VYPR

CVEs

102,253 total · page 1164 of 2,046

  • CVE-2022-25866HigApr 25, 2022
    risk 0.46cvss 8.1epss 0.04

    The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling the isRemoteUrlReadable($url, array $refs = NULL) function, both the url and refs parameters are passed to the git ls-remote subcommand in a way that…

  • CVE-2022-1441HigApr 25, 2022
    risk 0.00cvss 7.8epss 0.01

    MP4Box is a component of GPAC-2.0.0, which is a widely-used third-party package on RPM Fusion. When MP4Box tries to parse a MP4 file, it calls the function `diST_box_read()` to read from video. In this function, it allocates a buffer `str` with fixed length. However, content…

  • CVE-2022-24792HigApr 25, 2022
    risk 0.00cvss 7.5epss 0.02

    PJSIP is a free and open source multimedia communication library written in C. A denial-of-service vulnerability affects applications on a 32-bit systems that use PJSIP versions 2.12 and prior to play/read invalid WAV files. The vulnerability occurs when reading WAV file data…

  • CVE-2022-22392HigApr 25, 2022
    risk 0.51cvss 7.8epss 0.02

    IBM Planning Analytics Local 2.0 could allow an attacker to upload arbitrary executable files which, when executed by an unsuspecting victim could result in code execution. IBM X-Force ID: 222066.

  • CVE-2022-1392HigApr 25, 2022
    risk 0.50cvss 7.5epss 0.11

    The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues

  • CVE-2022-0656HigApr 25, 2022
    risk 0.49cvss 7.5epss 0.08

    The Web To Print Shop : uDraw WordPress plugin before 3.3.3 does not validate the url parameter in its udraw_convert_url_to_base64 AJAX action (available to both unauthenticated and authenticated users) before using it in the file_get_contents function and returning its content…

  • CVE-2021-4225HigApr 25, 2022
    risk 0.57cvss 8.8epss 0.02

    The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file…

  • CVE-2021-39040HigApr 25, 2022
    risk 0.52cvss 8.0epss 0.01

    IBM Planning Analytics Workspace 2.0 could be vulnerable to malicious file upload by not validating the file types or sizes. Attackers can make use of this weakness and upload malicious executable files into the system and it can be sent to victim for performing further attacks.…

  • CVE-2021-25094HigApr 25, 2022
    risk 0.62cvss 8.1epss 0.83

    The Tatsu WordPress plugin before 3.3.12 add_custom_font action can be used without prior authentication to upload a rogue zip file which is uncompressed under the WordPress's upload directory. By adding a PHP shell with a filename starting with a dot ".", this can bypass…

  • CVE-2021-24957HigApr 25, 2022
    risk 0.57cvss 8.8epss 0.01

    The Advanced Page Visit Counter WordPress plugin before 6.1.6 does not escape the artID parameter before using it in a SQL statement in the apvc_reset_count_art AJAX action, available to any authenticated user, leading to a SQL injection

  • CVE-2022-26111HigApr 25, 2022
    risk 0.58cvss 8.8epss 0.04

    The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote…

  • CVE-2022-28053HigApr 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Typemill v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2021-36460HigApr 25, 2022
    risk 0.51cvss 7.8epss 0.00

    VeryFitPro (com.veryfit2hr.second) 3.2.8 hashes the account's password locally on the device and uses the hash to authenticate in all communication with the backend API, including login, registration and changing of passwords. This allows an attacker in possession of a hash to…

  • CVE-2021-45842HigApr 25, 2022
    risk 0.49cvss 7.5epss 0.02

    It is possible to obtain the first administrator's hash set up in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) on the system as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/wapNasIPS…

  • CVE-2021-45841HigApr 25, 2022
    risk 0.56cvss 8.1epss 0.08

    In Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517), an attacker can self-sign session cookies by knowing the target's MAC address and the user's password hash. Guest users (disabled by default) can be abused using a null/empty hash and allow an unauthenticated attacker…

  • CVE-2021-45836HigApr 25, 2022
    risk 0.57cvss 8.8epss 0.02

    An authenticated attacker can execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by injecting a maliciously crafted input in the request through /tos/index.php?app/hand_app.

  • CVE-2022-1459HigApr 25, 2022
    risk 0.00cvss 8.3epss 0.01

    Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.

  • CVE-2021-40680HigApr 25, 2022
    risk 0.53cvss 8.1epss 0.01

    There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30.000000 through SP273) via the filename parameter to /cgi-bin/main.cgi.

  • CVE-2022-29603HigApr 25, 2022
    risk 0.00cvss 8.1epss 0.01

    A SQL Injection vulnerability exists in UniverSIS UniverSIS-API through 1.2.1 via the $select parameter to multiple API endpoints. A remote authenticated attacker could send crafted SQL statements to a vulnerable endpoint (such as /api/students/me/messages/) to, for example,…

  • CVE-2019-25059HigApr 25, 2022
    risk 0.51cvss 7.8epss 0.01

    Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.

  • CVE-2022-29546HigApr 25, 2022
    risk 0.42cvss 7.5epss 0.01

    HtmlUnit NekoHtml Parser before 2.61.0 suffers from a denial of service vulnerability. Crafted input associated with the parsing of Processing Instruction (PI) data leads to heap memory consumption. This is similar to CVE-2022-28366 but affects a much later version of the…

  • CVE-2022-1452HigApr 24, 2022
    risk 0.00cvss 7.1epss 0.01

    Out-of-bounds Read in r_bin_java_bootstrap_methods_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other…

  • CVE-2022-1451HigApr 24, 2022
    risk 0.00cvss 7.1epss 0.01

    Out-of-bounds Read in r_bin_java_constant_value_attr_new function in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end 2f the intented buffer. Typically, this can allow attackers to read sensitive information from other memory…

  • CVE-2022-1427HigApr 23, 2022
    risk 0.00cvss 7.8epss 0.00

    Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited.

  • CVE-2022-0354HigApr 22, 2022
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during the installation of a System Update package released before 2022-02-25 that displays a command…

  • CVE-2022-0192HigApr 22, 2022
    risk 0.47cvss 7.3epss 0.00

    A DLL search path vulnerability was reported in Lenovo PCManager prior to version 4.0.40.2175 that could allow privilege escalation.

  • CVE-2022-27340HigApr 22, 2022
    risk 0.57cvss 8.8epss 0.01

    MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data.

  • CVE-2021-38886HigApr 22, 2022
    risk 0.57cvss 8.8epss 0.01

    IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 209399.

  • CVE-2022-29583HigApr 22, 2022
    risk 0.44cvss 7.8epss 0.00

    service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory. NOTE: this finding could not be reproduced by its original reporter or by others.

  • CVE-2022-29582HigApr 22, 2022
    risk 0.00cvss 7.0epss 0.01

    In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequently.

  • CVE-2020-14123HigApr 22, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a pointer double free vulnerability in Some MIUI Services. When a function is called, the memory pointer is copied to two function modules, and an attacker can cause the pointer to be repeatedly released through malicious operations, resulting in the affected module…

  • CVE-2022-1437HigApr 22, 2022
    risk 0.00cvss 7.1epss 0.01

    Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

  • CVE-2021-32927HigApr 22, 2022
    risk 0.46cvss 7.1epss 0.01

    An attacker may be able to inject client-side JavaScript code on multiple instances within all versions of Uffizio GPS Tracker.

  • CVE-2022-27406HigApr 22, 2022
    risk 0.42cvss 7.5epss 0.03

    FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FT_Request_Size.

  • CVE-2022-27405HigApr 22, 2022
    risk 0.42cvss 7.5epss 0.03

    FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.

  • CVE-2022-1429HigApr 22, 2022
    risk 0.47cvss 7.5epss 0.64

    SQL injection in GridHelperService.php in GitHub repository pimcore/pimcore prior to 10.3.6. This vulnerability is capable of steal the data

  • CVE-2022-26672HigApr 22, 2022
    risk 0.48cvss 7.3epss 0.01

    ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote attacker can use this token to establish connections with the server and carry out login attempts to general user accounts. A successful login to a general user account allows the…

  • CVE-2022-28366HigApr 21, 2022
    risk 0.42cvss 7.5epss 0.02

    Certain Neko-related HTML parsers allow a denial of service via crafted Processing Instruction (PI) input that causes excessive heap memory consumption. In particular, this issue exists in HtmlUnit-Neko through 2.26, and is fixed in 2.27. This issue also exists in CyberNeko HTML…

  • CVE-2022-26856HigApr 21, 2022
    risk 0.53cvss 8.2epss 0.00

    Dell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access…

  • CVE-2022-24424HigApr 21, 2022
    risk 0.49cvss 7.5epss 0.02

    Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote unauthenticated attacker may potentially exploit this vulnerability to gain unauthorized read access to the files stored on the server filesystem, with the privileges of…

  • CVE-2022-28444HigApr 21, 2022
    risk 0.49cvss 7.5epss 0.02

    UCMS v1.6 was discovered to contain an arbitrary file read vulnerability.

  • CVE-2022-28440HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.02

    An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-28020HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\position_edit.php.

  • CVE-2022-28019HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_edit.php.

  • CVE-2022-28018HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_edit.php.

  • CVE-2022-28017HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_edit.php.

  • CVE-2022-28016HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\deduction_edit.php.

  • CVE-2022-28015HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_edit.php.

  • CVE-2022-28014HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_edit.php.

  • CVE-2022-28013HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_employee_edit.php.