VYPR

CVEs

102,253 total · page 1165 of 2,046

  • CVE-2022-28012HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\position_delete.php.

  • CVE-2022-28011HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\schedule_delete.php.

  • CVE-2022-28010HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\overtime_delete.php.

  • CVE-2022-28009HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_delete.php.

  • CVE-2022-28008HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\attendance_delete.php.

  • CVE-2022-28007HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\cashadvance_delete.php.

  • CVE-2022-28006HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.01

    Attendance and Payroll System v1.0 was discovered to contain a SQL injection vulnerability via the component \admin\employee_delete.php.

  • CVE-2022-27478HigApr 21, 2022
    risk 0.59cvss 8.8epss 0.20

    Victor v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component admin/profile.php?section=admin.

  • CVE-2022-29566HigApr 21, 2022
    risk 0.53cvss 8.1epss 0.01

    The Bulletproofs 2017/1066 paper mishandles Fiat-Shamir generation because the hash computation fails to include all of the public values from the Zero Knowledge proof statement as well as all of the public values computed in the proof, aka the Frozen Heart issue.

  • CVE-2022-20783HigApr 21, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is…

  • CVE-2022-20773HigApr 21, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacker to impersonate a VA. This vulnerability is due to the presence of a static SSH host key. An attacker could exploit this…

  • CVE-2022-20732HigApr 21, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the configuration file protections of Cisco Virtualized Infrastructure Manager (VIM) could allow an authenticated, local attacker to access confidential information and elevate privileges on an affected device. This vulnerability is due to improper access…

  • CVE-2020-14120HigApr 21, 2022
    risk 0.57cvss 8.8epss 0.00

    Some Xiaomi models have a vulnerability in a certain application. The vulnerability is caused by the lack of checksum when using a three-party application to pass in parameters, and attackers can induce users to install a malicious app and use the vulnerability to achieve…

  • CVE-2020-14116HigApr 21, 2022
    risk 0.49cvss 7.5epss 0.00

    An intent redirection vulnerability in the Mi Browser product. This vulnerability is caused by the Mi Browser does not verify the validity of the incoming data. Attackers can perform sensitive operations by exploiting this.

  • CVE-2022-24870HigApr 21, 2022
    risk 0.00cvss 8.7epss 0.01

    Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to 3.0.0 beta3 a malicious script can be injected in tooltips using iTop customization mechanism. This provides a stored cross site scripting attack vector to authorized users of the system.…

  • CVE-2022-24868HigApr 21, 2022
    risk 0.00cvss 7.3epss 0.01

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versions prior to 10.0.0 one can exploit a lack of sanitization on SVG file uploads and inject javascript into their user avatar. As a…

  • CVE-2022-24867HigApr 21, 2022
    risk 0.00cvss 7.5epss 0.01

    GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you pass the config to the javascript, some entries are filtered out. The variable ldap_pass is not filtered and when you look at the…

  • CVE-2022-29498HigApr 21, 2022
    risk 0.42cvss 7.5epss 0.01

    Blazer before 2.6.0 allows SQL Injection. In certain circumstances, an attacker could get a user to run a query they would not have normally run.

  • CVE-2022-29547HigApr 21, 2022
    risk 0.49cvss 7.5epss 0.01

    The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to edit the target page. This could lead to an unauthorised (or blocked) user being able to edit a page.

  • CVE-2022-27925HigKEVApr 21, 2022
    risk 0.76cvss 7.2epss 0.99

    Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

  • CVE-2022-27924HigKEVApr 21, 2022
    risk 0.74cvss 7.5epss 0.85

    Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.

  • CVE-2022-29536HigApr 20, 2022
    risk 0.42cvss 7.5epss 0.02

    In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.

  • CVE-2022-29534HigApr 20, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in MISP before 2.4.158. In UsersController.php, password confirmation can be bypassed via vectors involving an "Accept: application/json" header.

  • CVE-2022-24872HigApr 20, 2022
    risk 0.46cvss 8.1epss 0.01

    Shopware is an open commerce platform based on Symfony Framework and Vue. Permissions set to sales channel context by admin-api are still usable within normal user session. Users are advised to update to the current version 6.4.10.1. For older versions of 6.1, 6.2, and 6.3,…

  • CVE-2021-37740HigApr 20, 2022
    risk 0.49cvss 7.5epss 0.05

    A denial of service vulnerability exists in MDT's firmware for the KNXnet/IP Secure router SCN-IP100.03 and KNX IP interface SCN-IP000.03 before v3.0.4, that allows a remote attacker to turn the device unresponsive to all requests on the KNXnet/IP Secure layer, until the device…

  • CVE-2022-24871HigApr 20, 2022
    risk 0.40cvss 7.2epss 0.01

    Shopware is an open commerce platform based on Symfony Framework and Vue. In affected versions an attacker can abuse the Admin SDK functionality on the server to read or update internal resources. Users are advised to update to the current version 6.4.10.1. For older versions of…

  • CVE-2022-24862HigApr 20, 2022
    risk 0.50cvss 7.7epss 0.01

    Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Server-Side Request Forgery vulnerability. During the download verification process of a JDBC driver the corresponding JDBC driver download address will be downloaded first,…

  • CVE-2022-26516HigApr 20, 2022
    risk 0.55cvss 8.4epss 0.00

    Authorized users may install a maliciously modified package file when updating the device via the web user interface. The user may inadvertently use a package file obtained from an unauthorized source or a file that was compromised between download and deployment.

  • CVE-2022-25343HigApr 20, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Denial of Service. An unauthenticated attacker, who can send POST requests to the /download/set.cgi page by manipulating the failhtmfile variable, is able to cause…

  • CVE-2022-25342HigApr 20, 2022
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered on Olivetti d-COLOR MF3555 2XD_S000.002.271 devices. The Web Application is affected by Broken Access Control. It does not properly validate requests for access to data and functionality under the /mngset/authset path. By not verifying permissions for…

  • CVE-2022-29527HigApr 20, 2022
    risk 0.00cvss 7.0epss 0.00

    Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate privileges to root. This occurs in certain situations involving a race condition.

  • CVE-2022-28327HigApr 20, 2022
    risk 0.49cvss 7.5epss 0.04

    The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.

  • CVE-2022-27536HigApr 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Certificate.Verify in crypto/x509 in Go 1.18.x before 1.18.1 can be caused to panic on macOS when presented with certain malformed certificates. This allows a remote TLS server to cause a TLS client to panic.

  • CVE-2022-24675HigApr 20, 2022
    risk 0.49cvss 7.5epss 0.10

    encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.

  • CVE-2022-29266HigApr 20, 2022
    risk 0.49cvss 7.5epss 0.08

    In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information.

  • CVE-2022-27629HigApr 20, 2022
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in 'MicroPayments - Paid Author Subscriptions, Content, Downloads, Membership' versions prior to 1.9.6 allows a remote unauthenticated attacker to hijack the authentication of an administrator and perform unintended operation via…

  • CVE-2022-24860HigApr 20, 2022
    risk 0.48cvss 7.4epss 0.02

    Databasir is a team-oriented relational database model document management platform. Databasir 1.01 has Use of Hard-coded Cryptographic Key vulnerability. An attacker can use hard coding to generate login credentials of any user and log in to the service background located at…

  • CVE-2022-0071HigApr 19, 2022
    risk 0.57cvss 8.8epss 0.00

    Incomplete fix for CVE-2021-3101. Hotdog, prior to v1.0.2, did not mimic the resource limits, device restrictions, or syscall filters of the target JVM process. This would allow a container to exhaust the resources of the host, modify devices, or make syscalls that would…

  • CVE-2022-0070HigApr 19, 2022
    risk 0.57cvss 8.8epss 0.00

    Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.

  • CVE-2021-3101HigApr 19, 2022
    risk 0.57cvss 8.8epss 0.00

    Hotdog, prior to v1.0.1, did not mimic the capabilities or the SELinux label of the target JVM process. This would allow a container to gain full privileges on the host, bypassing restrictions set on the container.

  • CVE-2021-3100HigApr 19, 2022
    risk 0.57cvss 8.8epss 0.00

    The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM being patched, allowing it to escalate privileges.

  • CVE-2022-27527HigApr 19, 2022
    risk 0.51cvss 7.8epss 0.00

    A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files. It was fixed in PDFTron earlier than 9.0.7 version in Autodesk Navisworks 2022, and 2020.

  • CVE-2022-25788HigApr 19, 2022
    risk 0.51cvss 7.8epss 0.01

    A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT files. This vulnerability can be exploited to execute arbitrary code.

  • CVE-2022-21497HigApr 19, 2022
    risk 0.53cvss 8.1epss 0.02

    Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

  • CVE-2022-21491HigApr 19, 2022
    risk 0.51cvss 7.8epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.34. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…

  • CVE-2022-21476HigApr 19, 2022
    risk 0.49cvss 7.5epss 0.04

    Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2.…

  • CVE-2022-21466HigApr 19, 2022
    risk 0.49cvss 7.5epss 0.02

    Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Tools and Frameworks). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…

  • CVE-2022-21464HigApr 19, 2022
    risk 0.53cvss 8.2epss 0.02

    Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). The supported version that is affected is Prior to 9.2.6.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2022-21449HigApr 19, 2022
    risk 0.52cvss 7.5epss 0.60

    Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.2 and 18; Oracle GraalVM Enterprise Edition: 21.3.1 and 22.0.0.2. Easily exploitable…

  • CVE-2022-21446HigApr 19, 2022
    risk 0.53cvss 8.2epss 0.01

    Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris. Successful…