VYPR

CVEs

102,253 total · page 1182 of 2,046

  • CVE-2021-1000HigMar 30, 2022
    risk 0.51cvss 7.8epss 0.00

    In createBluetoothDeviceSlice of ConnectedDevicesSliceProvider.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-1155HigMar 30, 2022
    risk 0.41cvss 7.4epss 0.01

    Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10.

  • CVE-2022-1154HigMar 30, 2022
    risk 0.00cvss 7.8epss 0.01

    Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.

  • CVE-2022-23868HigMar 30, 2022
    risk 0.51cvss 7.8epss 0.01

    RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file.

  • CVE-2022-25598HigMar 30, 2022
    risk 0.49cvss 7.5epss 0.02

    Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher.

  • CVE-2022-27816HigMar 30, 2022
    risk 0.39cvss 7.1epss 0.00

    SWHKD 1.1.5 unsafely uses the /tmp/swhks.pid pathname. There can be data loss or a denial of service.

  • CVE-2020-24771HigMar 30, 2022
    risk 0.49cvss 7.5epss 0.02

    Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access published content.

  • CVE-2022-27815HigMar 30, 2022
    risk 0.44cvss 7.8epss 0.01

    SWHKD 1.1.5 unsafely uses the /tmp/swhkd.pid pathname. There can be an information leak or denial of service.

  • CVE-2022-27432HigMar 30, 2022
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) in Pluck CMS v4.7.15 allows attackers to change the password of any given user by exploiting this feature leading to account takeover.

  • CVE-2015-3298HigMar 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.

  • CVE-2021-44082HigMar 29, 2022
    risk 0.54cvss 8.3epss 0.03

    textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before submitting a file…

  • CVE-2022-21821HigMar 29, 2022
    risk 0.51cvss 7.8epss 0.02

    NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially crafted, corrupted file and locally execute cuobjdump against the file. Such an attack may lead to…

  • CVE-2021-43109HigMar 29, 2022
    risk 0.49cvss 7.5epss 0.01

    An SQL Injection vulnerability exits in PuneethReddyHC online-shopping-system as of 11/01/2021 via the p parameter in product.php.

  • CVE-2022-26839HigMar 29, 2022
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to an incorrect default permission in the DIAEnergie application, which may allow an attacker to plant new files (such as DLLs) or replace existing executable files.

  • CVE-2022-22941HigMar 29, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Masters, with a publisher_acl, if a user configured in the publisher_acl targets any minion connected to the Syndic, the Salt Master incorrectly interpreted no…

  • CVE-2022-22936HigMar 29, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server replies are susceptible to replay attacks, which can result in an attacker replaying job publishes causing minions to run old jobs. File server replies can also be…

  • CVE-2022-22934HigMar 29, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar data with the minion’s public key, which can result in attackers substituting arbitrary pillar data.

  • CVE-2022-1050HigMar 29, 2022
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commands when shared buffers are not yet allocated, potentially leading to a use-after-free condition.

  • CVE-2021-44081HigMar 29, 2022
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 characters, it leads to AMF denial of service.

  • CVE-2022-1055HigMar 29, 2022
    risk 0.51cvss 7.8epss 0.01

    A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5

  • CVE-2022-28155HigMar 29, 2022
    risk 0.53cvss 8.1epss 0.01

    Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-28154HigMar 29, 2022
    risk 0.53cvss 8.1epss 0.01

    Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-28150HigMar 29, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers to change the owners and item-specific permissions of a job.

  • CVE-2022-28142HigMar 29, 2022
    risk 0.49cvss 7.5epss 0.01

    Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Jenkins controller JVM when configured to ignore SSL/TLS issues.

  • CVE-2022-28140HigMar 29, 2022
    risk 0.46cvss 8.1epss 0.01

    Jenkins Flaky Test Handler Plugin 1.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-28136HigMar 29, 2022
    risk 0.50cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.

  • CVE-2022-1032HigMar 29, 2022
    risk 0.00cvss 7.2epss 0.02

    Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.

  • CVE-2022-1084HigMar 29, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in SourceCodester One Church Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /one_church/userregister.php. The manipulation leads to authentication bypass. The attack can be launched…

  • CVE-2022-1083HigMar 29, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in Microfinance Management System. The manipulation of arguments like customer_type_number/account_number/account_status_number/account_type_number with the input ' and (select * from(select(sleep(10)))Avx) and 'abc' = 'abc…

  • CVE-2022-1082HigMar 29, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been rated as critical. This issue affects the file /mims/login.php of the Login Page. The manipulation of the argument username/password with the input '||1=1# leads to sql injection. The…

  • CVE-2022-1080HigMar 29, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester One Church Management System 1.0. It has been declared as critical. This vulnerability affects code of the file attendancy.php as the manipulation of the argument search2 leads to sql injection. The attack can be initiated remotely.

  • CVE-2022-1078HigMar 29, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester College Website Management System 1.0. It has been classified as critical. Affected is the file /cwms/admin/?page=articles/view_article/. The manipulation of the argument id with the input ' and (select * from(select(sleep(10)))Avx)…

  • CVE-2022-1073HigMar 29, 2022
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely.

  • CVE-2021-44581HigMar 29, 2022
    risk 0.49cvss 7.5epss 0.01

    An SQL Injection vulnerabilty exists in Kreado Kreasfero 1.5 via the id parameter.

  • CVE-2022-26642HigMar 28, 2022
    risk 0.47cvss 7.2epss 0.01

    TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter.

  • CVE-2022-26641HigMar 28, 2022
    risk 0.47cvss 7.2epss 0.01

    TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.

  • CVE-2022-26640HigMar 28, 2022
    risk 0.47cvss 7.2epss 0.01

    TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter.

  • CVE-2022-26639HigMar 28, 2022
    risk 0.47cvss 7.2epss 0.01

    TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter.

  • CVE-2022-24789HigMar 28, 2022
    risk 0.49cvss 7.6epss 0.01

    C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user to exploit Server Side Request Forgery (SSRF) by causing the server to make arbitrary GET requests to other servers in the local network or on localhost. The…

  • CVE-2021-43103HigMar 28, 2022
    risk 0.47cvss 7.2epss 0.02

    A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.

  • CVE-2021-43102HigMar 28, 2022
    risk 0.47cvss 7.2epss 0.02

    A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.

  • CVE-2021-43101HigMar 28, 2022
    risk 0.47cvss 7.2epss 0.02

    A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.

  • CVE-2021-43100HigMar 28, 2022
    risk 0.47cvss 7.2epss 0.02

    A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code.

  • CVE-2021-43098HigMar 28, 2022
    risk 0.47cvss 7.2epss 0.01

    A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function.

  • CVE-2021-43097HigMar 28, 2022
    risk 0.47cvss 7.2epss 0.02

    A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user execute arbitrary code.

  • CVE-2022-27658HigMar 28, 2022
    risk 0.49cvss 7.5epss 0.01

    Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering for further exploits and attacks.

  • CVE-2022-0427HigMar 28, 2022
    risk 0.50cvss 7.7epss 0.01

    Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

  • CVE-2022-0770HigMar 28, 2022
    risk 0.57cvss 8.8epss 0.01

    The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write debug data such as user's cookies in a publicly accessible file if a specific parameter is used when requesting them. Combining those two issues, an attacker…

  • CVE-2022-0499HigMar 28, 2022
    risk 0.57cvss 8.8epss 0.01

    The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.

  • CVE-2021-25068HigMar 28, 2022
    risk 0.47cvss 7.2epss 0.01

    The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboard