VYPR

CVEs

102,253 total · page 1179 of 2,046

  • CVE-2022-24787HigApr 4, 2022
    risk 0.00cvss 7.5epss 0.01

    Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. In version 0.3.1 and prior, bytestrings can have dirty bytes in them, resulting in the word-for-word comparisons giving incorrect results. Even without dirty nonzero bytes, two bytestrings can compare…

  • CVE-2021-43464HigApr 4, 2022
    risk 0.57cvss 8.8epss 0.01

    A Remiote Code Execution (RCE) vulnerability exiss in Subrion CMS 4.2.1 via modified code in a background field; when the information is modified, the data in it will be executed through eval().

  • CVE-2022-24785HigApr 4, 2022
    risk 0.42cvss 7.5epss 0.06

    Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch…

  • CVE-2020-28062HigApr 4, 2022
    risk 0.47cvss 7.2epss 0.02

    An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plugins /, which could let a remote malicious user execute arbitrary code.

  • CVE-2022-0887HigApr 4, 2022
    risk 0.47cvss 7.2epss 0.01

    The Easy Social Icons WordPress plugin before 3.1.4 does not sanitize the selected_icons attribute to the cnss_widget before using it in an SQL statement, leading to a SQL injection vulnerability.

  • CVE-2022-0709HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.02

    The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's booking calendar, but this token is returned in the json response to unauthenticated users performing a booking, leading to a sensitive data disclosure vulnerability.

  • CVE-2022-0537HigApr 4, 2022
    risk 0.47cvss 7.2epss 0.01

    The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS settings and upload arbitrary files to the site through the "ajax_save" function. The file is written relative to the current 's stylesheet…

  • CVE-2022-0403HigApr 4, 2022
    risk 0.53cvss 8.1epss 0.01

    The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any…

  • CVE-2021-43463HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service executable service path.

  • CVE-2021-43460HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An Unquoted Service Path vulnerability exists in System Explorer 7.0.0 via via a specially crafted file in the SystemExplorerHelpService service executable path.

  • CVE-2022-1026HigApr 4, 2022
    risk 0.57cvss 8.6epss 0.15

    Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficiently protected address book export function.

  • CVE-2021-43458HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) VembuBDR360Agent, or (3) VembuOffice365Agent service paths.

  • CVE-2021-43457HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An Unquoted Service Path vulnerability exists in bVPN 2.5.1 via a specially crafted file in the waselvpnserv service path.

  • CVE-2021-43456HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the RumbleService executable service path.

  • CVE-2021-43455HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An Unquoted Service Path vulnerability exists in FreeLAN 2.2 via a specially crafted file in the FreeLAN Service path.

  • CVE-2021-43454HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An Unquoted Service Path vulnerability exists in AnyTXT Searcher 1.2.394 via a specially crafted file in the ATService path. .

  • CVE-2022-28062HigApr 4, 2022
    risk 0.57cvss 8.8epss 0.02

    Car Rental System v1.0 contains an arbitrary file upload vulnerability via the Add Car component which allows attackers to upload a webshell and execute arbitrary code.

  • CVE-2022-27435HigApr 4, 2022
    risk 0.57cvss 8.8epss 0.02

    An unrestricted file upload at /public/admin/index.php?add_product of Ecommerce-Website v1.1.0 allows attackers to upload a webshell via the Product Image component.

  • CVE-2021-44138HigApr 4, 2022
    risk 0.50cvss 7.5epss 0.14

    There is a Directory traversal vulnerability in Caucho Resin, as distributed in Resin 4.0.52 - 4.0.56, which allows remote attackers to read files in arbitrary directories via a ; in a pathname within an HTTP request.

  • CVE-2021-36776HigApr 4, 2022
    risk 0.57cvss 8.8epss 0.01

    A Improper Access Control vulnerability in SUSE Rancher allows remote attackers impersonate arbitrary users. This issue affects: SUSE Rancher Rancher versions prior to 2.5.10.

  • CVE-2021-36775HigApr 4, 2022
    risk 0.57cvss 8.8epss 0.01

    a Improper Access Control vulnerability in SUSE Rancher allows users to keep privileges that should have been revoked. This issue affects: SUSE Rancher Rancher versions prior to 2.4.18; Rancher versions prior to 2.5.12; Rancher versions prior to 2.6.3.

  • CVE-2022-27249HigApr 3, 2022
    risk 0.58cvss 8.8epss 0.05

    An unrestricted file upload vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to execute arbitrary code by using UploadDwg to upload a crafted aspx file to the web root, and then visiting the URL for this aspx resource.

  • CVE-2022-26233HigApr 3, 2022
    risk 0.50cvss 7.5epss 0.15

    Barco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensitive information and components. Requests must begin with the "GET /..\.." substring.

  • CVE-2021-30065HigApr 3, 2022
    risk 0.49cvss 7.5epss 0.01

    On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, crafted ModBus packets can bypass the ModBus enforcer. NOTE: this issue exists because of an incomplete fix of CVE-2017-11401.

  • CVE-2021-30063HigApr 3, 2022
    risk 0.49cvss 7.5epss 0.01

    On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can cause an OPC enforcer denial of service.

  • CVE-2021-30062HigApr 3, 2022
    risk 0.49cvss 7.5epss 0.01

    On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can bypass the OPC enforcer.

  • CVE-2022-28391HigApr 3, 2022
    risk 0.57cvss 8.8epss 0.03

    BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatible terminal. Alternatively, the attacker could choose to change the terminal's colors.

  • CVE-2022-28390HigApr 3, 2022
    risk 0.00cvss 7.8epss 0.00

    ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.

  • CVE-2022-28380HigApr 3, 2022
    risk 0.49cvss 7.5epss 0.02

    The rc-httpd component through 2022-03-31 for 9front (Plan 9 fork) allows ..%2f directory traversal if serve-static is used.

  • CVE-2022-0088HigApr 3, 2022
    risk 0.44cvss 7.4epss 0.02

    Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3.

  • CVE-2022-28376HigApr 3, 2022
    risk 0.53cvss 8.1epss 0.01

    Verizon 5G Home LVSKIHP outside devices through 2022-02-15 allow anyone (knowing the device's serial number) to access a CPE admin website, e.g., at the 10.0.0.1 IP address. The password (for the verizon username) is calculated by concatenating the serial number and the model…

  • CVE-2022-28355HigApr 2, 2022
    risk 0.49cvss 7.5epss 0.01

    randomUUID in Scala.js before 1.10.0 generates predictable values.

  • CVE-2022-26419HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.02

    Omron CX-Position (versions 2.5.3 and prior) is vulnerable to multiple stack-based buffer overflow conditions while parsing a specific project file, which may allow an attacker to locally execute arbitrary code.

  • CVE-2022-26417HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.01

    Omron CX-Position (versions 2.5.3 and prior) is vulnerable to a use after free memory condition while processing a specific project file, which may allow an attacker to execute arbitrary code.

  • CVE-2022-26022HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.01

    Omron CX-Position (versions 2.5.3 and prior) is vulnerable to an out-of-bounds write while processing a specific project file, which may allow an attacker to execute arbitrary code.

  • CVE-2022-25959HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.01

    Omron CX-Position (versions 2.5.3 and prior) is vulnerable to memory corruption while processing a specific project file, which may allow an attacker to execute arbitrary code.

  • CVE-2022-25159HigApr 1, 2022
    risk 0.53cvss 8.1epss 0.02

    Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU all versions, Mitsubishi Electric MELSEC…

  • CVE-2022-25156HigApr 1, 2022
    risk 0.53cvss 8.1epss 0.01

    Use of Weak Hash vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU all versions, Mitsubishi Electric MELSEC iQ-R series…

  • CVE-2022-25155HigApr 1, 2022
    risk 0.53cvss 8.1epss 0.02

    Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU all versions,…

  • CVE-2022-1159HigApr 1, 2022
    risk 0.50cvss 7.7epss 0.03

    Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio 5000 Logix Designer could inject controller code undetectable to a user.

  • CVE-2022-1098HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combined with the Incorrect Default Permissions vulnerability of 4.2.2 above, this makes it possible for an attacker to escalate privileges

  • CVE-2021-3847HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the…

  • CVE-2021-3461HigApr 1, 2022
    risk 0.46cvss 7.1epss 0.00

    A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].

  • CVE-2021-33657HigApr 1, 2022
    risk 0.00cvss 8.8epss 0.02

    There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a malicious .BMP file, an attacker can cause the application using this library to crash, denial of service or Code execution.

  • CVE-2021-33022HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

  • CVE-2021-33020HigApr 1, 2022
    risk 0.53cvss 8.2epss 0.01

    Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.

  • CVE-2021-33018HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    The use of a broken or risky cryptographic algorithm in Philips Vue PACS versions 12.2.x.x and prior is an unnecessary risk that may result in the exposure of sensitive information.

  • CVE-2021-32970HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.02

    Data can be copied without validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier, which may allow a remote attacker to cause denial-of-service conditions.

  • CVE-2021-32968HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.02

    Two buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O Series firmware version 2.2 or earlier may allow a remote attacker to cause a denial-of-service condition.

  • CVE-2021-32961HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    A getfile function in MDT AutoSave versions prior to v6.02.06 enables a user to supply an optional parameter, resulting in the processing of a request in a special manner. This can result in the execution of an unzip command and place a malicious .exe file in one of the…