VYPR

CVEs

102,253 total · page 1172 of 2,046

  • CVE-2021-43287HigApr 14, 2022
    risk 0.02cvss 7.5epss 0.28

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.

  • CVE-2022-24847HigApr 13, 2022
    risk 0.40cvss 7.2epss 0.01

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The GeoServer security mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class deserialization and result in arbitrary code…

  • CVE-2022-24845HigApr 13, 2022
    risk 0.50cvss 8.8epss 0.01

    Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In affected versions, the return of `.returns_int128()` is not validated to fall within the bounds of `int128`. This issue can result in a misinterpretation of the integer value and lead to…

  • CVE-2022-24843HigApr 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin 2.50 has arbitrary file read vulnerability due to a lack of parameter validation. This has been resolved in version 2.5.1. There are no known…

  • CVE-2022-24844HigApr 13, 2022
    risk 0.53cvss 8.1epss 0.01

    Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. The problem occurs in the following code in server/service/system/sys_auto_code_pgsql.go, which means that PostgreSQL must be used as the database for this…

  • CVE-2022-24828HigApr 13, 2022
    risk 0.47cvss 8.3epss 0.02

    Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$identifier` argument. This leads to a vulnerability on…

  • CVE-2022-24818HigApr 13, 2022
    risk 0.00cvss 8.2epss 0.02

    GeoTools is an open source Java library that provides tools for geospatial data. The GeoTools library has a number of data sources that can perform unchecked JNDI lookups, which in turn can be used to perform class deserialization and result in arbitrary code execution. Similar…

  • CVE-2022-24788HigApr 13, 2022
    risk 0.39cvss 7.1epss 0.01

    Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Versions of vyper prior to 0.3.2 suffer from a potential buffer overrun. Importing a function from a JSON interface which returns `bytes` generates bytecode which does not clamp bytes length,…

  • CVE-2022-1347HigApr 13, 2022
    risk 0.00cvss 8.4epss 0.01

    Stored XSS in the "Username" & "Email" input fields leads to account takeover of Admin & Co-admin users in GitHub repository causefx/organizr prior to 2.1.1810. Account takeover and privilege escalation

  • CVE-2022-27524HigApr 13, 2022
    risk 0.46cvss 7.1epss 0.01

    An out-of-bounds read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a crash through using a maliciously crafted DWG file as an Input. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the…

  • CVE-2022-27523HigApr 13, 2022
    risk 0.46cvss 7.1epss 0.01

    A buffer over-read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a crash through using a maliciously crafted DWG file as an Input. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the…

  • CVE-2022-25797HigApr 13, 2022
    risk 0.51cvss 7.8epss 0.01

    A maliciously crafted PDF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to dereference for a write beyond the allocated buffer while parsing PDF files. The vulnerability exists because the application fails to handle a crafted PDF file, which causes an unhandled…

  • CVE-2022-25795HigApr 13, 2022
    risk 0.51cvss 7.8epss 0.02

    A Memory Corruption Vulnerability in Autodesk TrueView 2022 and 2021 may lead to remote code execution through maliciously crafted DWG files.

  • CVE-2022-22960HigKEVApr 13, 2022
    risk 0.69cvss 7.8epss 0.37

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.

  • CVE-2022-22958HigApr 13, 2022
    risk 0.47cvss 7.2epss 0.03

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which…

  • CVE-2022-22957HigApr 13, 2022
    risk 0.52cvss 7.2epss 0.23

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malicious JDBC URI which…

  • CVE-2021-22797HigApr 13, 2022
    risk 0.53cvss 7.8epss 0.26

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when a malicious project file…

  • CVE-2019-6834HigApr 13, 2022
    risk 0.48cvss 7.3epss 0.01

    A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when placing a malicious user to be authenticated for this vulnerability to be successfully exploited. Affected…

  • CVE-2015-20107HigApr 13, 2022
    risk 0.50cvss 7.6epss 0.07

    In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack…

  • CVE-2022-28052HigApr 13, 2022
    risk 0.52cvss 8.0epss 0.02

    Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution.

  • CVE-2021-46167HigApr 13, 2022
    risk 0.51cvss 7.8epss 0.00

    An access control issue in the authentication module of wizplat PD065 v1.19 allows attackers to access sensitive data and cause a Denial of Service (DoS).

  • CVE-2022-1339HigApr 13, 2022
    risk 0.42cvss 7.5epss 0.05

    SQL injection in ElementController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data

  • CVE-2022-29156HigApr 13, 2022
    risk 0.00cvss 7.8epss 0.00

    drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release.

  • CVE-2022-26151HigApr 13, 2022
    risk 0.47cvss 7.2epss 0.08

    Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.

  • CVE-2021-44520HigApr 13, 2022
    risk 0.58cvss 8.8epss 0.06

    In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.

  • CVE-2022-29050HigApr 12, 2022
    risk 0.50cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over FTP Plugin 1.16 and earlier allows attackers to connect to an FTP server using attacker-specified credentials.

  • CVE-2022-27418HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.01

    Tcpreplay v4.4.1 has a heap-based buffer overflow in do_checksum_math at /tcpedit/checksum.c.

  • CVE-2022-27416HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.01

    Tcpreplay v4.4.1 was discovered to contain a double-free via __interceptor_free.

  • CVE-2022-27387HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, which is exploited via specially crafted SQL statements.

  • CVE-2022-27386HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.

  • CVE-2022-27385HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27384HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27383HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.6 and below was discovered to contain an use-after-free in the component my_strcasecmp_8bit, which is exploited via specially crafted SQL statements.

  • CVE-2022-27382HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component Item_field::used_tables/update_depend_map_for_order.

  • CVE-2022-27381HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component Field::set_default of MariaDB Server v10.6 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27380HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component my_decimal::operator= of MariaDB Server v10.6.3 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27379HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component Arg_comparator::compare_real_fixed of MariaDB Server v10.6.2 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27378HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in the component Create_tmp_table::finalize of MariaDB Server v10.7 and below was discovered to allow attackers to cause a Denial of Service (DoS) via specially crafted SQL statements.

  • CVE-2022-27377HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component Item_func_in::cleanup(), which is exploited via specially crafted SQL statements.

  • CVE-2022-27376HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB Server v10.6.5 and below was discovered to contain an use-after-free in the component Item_args::walk_arg, which is exploited via specially crafted SQL statements.

  • CVE-2022-24842HigApr 12, 2022
    risk 0.00cvss 8.8epss 0.02

    MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. A security issue was found where an non-admin user is able to create service accounts for root or other admin users and then is able to assume their access policies via the…

  • CVE-2022-24767HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.01

    GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.

  • CVE-2022-24412HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Dell EMC PowerScale OneFS 8.2.x - 9.3.0.x contain an improper handling of value vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to denial-of-service.

  • CVE-2022-24411HigApr 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability. A local attacker with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE could potentially exploit this vulnerability, leading to elevation of privilege. This could potentially allow users to…

  • CVE-2022-24070HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.09

    Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do…

  • CVE-2022-23161HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Dell PowerScale OneFS versions 8.2.x - 9.3.0.x contain a denial-of-service vulnerability in SmartConnect. An unprivileged network attacker may potentially exploit this vulnerability, leading to denial-of-service.

  • CVE-2022-22562HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Dell PowerScale OneFS, versions 8.2.0-9.3.0, contain a improper handling of missing values exploit. An unauthenticated network attacker could potentially exploit this denial-of-service vulnerability.

  • CVE-2022-22561HigApr 12, 2022
    risk 0.53cvss 8.1epss 0.01

    Dell PowerScale OneFS, versions 8.2.x-9.3.0.x, contain an improper restriction of excessive authentication attempts. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to compromised accounts.

  • CVE-2022-22560HigApr 12, 2022
    risk 0.46cvss 7.1epss 0.00

    Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user with knowledge of the credentials to login as the admin user to the backend ethernet switch of a PowerScale cluster. The attacker can exploit this vulnerability to take the switch…

  • CVE-2022-22559HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Dell PowerScale OneFS, version 9.3.0, contains a use of a broken or risky cryptographic algorithm. An unprivileged network attacker could exploit this vulnerability, leading to the potential for information disclosure.