VYPR

CVEs

102,253 total · page 1184 of 2,046

  • CVE-2021-43666HigMar 24, 2022
    risk 0.49cvss 7.5epss 0.02

    A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.

  • CVE-2022-25568HigMar 24, 2022
    risk 0.42cvss 7.5epss 0.07

    MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.

  • CVE-2022-0153HigMar 24, 2022
    risk 0.42cvss 7.5epss 0.01

    SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1.

  • CVE-2022-0551HigMar 24, 2022
    risk 0.47cvss 7.2epss 0.01

    Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi…

  • CVE-2022-0550HigMar 24, 2022
    risk 0.47cvss 7.2epss 0.01

    Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects:…

  • CVE-2022-1061HigMar 24, 2022
    risk 0.00cvss 7.5epss 0.01

    Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8.

  • CVE-2022-0315HigMar 24, 2022
    risk 0.42cvss 7.5epss 0.01

    Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0.

  • CVE-2022-25268HigMar 23, 2022
    risk 0.57cvss 8.8epss 0.00

    Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems.

  • CVE-2022-25267HigMar 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Passwork On-Premise Edition before 4.6.13 allows migration/uploadExportFile Directory Traversal (to upload files).

  • CVE-2022-27192HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.01

    The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file download. An unauthenticated attacker can impersonate an administrator by reading administrative files.

  • CVE-2022-22819HigMar 23, 2022
    risk 0.51cvss 7.8epss 0.01

    NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates before the signature is verified. This can allow an attacker to achieve non-persistent code…

  • CVE-2021-44226HigMar 23, 2022
    risk 0.48cvss 7.3epss 0.01

    Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have placed Trojan horse…

  • CVE-2022-24757HigMar 23, 2022
    risk 0.42cvss 7.5epss 0.01

    The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications. Prior to version 1.15.4, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie and other…

  • CVE-2022-24730HigMar 23, 2022
    risk 0.50cvss 7.7epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal bug, compounded by an improper access control bug, allowing a malicious user with…

  • CVE-2021-28278HigMar 23, 2022
    risk 0.51cvss 7.8epss 0.01

    A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c.

  • CVE-2021-28277HigMar 23, 2022
    risk 0.51cvss 7.8epss 0.01

    A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUnknownSections function in jpgfile.c.

  • CVE-2021-28276HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.01

    A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir function in makernote.c.

  • CVE-2022-24291HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.04

    Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution.

  • CVE-2022-1030HigMar 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host where the user has…

  • CVE-2022-0981HigMar 23, 2022
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another in RestEasy Reactive. This flaw allows a low-privileged user to perform operations on the database with a different set of privileges than intended.

  • CVE-2022-0889HigMar 23, 2022
    risk 0.47cvss 7.2epss 0.01

    The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add…

  • CVE-2022-0834HigMar 23, 2022
    risk 0.47cvss 7.2epss 0.01

    The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the lastName parameter found in the ~/src/Application/Controller/User/Customer/AddCustomerController.php file which allows attackers to inject arbitrary web scripts…

  • CVE-2021-4197HigMar 23, 2022
    risk 0.51cvss 7.8epss 0.01

    An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is actually both for…

  • CVE-2021-4156HigMar 23, 2022
    risk 0.00cvss 7.1epss 0.02

    An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds…

  • CVE-2021-3748HigMar 23, 2022
    risk 0.00cvss 7.5epss 0.01

    A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to…

  • CVE-2021-3618HigMar 23, 2022
    risk 0.48cvss 7.4epss 0.02

    ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can…

  • CVE-2021-3589HigMar 23, 2022
    risk 0.45cvss 8.0epss 0.01

    An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system…

  • CVE-2021-27475HigMar 23, 2022
    risk 0.56cvss 8.6epss 0.03

    Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in Connected Components Workbench, may result in…

  • CVE-2021-27471HigMar 23, 2022
    risk 0.50cvss 7.7epss 0.03

    The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Components Workbench v12.00.00 and prior, can traverse the file…

  • CVE-2021-27430HigMar 23, 2022
    risk 0.55cvss 8.4epss 0.00

    GE UR bootloader binary Version 7.00, 7.01 and 7.02 included unused hardcoded credentials. Additionally, a user with physical access to the UR IED can interrupt the boot sequence by rebooting the UR.

  • CVE-2021-27422HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.01

    GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sensitive information exposure without authentication.

  • CVE-2022-26243HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow in the setSmartPowerManagement function.

  • CVE-2021-38772HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.

  • CVE-2021-46064HigMar 23, 2022
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). The vulnerability triggers when the user opens malicious .tiff image.

  • CVE-2021-44139HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.06

    Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).

  • CVE-2021-43738HigMar 23, 2022
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrator account.

  • CVE-2021-44759HigMar 23, 2022
    risk 0.53cvss 8.1epss 0.02

    Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0.

  • CVE-2021-44040HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.02

    Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send invalid requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.3 and 9.0.0 to 9.1.1.

  • CVE-2022-0635HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.01

    Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check.

  • CVE-2021-45757HigMar 23, 2022
    risk 0.49cvss 7.5epss 0.01

    ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (DoS).

  • CVE-2022-1033HigMar 23, 2022
    risk 0.00cvss 7.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.

  • CVE-2022-27666HigMar 23, 2022
    risk 0.00cvss 7.8epss 0.06

    A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.

  • CVE-2022-1031HigMar 22, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in op_is_set_bp in GitHub repository radareorg/radare2 prior to 5.6.6.

  • CVE-2022-24774HigMar 22, 2022
    risk 0.00cvss 7.1epss 0.01

    CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneDX BOM Repository Server before version 2.0.1 has an improper input validation vulnerability leading to path traversal. A malicious user may potentially exploit…

  • CVE-2022-24764HigMar 22, 2022
    risk 0.00cvss 7.5epss 0.02

    PJSIP is a free and open source multimedia communication library written in C. Versions 2.12 and prior contain a stack buffer overflow vulnerability that affects PJSUA2 users or users that call the API `pjmedia_sdp_print(), pjmedia_sdp_media_print()`. Applications that do not…

  • CVE-2022-1036HigMar 22, 2022
    risk 0.42cvss 7.5epss 0.01

    Able to create an account with long password leads to memory corruption / Integer Overflow in GitHub repository microweber/microweber prior to 1.2.12.

  • CVE-2022-0667HigMar 22, 2022
    risk 0.49cvss 7.5epss 0.01

    When the vulnerability is triggered the BIND process will exit. BIND 9.18.0

  • CVE-2021-45810HigMar 22, 2022
    risk 0.49cvss 7.5epss 0.01

    GlobalProtect-openconnect versions prior to 2.0.0 (exclusive) are affected by incorrect access control in GPService through DBUS, GUI. The way GlobalProtect-Openconnect is set up enables arbitrary users to start a VPN connection to arbitrary servers. By hosting an openconnect…

  • CVE-2022-1034HigMar 22, 2022
    risk 0.40cvss 7.2epss 0.01

    There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4.

  • CVE-2022-0386HigMar 22, 2022
    risk 0.57cvss 8.8epss 0.01

    A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.