VYPR

CVEs

102,253 total · page 1175 of 2,046

  • CVE-2022-1006HigApr 11, 2022
    risk 0.47cvss 7.2epss 0.01

    The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the id parameter when editing Calendars, which could allow high privilege users such as admin to perform SQL injection attacks

  • CVE-2022-0989HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load images that hide malware for example from passing malicious domains to hide their trace, by making them pass through the vulnerable domain.

  • CVE-2022-0920HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its endpoints, which could allow customers to access all bookings and other customer's data

  • CVE-2022-0828HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.02

    The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password…

  • CVE-2022-27089HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.00

    In Fujitsu PlugFree Network <= 7.3.0.3, an Unquoted service path in PFNService.exe software allows a local attacker to potentially escalate privileges to system level.

  • CVE-2022-27088HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges.

  • CVE-2022-27041HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to inject SQL queries to extract information from databases.

  • CVE-2022-26413HigApr 11, 2022
    risk 0.52cvss 8.0epss 0.01

    A command injection vulnerability in the CGI program of Zyxel VMG3312-T20A firmware version 5.30(ABFX.5)C0 could allow a local authenticated attacker to execute arbitrary OS commands on a vulnerable device via a LAN interface.

  • CVE-2022-0556HigApr 11, 2022
    risk 0.47cvss 7.3epss 0.00

    A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1.1.4, which could allow an attacker to execute arbitrary code as a local administrator.

  • CVE-2022-1252HigApr 11, 2022
    risk 0.53cvss 8.2epss 0.01

    Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5.5.5 and below uses weak encryption algorithms leading to sensitive information exposure. This allows an attacker to derive the…

  • CVE-2021-32162HigApr 11, 2022
    risk 0.57cvss 8.8epss 0.03

    A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 through the File Manager feature.

  • CVE-2021-32159HigApr 11, 2022
    risk 0.57cvss 8.8epss 0.02

    A Cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Upload and Download feature.

  • CVE-2021-32156HigApr 11, 2022
    risk 0.57cvss 8.8epss 0.02

    A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.

  • CVE-2022-28893HigApr 11, 2022
    risk 0.00cvss 7.8epss 0.00

    The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state.

  • CVE-2022-27295HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formAdvanceSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

  • CVE-2022-27294HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formWlanWizardSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

  • CVE-2022-27293HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.03

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formWlanSetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the webpage parameter.

  • CVE-2022-27292HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter.

  • CVE-2022-27291HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formdumpeasysetup. This vulnerability allows attackers to cause a Denial of Service (DoS) via the config.save_network_enabled parameter.

  • CVE-2022-27290HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanDhcpplus. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

  • CVE-2022-27289HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanL2TP. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

  • CVE-2022-27288HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPTP. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

  • CVE-2022-27287HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPPoE. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

  • CVE-2022-27286HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanNonLogin. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

  • CVE-2022-27279HigApr 10, 2022
    risk 0.49cvss 7.5epss 0.01

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file read via the function sub_177E0.

  • CVE-2022-27883HigApr 9, 2022
    risk 0.48cvss 7.3epss 0.01

    A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-crafted file as a symlink that can lead to privilege escalation. Please note that an attacker must at least have low-level privileges on the system to attempt to…

  • CVE-2022-26180HigApr 8, 2022
    risk 0.61cvss 8.8epss 0.04

    qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.

  • CVE-2022-26854HigApr 8, 2022
    risk 0.53cvss 8.1epss 0.01

    Dell PowerScale OneFS, versions 8.2.x-9.2.x, contain risky cryptographic algorithms. A remote unprivileged malicious attacker could potentially exploit this vulnerability, leading to full system access

  • CVE-2022-26852HigApr 8, 2022
    risk 0.53cvss 8.1epss 0.01

    Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a predictable seed in pseudo-random number generator. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to an account compromise.

  • CVE-2021-36288HigApr 8, 2022
    risk 0.56cvss 8.6epss 0.01

    Dell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unauthenticated users to read/write restricted files

  • CVE-2021-36287HigApr 8, 2022
    risk 0.48cvss 7.3epss 0.02

    Dell VNX2 for file version 8.1.21.266 and earlier, contain an unauthenticated remote code execution vulnerability which may lead unauthenticated users to execute commands on the system.

  • CVE-2021-43498HigApr 8, 2022
    risk 0.49cvss 7.5epss 0.02

    An Access Control vulnerability exists in ATutor 2.2.4 in password_reminder.php when the g, id, h, form_password_hidden, and form_change HTTP POST parameters are set.

  • CVE-2021-43515HigApr 8, 2022
    risk 0.44cvss 7.8epss 0.01

    CSV Injection (aka Excel Macro Injection or Formula Injection) exists in creating new timesheet in Kimai. By filling the Description field with malicious payload, it will be mistreated while exporting to a CSV file.

  • CVE-2022-22339HigApr 8, 2022
    risk 0.47cvss 7.3epss 0.01

    IBM Planning Analytics 2.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 219736.

  • CVE-2021-43521HigApr 8, 2022
    risk 0.49cvss 7.5epss 0.01

    A Buffer Overflow vulnerability exists in zlog 1.2.15 via zlog_conf_build_with_file in src/zlog/src/conf.c.

  • CVE-2021-43483HigApr 8, 2022
    risk 0.52cvss 8.0epss 0.01

    An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a malicious user to read or update the configuraiton without authentication.

  • CVE-2021-40656HigApr 8, 2022
    risk 0.50cvss 8.8epss 0.01

    libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.

  • CVE-2020-4668HigApr 8, 2022
    risk 0.57cvss 8.8epss 0.00

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.3, and 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM…

  • CVE-2022-27046HigApr 8, 2022
    risk 0.57cvss 8.8epss 0.01

    libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.

  • CVE-2022-27044HigApr 8, 2022
    risk 0.57cvss 8.8epss 0.01

    libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.

  • CVE-2021-41715HigApr 8, 2022
    risk 0.57cvss 8.8epss 0.01

    libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.

  • CVE-2021-46367HigApr 8, 2022
    risk 0.49cvss 7.2epss 0.30

    RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated attacker can upload a PHP file and bypass the .htacess configuration to deny execution of .php files in media and files directory by default.

  • CVE-2021-46436HigApr 8, 2022
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php.

  • CVE-2022-28002HigApr 8, 2022
    risk 0.49cvss 7.5epss 0.02

    Movie Seat Reservation v1 was discovered to contain an unauthenticated file disclosure vulnerability via /index.php?page=home.

  • CVE-2022-28000HigApr 8, 2022
    risk 0.57cvss 8.8epss 0.02

    Car Rental System v1.0 was discovered to contain a SQL injection vulnerability at /Car_Rental/booking.php via the id parameter.

  • CVE-2022-27992HigApr 8, 2022
    risk 0.57cvss 8.8epss 0.02

    Zoo Management System v1.0 was discovered to contain a SQL injection vulnerability at /public_html/animals via the class_id parameter.

  • CVE-2022-27352HigApr 8, 2022
    risk 0.57cvss 8.8epss 0.03

    Simple House Rental System v1 was discovered to contain an arbitrary file upload vulnerability via /app/register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27349HigApr 8, 2022
    risk 0.47cvss 7.2epss 0.02

    Social Codia SMS v1 was discovered to contain an arbitrary file upload vulnerability via addteacher.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27346HigApr 8, 2022
    risk 0.57cvss 8.8epss 0.03

    Ecommece-Website v1.1.0 was discovered to contain an arbitrary file upload vulnerability via /admin/index.php?slides. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27064HigApr 8, 2022
    risk 0.57cvss 8.8epss 0.03

    Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.