VYPR

CVEs

102,253 total · page 1178 of 2,046

  • CVE-2022-0799HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker to perform local privilege escalation via a crafted offline installer file.

  • CVE-2022-0798HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

  • CVE-2022-0797HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.02

    Out of bounds memory access in Mojo in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

  • CVE-2022-0796HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Media in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0795HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Type confusion in Blink Layout in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0794HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebShare in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0793HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Cast in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension and engage in specific user interaction to potentially exploit heap corruption via a crafted Chrome Extension.

  • CVE-2022-0791HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Omnibox in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via user interactions.

  • CVE-2022-0789HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0470HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Out of bounds memory access in V8 in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0469HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Cast in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific interactions to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0468HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Payments in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0467HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Inappropriate implementation in Pointer Lock in Google Chrome on Windows prior to 98.0.4758.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2022-0465HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Extensions in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via user interaction.

  • CVE-2022-0464HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.

  • CVE-2022-0463HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.

  • CVE-2022-0460HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Window Dialogue in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0459HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Screen Capture in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who had compromised the renderer process and convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0458HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Thumbnail Tab Strip in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0457HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Type confusion in V8 in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0456HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Web Search in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via profile destruction.

  • CVE-2022-0454HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in ANGLE in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0453HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Reader Mode in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-23732HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.02

    A path traversal vulnerability was identified in GitHub Enterprise Server management console that allowed the bypass of CSRF protections. This could potentially lead to privilege escalation. To exploit this vulnerability, an attacker would need to target a user that was actively…

  • CVE-2022-0610HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Inappropriate implementation in Gamepad API in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0609HigKEVApr 5, 2022
    risk 0.71cvss 8.8epss 0.21

    Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0608HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Integer overflow in Mojo in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0607HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in GPU in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0606HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in ANGLE in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0605HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Webstore API in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and convinced a user to enage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0604HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in Tab Groups in Google Chrome prior to 98.0.4758.102 allowed an attacker who convinced a user to install a malicious extension and engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0603HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in File Manager in Google Chrome on Chrome OS prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-27442HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.01

    TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password.

  • CVE-2022-27650HigApr 4, 2022
    risk 0.00cvss 7.5epss 0.01

    A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker…

  • CVE-2022-27649HigApr 4, 2022
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an…

  • CVE-2022-23699HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2022-23698HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.01

    A remote unauthenticated disclosure of information vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2022-1190HigApr 4, 2022
    risk 0.57cvss 8.7epss 0.87

    Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.

  • CVE-2022-1175HigApr 4, 2022
    risk 0.59cvss 8.7epss 0.82

    Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

  • CVE-2021-33010HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.01

    An exception is thrown from a function in AVEVA System Platform versions 2017 through 2020 R2 P01, but it is not caught, which may cause a denial-of-service condition.

  • CVE-2021-33008HigApr 4, 2022
    risk 0.57cvss 8.8epss 0.01

    AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requires a provable user identity.

  • CVE-2021-32994HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.02

    Softing OPC UA C++ SDK (Software Development Kit) versions from 5.59 to 5.64 exported library functions don't properly validate received extension objects, which may allow an attacker to crash the software by sending a variety of specially crafted packets to access several…

  • CVE-2021-32985HigApr 4, 2022
    risk 0.47cvss 7.2epss 0.00

    AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communication is valid.

  • CVE-2021-32982HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during unlocking and project transfers. An attacker who has network visibility can observe the password exchange.

  • CVE-2021-32981HigApr 4, 2022
    risk 0.47cvss 7.2epss 0.01

    AVEVA System Platform versions 2017 through 2020 R2 P01 uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within…

  • CVE-2021-32978HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.01

    The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previously entered password was successful, the attacker can then use the password to unlock Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior…

  • CVE-2021-32977HigApr 4, 2022
    risk 0.47cvss 7.2epss 0.01

    AVEVA System Platform versions 2017 through 2020 R2 P01 does not verify, or incorrectly verifies, the cryptographic signature for data.

  • CVE-2022-26572HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Xerox ColorQube 8580 was discovered to contain an access control issue which allows attackers to print, view the status, and obtain sensitive information.

  • CVE-2022-24814HigApr 4, 2022
    risk 0.00cvss 8.8epss 0.01

    Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized JavaScript (JS) can be executed by inserting an iframe into the rich text html interface that links to a file uploaded HTML file that loads another uploaded JS…

  • CVE-2022-24801HigApr 4, 2022
    risk 0.46cvss 8.1epss 0.03

    Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request constructs more leniently than permitted by RFC 7230. This…