, 2022
    risk 0.49cvss 7.5epss 0.02

    A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages.

  • CVE-2022-1353HigApr 29, 2022
    risk 0.00cvss 7.1epss 0.00

    A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel information.

  • CVE-2022-1227HigApr 29, 2022
    risk 0.00cvss 8.8epss 0.04

    A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the…

  • CVE-2022-1114HigApr 29, 2022
    risk 0.46cvss 7.1epss 0.01

    A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a…

  • CVE-2022-1048HigApr 29, 2022
    risk 0.46cvss 7.0epss 0.00

    A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or potentially…

  • CVE-2021-43938HigApr 29, 2022
    risk 0.53cvss 8.1epss 0.01

    Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server without any authentication or authorization.

  • CVE-2021-43937HigApr 29, 2022
    risk 0.49cvss 7.6epss 0.00

    Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

  • CVE-2021-39082HigApr 29, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM UrbanCode Deploy (UCD) 7.1.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2021-44595HigApr 29, 2022
    risk 0.62cvss 8.8epss 0.21

    Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send manually crafted packets to the ElevationService.exe and execute arbitrary code without any validation with SYSTEM privileges.

  • CVE-2021-41942HigApr 29, 2022
    risk 0.49cvss 7.5epss 0.01

    The Magic CMS MSVOD v10 video system has a SQL injection vulnerability. Attackers can use vulnerabilities to obtain sensitive information in the database.