VYPR

CVEs

102,253 total · page 1180 of 2,046

  • CVE-2021-32960HigApr 1, 2022
    risk 0.55cvss 8.5epss 0.02

    Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on the computer name. If successfully…

  • CVE-2021-32957HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    A function in MDT AutoSave versions prior to v6.02.06 is used to retrieve system information for a specific process, and this information collection executes multiple commands and summarizes the information into an XML. This function and subsequent process gives full path to the…

  • CVE-2021-32949HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path to another path and traversing the directory, allowing the replacement of an existing file with a malicious file.

  • CVE-2021-32945HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.00

    An attacker could decipher the encryption and gain access to MDT AutoSave versions prior to v6.02.06.

  • CVE-2021-32937HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a malicious command to the working directory where the read and…

  • CVE-2021-28504HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected.

  • CVE-2021-27501HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.

  • CVE-2021-26624HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.02

    An local privilege escalation vulnerability due to a "runasroot" command in eScan Anti-Virus. This vulnerability is due to invalid arguments and insufficient execution conditions related to "runasroot" command. This vulnerability can induce remote attackers to exploit root…

  • CVE-2021-26623HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.01

    A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. Remote attackers can induce exploit malicious code using this function.

  • CVE-2021-22277HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder Safe, Compact Product Suite - Control and I/O, ABB Base Software for SoftControl allows an attacker to cause the denial of service.

  • CVE-2020-25691HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system availability.

  • CVE-2019-14839HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc.

  • CVE-2022-24426HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell Command | Update, Dell Update, and Alienware Update version 4.4.0 contains a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation.

  • CVE-2022-24066HigApr 1, 2022
    risk 0.46cvss 8.1epss 0.04

    The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2421199) which only patches against the git fetch attack vector. A similar use of the --upload-pack feature of git…

  • CVE-2022-23155HigApr 1, 2022
    risk 0.47cvss 7.2epss 0.01

    Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges can exploit this vulnerability in order to execute arbitrary code on the system.

  • CVE-2022-24440HigApr 1, 2022
    risk 0.46cvss 8.1epss 0.03

    The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git…

  • CVE-2022-21223HigApr 1, 2022
    risk 0.00cvss 8.1epss 0.02

    The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set.…

  • CVE-2022-22332HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocation mechanism for the JWT token. IBM X-Force ID: 219131.

  • CVE-2022-22331HigApr 1, 2022
    risk 0.46cvss 7.1epss 0.01

    IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 219130.

  • CVE-2022-22327HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 218859.

  • CVE-2022-21235HigApr 1, 2022
    risk 0.46cvss 8.1epss 0.02

    The package github.com/masterminds/vcs before 1.13.3 are vulnerable to Command Injection via argument injection. When hg is executed, argument strings are passed to hg in a way that additional flags can be set. The additional flags can be used to perform a command injection.

  • CVE-2022-21947HigApr 1, 2022
    risk 0.54cvss 8.3epss 0.01

    A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to connect to the Dashboard API (steve) to carry out arbitrary actions. This issue affects: SUSE Rancher Desktop versions prior to V.

  • CVE-2021-35117HigApr 1, 2022
    risk 0.53cvss 8.2epss 0.01

    An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2021-35115HigApr 1, 2022
    risk 0.55cvss 8.4epss 0.00

    Improper handling of multiple session supported by PVM backend can lead to use after free in Snapdragon Auto, Snapdragon Mobile

  • CVE-2021-35110HigApr 1, 2022
    risk 0.53cvss 8.1epss 0.00

    Possible buffer overflow to improper validation of hash segment of file while allocating memory in Snapdragon Connectivity, Snapdragon Mobile

  • CVE-2021-35106HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible out of bound read due to improper length calculation of WMI message. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-35105HigApr 1, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible out of bounds access due to improper input validation during graphics profiling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-35103HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Possible out of bound write due to improper validation of number of timer values received from firmware while syncing timers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired…

  • CVE-2021-35089HigApr 1, 2022
    risk 0.55cvss 8.4epss 0.00

    Possible buffer overflow due to lack of input IB amount validation while processing the user command in Snapdragon Auto

  • CVE-2021-35088HigApr 1, 2022
    risk 0.53cvss 8.2epss 0.01

    Possible out of bound read due to improper validation of IE length during SSID IE parse when channel is DFS in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon…

  • CVE-2021-30333HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper validation of buffer size input to the EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

  • CVE-2021-30332HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Possible assertion due to improper validation of OTA configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-30329HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Possible assertion due to improper validation of TCI configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-30328HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Possible assertion due to improper validation of invalid NR CSI-IM resource configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-1950HigApr 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper cleaning of secure memory between authenticated users can lead to face authentication bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

  • CVE-2022-24802HigApr 1, 2022
    risk 0.46cvss 8.1epss 0.02

    deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords(). This issue has been patched in version 4.0.2. There are no known…

  • CVE-2022-27052HigMar 31, 2022
    risk 0.51cvss 7.8epss 0.00

    FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.

  • CVE-2022-27050HigMar 31, 2022
    risk 0.51cvss 7.8epss 0.00

    BitComet Service for Windows before version 1.8.6 contains an unquoted service path vulnerability which allows attackers to escalate privileges to the system level.

  • CVE-2022-24798HigMar 31, 2022
    risk 0.42cvss 7.5epss 0.01

    Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. IRRd did not always filter password hashes in query responses relating to `mntner` objects and database exports. This may have allowed adversaries to retrieve some of…

  • CVE-2022-24794HigMar 31, 2022
    risk 0.42cvss 7.5epss 0.01

    Express OpenID Connect is an Express JS middleware implementing sign on for Express web apps using OpenID Connect. Users of the `requiresAuth` middleware, either directly or through the default `authRequired` option, are vulnerable to an Open Redirect when the middleware is…

  • CVE-2022-24791HigMar 31, 2022
    risk 0.46cvss 8.1epss 0.01

    Wasmtime is a standalone JIT-style runtime for WebAssembly, using Cranelift. There is a use after free vulnerability in Wasmtime when both running Wasm that uses externrefs and enabling epoch interruption in Wasmtime. If you are not explicitly enabling epoch interruption (it is…

  • CVE-2022-24758HigMar 31, 2022
    risk 0.49cvss 7.5epss 0.01

    The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other header values are recorded in Jupyter…

  • CVE-2021-37517HigMar 31, 2022
    risk 0.42cvss 7.5epss 0.01

    An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.

  • CVE-2021-36625HigMar 31, 2022
    risk 0.50cvss 8.8epss 0.01

    An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.

  • CVE-2021-34257HigMar 31, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple Remote Code Execution (RCE) vulnerabilities exist in WPanel 4 4.3.1 and below via a malicious PHP file upload to (1) Dashboard's Avatar image, (2) Posts Folder image, (3) Pages Folder image and (4) Gallery Folder image.

  • CVE-2022-1176HigMar 31, 2022
    risk 0.42cvss 7.5epss 0.01

    Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.

  • CVE-2022-25915HigMar 31, 2022
    risk 0.57cvss 8.8epss 0.00

    Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware…

  • CVE-2022-1191HigMar 31, 2022
    risk 0.00cvss 8.1epss 0.01

    SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.

  • CVE-2022-28128HigMar 31, 2022
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path vulnerability in AttacheCase ver.3.6.1.0 and earlier allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.

  • CVE-2022-26019HigMar 31, 2022
    risk 0.58cvss 8.8epss 0.04

    Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change NTP GPS settings to rewrite existing files on the file…