VYPR

CVEs

102,253 total · page 1174 of 2,046

  • CVE-2022-24833HigApr 11, 2022
    risk 0.46cvss 8.2epss 0.01

    PrivateBin is minimalist, open source online pastebin clone where the server has zero knowledge of pasted data. In PrivateBin < v1.4.0 a cross-site scripting (XSS) vulnerability was found. The vulnerability is present in all versions from v0.21 of the project, which was at the…

  • CVE-2022-24832HigApr 11, 2022
    risk 0.00cvss 8.2epss 0.02

    GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD Server fails to correctly escape special characters when using the username to construct LDAP queries. While this does not directly allow arbitrary LDAP data…

  • CVE-2022-24827HigApr 11, 2022
    risk 0.00cvss 8.1epss 0.01

    Elide is a Java library that lets you stand up a GraphQL/JSON-API web service with minimal effort. When leveraging the following together: Elide Aggregation Data Store for Analytic Queries, Parameterized Columns (A column that requires a client provided parameter), and a…

  • CVE-2022-27838HigApr 11, 2022
    risk 0.50cvss 7.7epss 0.00

    Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege.

  • CVE-2022-27836HigApr 11, 2022
    risk 0.55cvss 8.4epss 0.00

    Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation logic to prevent arbitrary…

  • CVE-2022-27835HigApr 11, 2022
    risk 0.49cvss 7.6epss 0.00

    Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.

  • CVE-2022-27830HigApr 11, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-27829HigApr 11, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-27828HigApr 11, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in MediaMonitorEvent prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-27827HigApr 11, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in MediaMonitorDimension prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-27826HigApr 11, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-27578HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.00

    An attacker can perform a privilege escalation through the SICK OEE if the application is installed in a directory where non authenticated or low privilege users can modify its content.

  • CVE-2022-27572HigApr 11, 2022
    risk 0.53cvss 8.1epss 0.01

    Heap-based buffer overflow vulnerability in parser_ipma function of libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attackers.

  • CVE-2022-27571HigApr 11, 2022
    risk 0.53cvss 8.1epss 0.01

    Heap-based buffer overflow vulnerability in sheifd_get_info_image function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.

  • CVE-2022-27570HigApr 11, 2022
    risk 0.53cvss 8.1epss 0.01

    Heap-based buffer overflow vulnerability in parser_single_iref function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.

  • CVE-2022-27569HigApr 11, 2022
    risk 0.53cvss 8.1epss 0.01

    Heap-based buffer overflow vulnerability in parser_infe function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.

  • CVE-2022-27568HigApr 11, 2022
    risk 0.53cvss 8.1epss 0.01

    Heap-based buffer overflow vulnerability in parser_iloc function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.

  • CVE-2022-27528HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.01

    A maliciously crafted DWFX and SKP files in Autodesk Navisworks 2022 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.

  • CVE-2022-26098HigApr 11, 2022
    risk 0.53cvss 8.1epss 0.01

    Heap-based buffer overflow vulnerability in sheifd_create function of libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attackers.

  • CVE-2022-26092HigApr 11, 2022
    risk 0.48cvss 7.4epss 0.00

    Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows arbitrary code execution.

  • CVE-2022-25796HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.01

    A Double Free vulnerability allows remote malicious actors to execute arbitrary code on DWF file in Autodesk Navisworks 2022 within affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…

  • CVE-2022-25794HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.01

    An Out-Of-Bounds Read Vulnerability in Autodesk FBX Review version 1.5.2 and prior may lead to code execution through maliciously crafted ActionScript Byte Code 'ABC' files or information disclosure. ABC files are created by the Flash compiler and contain executable code. This…

  • CVE-2022-25792HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.01

    A maliciously crafted DXF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability can be exploited to execute arbitrary code.

  • CVE-2022-25791HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.01

    A Memory Corruption vulnerability for DWF and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 may lead to code execution through maliciously crafted DLL files.

  • CVE-2022-25790HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.01

    A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated boundaries when parsing the DWF files. Exploitation of this vulnerability may lead to code execution.

  • CVE-2022-25789HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.02

    A maliciously crafted DWF, 3DS and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.

  • CVE-2022-24829HigApr 11, 2022
    risk 0.00cvss 8.1epss 0.01

    Garden is an automation platform for Kubernetes development and testing. In versions prior to 0.12.39 multiple endpoints did not require authentication. In some operating modes this allows for an attacker to gain access to the application erroneously. The configuration is leaked…

  • CVE-2022-24815HigApr 11, 2022
    risk 0.46cvss 8.1epss 0.01

    JHipster is a development platform to quickly generate, develop, & deploy modern web applications & microservice architectures. SQL Injection vulnerability in entities for applications generated with the option "reactive with Spring WebFlux" enabled and an SQL database using…

  • CVE-2022-22964HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.00

    VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file.

  • CVE-2022-22962HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.00

    VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file.

  • CVE-2022-22572HigApr 11, 2022
    risk 0.57cvss 8.8epss 0.02

    A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality. The vulnerability affects Incapptic Connect version < 1.40.1.

  • CVE-2022-22257HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerability may affect data integrity.

  • CVE-2022-22256HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    The DFX module has an access control vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-22255HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    The application framework has a common DoS vulnerability.Successful exploitation of this vulnerability may affect the availability.

  • CVE-2022-22254HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2022-22253HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.00

    The DFX module has a vulnerability of improper validation of integrity check values.Successful exploitation of this vulnerability may affect system stability.

  • CVE-2022-1316HigApr 11, 2022
    risk 0.00cvss 8.8epss 0.00

    Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation

  • CVE-2022-1262HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.02

    A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root.

  • CVE-2022-0999HigApr 11, 2022
    risk 0.57cvss 8.8epss 0.01

    An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.

  • CVE-2022-0835HigApr 11, 2022
    risk 0.53cvss 8.1epss 0.00

    AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-privileged user.

  • CVE-2021-4047HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9.

  • CVE-2021-46740HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    The device authentication service module has a defect vulnerability introduced in the design process.Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-40065HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    The communication module has a service logic error vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-43442HigApr 11, 2022
    risk 0.53cvss 8.1epss 0.01

    A Logic Flaw vulnerability exists in i3 International Inc Annexxus Camera V5.2.0 build 150317 (Ax46), V5.0.9 build 151106 (Ax68), and V5.0.9 build 150615 (Ax78) due to a failure to allow the creation of more than one administrator account; however, this can be bypassed by…

  • CVE-2021-38930HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210331.

  • CVE-2021-38929HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210330.

  • CVE-2021-37292HigApr 11, 2022
    risk 0.47cvss 7.2epss 0.07

    An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor account. A malicious user can log in using the backdor account with admin highest privileges and obtain system control.

  • CVE-2021-40219HigApr 11, 2022
    risk 0.57cvss 8.8epss 0.03

    Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution.

  • CVE-2022-1023HigApr 11, 2022
    risk 0.47cvss 7.2epss 0.01

    The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file

  • CVE-2022-1008HigApr 11, 2022
    risk 0.47cvss 7.2epss 0.02

    The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed