VYPR

CVEs

102,253 total · page 1163 of 2,046

  • CVE-2022-1534HigApr 29, 2022
    risk 0.00cvss 7.1epss 0.00

    Buffer Over-read at parse_rawml.c:1416 in GitHub repository bfabiszewski/libmobi prior to 0.11. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a…

  • CVE-2022-1533HigApr 29, 2022
    risk 0.00cvss 7.8epss 0.00

    Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11. This vulnerability is capable of arbitrary code execution.

  • CVE-2022-29555HigApr 28, 2022
    risk 0.57cvss 8.8epss 0.00

    The Deviceconnect microservice through 1.3.0 in Northern.tech Mender Enterprise before 3.2.2. allows Cross-Origin Websocket Hijacking.

  • CVE-2022-28060HigApr 28, 2022
    risk 0.49cvss 7.5epss 0.02

    SQL Injection vulnerability in Victor CMS v1.0, via the user_name parameter to /includes/login.php.

  • CVE-2022-29411HigApr 28, 2022
    risk 0.54cvss 8.3epss 0.01

    SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers to execute SQLi attack via (&id).

  • CVE-2022-29410HigApr 28, 2022
    risk 0.48cvss 7.4epss 0.01

    Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit 音乐播放器 plugin <= 3.1.6 on WordPress allows attackers with Subscriber or higher user roles to execute SQLi attack via (&ids).

  • CVE-2022-29585HigApr 28, 2022
    risk 0.49cvss 7.5epss 0.01

    In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of).

  • CVE-2022-28892HigApr 28, 2022
    risk 0.57cvss 8.8epss 0.00

    Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.

  • CVE-2022-24879HigApr 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Shopware is an open source e-commerce software platform. Versions prior to 5.7.9 are vulnerable to malfunction of cross-site request forgery (CSRF) token validation. Under certain circumstances, the CSRF tokens were not generated anew and not validated correctly. This issue is…

  • CVE-2022-22782HigApr 28, 2022
    risk 0.51cvss 7.9epss 0.00

    The Zoom Client for Meetings for Windows prior to version 5.9.7, Zoom Rooms for Conference Room for Windows prior to version 5.10.0, Zoom Plugins for Microsoft Outlook for Windows prior to version 5.10.3, and Zoom VDI Windows Meeting Clients prior to version 5.9.6; was…

  • CVE-2022-22781HigApr 28, 2022
    risk 0.49cvss 7.5epss 0.00

    The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting user’s currently installed version to a less secure…

  • CVE-2021-43939HigApr 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Elcomplus SmartPTT is vulnerable when a low-authenticated user can access higher level administration authorization by issuing requests directly to the desired endpoints.

  • CVE-2022-24935HigApr 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Lexmark products through 2022-02-10 have Incorrect Access Control.

  • CVE-2021-33436HigApr 28, 2022
    risk 0.47cvss 7.3epss 0.00

    NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe DLL loading. This vulnerability allows local non-privileged users to perform DLL Hijacking via any writable directory listed under the system path and…

  • CVE-2021-3523HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. This flaw allows an attacker to bypass security restrictions for an API request when hosting multiple APIs on the same IP address.

  • CVE-2022-28194HigApr 27, 2022
    risk 0.47cvss 7.3epss 0.00

    NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled, a local attacker with elevated privileges can cause a memory buffer overflow, which may lead to code execution, loss of Integrity, limited denial of service,…

  • CVE-2022-22315HigApr 27, 2022
    risk 0.57cvss 8.8epss 0.01

    IBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated privileges due to improper handling of permissions. IBM X-Force ID: 217955.

  • CVE-2022-22278HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try to access prohibited resource this allows an attacker to cause HTTP Denial of Service (DoS) attack

  • CVE-2022-22275HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially resulting in Denial of Service (DoS) attack if a target host is vulnerable.

  • CVE-2022-22521HigApr 27, 2022
    risk 0.47cvss 7.3epss 0.01

    In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin.

  • CVE-2021-38919HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-Force ID: 210021

  • CVE-2021-38878HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID: 208756.

  • CVE-2021-34602HigApr 27, 2022
    risk 0.57cvss 8.8epss 0.01

    In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields that are executed with root privileges.

  • CVE-2021-34592HigApr 27, 2022
    risk 0.57cvss 8.8epss 0.01

    In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields.

  • CVE-2021-34591HigApr 27, 2022
    risk 0.51cvss 7.8epss 0.00

    In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacker could get root access via the suid applications socat, ip udhcpc and ifplugd.

  • CVE-2021-34589HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.01

    In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can be read without authentication via the web interface.

  • CVE-2021-34588HigApr 27, 2022
    risk 0.56cvss 8.6epss 0.01

    In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected via a random key. The key is set at user login. It is empty after reboot .

  • CVE-2022-29505HigApr 27, 2022
    risk 0.51cvss 7.8epss 0.00

    Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilege escalation.

  • CVE-2022-27905HigApr 27, 2022
    risk 0.47cvss 7.2epss 0.01

    In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require write permissions to the root level of the OS drive (C:\) to exploit this.

  • CVE-2022-27239HigApr 27, 2022
    risk 0.00cvss 7.8epss 0.01

    In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.

  • CVE-2021-46441HigApr 27, 2022
    risk 0.60cvss 8.8epss 0.33

    In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization.

  • CVE-2021-46421HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.06

    Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.

  • CVE-2021-46420HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.06

    Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.

  • CVE-2022-29701HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount of reset requests for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.

  • CVE-2022-29700HigApr 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cause a Denial of Service (DoS) during password verification.

  • CVE-2022-28085HigApr 27, 2022
    risk 0.00cvss 7.8epss 0.01

    A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lead to arbitrary code execution and Denial of Service (DoS).

  • CVE-2022-28918HigApr 26, 2022
    risk 0.53cvss 8.1epss 0.01

    GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=plugindelhandle&plugin_name=.

  • CVE-2022-28528HigApr 26, 2022
    risk 0.57cvss 8.8epss 0.01

    bloofoxCMS v0.5.2.1 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?mode=content&page=media&action=edit.

  • CVE-2022-28527HigApr 26, 2022
    risk 0.53cvss 8.1epss 0.01

    dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/del.

  • CVE-2022-28525HigApr 26, 2022
    risk 0.57cvss 8.8epss 0.01

    ED01-CMS v20180505 was discovered to contain an arbitrary file upload vulnerability via /admin/users.php?source=edit_user&id=1.

  • CVE-2022-28523HigApr 26, 2022
    risk 0.53cvss 8.1epss 0.01

    HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete.

  • CVE-2022-28059HigApr 26, 2022
    risk 0.53cvss 8.1epss 0.01

    Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php.

  • CVE-2022-28058HigApr 26, 2022
    risk 0.53cvss 8.1epss 0.01

    Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\file_controller.php.

  • CVE-2021-26629HigApr 26, 2022
    risk 0.57cvss 8.8epss 0.01

    A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern ‘..\’.

  • CVE-2021-26628HigApr 26, 2022
    risk 0.53cvss 8.1epss 0.01

    Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges. When uploading file in a specific menu, the verification of the files is insufficient. It allows remote attackers to upload arbitrary files disguising them as…

  • CVE-2022-24883HigApr 26, 2022
    risk 0.00cvss 7.4epss 0.02

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not…

  • CVE-2022-24881HigApr 26, 2022
    risk 0.50cvss 8.8epss 0.03

    Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine. This happens because Velocity and freemarker templates…

  • CVE-2022-23942HigApr 26, 2022
    risk 0.49cvss 7.5epss 0.03

    Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure.

  • CVE-2022-23457HigApr 25, 2022
    risk 0.42cvss 7.5epss 0.03

    ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to version 2.3.0.0, the default implementation of `Validator.getValidDirectoryPath(String, String, File, boolean)` may incorrectly treat the tested input string as a…

  • CVE-2021-35250HigApr 25, 2022
    risk 0.50cvss 7.5epss 0.13

    A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1.