VYPR

CVEs

102,253 total · page 1185 of 2,046

  • CVE-2022-27607HigMar 21, 2022
    risk 0.53cvss 8.1epss 0.01

    Bento4 1.6.0-639 has a heap-based buffer over-read in the AP4_HvccAtom class, a different issue than CVE-2018-14531.

  • CVE-2022-27333HigMar 21, 2022
    risk 0.49cvss 7.5epss 0.01

    idcCMS v1.10 was discovered to contain an issue which allows attackers to arbitrarily delete the install.lock file, resulting in a reset of the CMS settings and data.

  • CVE-2022-26183HigMar 21, 2022
    risk 0.50cvss 8.8epss 0.02

    PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

  • CVE-2021-40662HigMar 21, 2022
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL.

  • CVE-2022-23352HigMar 21, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).

  • CVE-2022-23349HigMar 21, 2022
    risk 0.57cvss 8.8epss 0.01

    BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF).

  • CVE-2022-23347HigMar 21, 2022
    risk 0.50cvss 7.5epss 0.12

    BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.

  • CVE-2022-23346HigMar 21, 2022
    risk 0.57cvss 8.8epss 0.01

    BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.

  • CVE-2022-23345HigMar 21, 2022
    risk 0.49cvss 7.5epss 0.02

    BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.

  • CVE-2022-24775HigMar 21, 2022
    risk 0.00cvss 7.5epss 0.02

    guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known…

  • CVE-2022-0687HigMar 21, 2022
    risk 0.57cvss 8.8epss 0.01

    The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.

  • CVE-2022-0229HigMar 21, 2022
    risk 0.53cvss 8.1epss 0.01

    The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper authorisation and CSRF checks when handling the reconfigureMethod, and does not validate the parameters passed to it properly. As a result, unauthenticated users could delete arbitrary options…

  • CVE-2021-24905HigMar 21, 2022
    risk 0.52cvss 8.0epss 0.01

    The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server.…

  • CVE-2022-25766HigMar 21, 2022
    risk 0.03cvss 8.8epss 0.34

    The package ungit before 1.5.20 are vulnerable to Remote Code Execution (RCE) via argument injection. The issue occurs when calling the /api/fetch endpoint. User controlled values (remote and ref) are passed to the git fetch command. By injecting some git options it was possible…

  • CVE-2022-24237HigMar 21, 2022
    risk 0.59cvss 8.8epss 0.25

    The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands.

  • CVE-2022-24235HigMar 21, 2022
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) in the management portal of Snapt Aria v12.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors.

  • CVE-2022-22394HigMar 21, 2022
    risk 0.57cvss 8.8epss 0.02

    The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access controls. By signing in, an attacker could exploit this vulnerability to bypass security and gain unauthorized administrator or node…

  • CVE-2020-24772HigMar 21, 2022
    risk 0.57cvss 8.8epss 0.01

    In Dreamacro Clash for Windows v0.11.4, an attacker could embed a malicious iframe in a website with a crafted URL that would launch the Clash Windows client and force it to open a remote SMB share. Windows will perform NTLM authentication when opening the SMB share and that…

  • CVE-2022-0415HigMar 21, 2022
    risk 0.55cvss 8.8epss 0.65

    Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.

  • CVE-2022-25481HigMar 21, 2022
    risk 0.49cvss 7.5epss 0.05

    ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the…

  • CVE-2021-42194HigMar 20, 2022
    risk 0.47cvss 7.2epss 0.01

    The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ String function, which itself does not prohibit external entities, triggering a XML external entity (XXE) injection vulnerability.

  • CVE-2020-26008HigMar 20, 2022
    risk 0.51cvss 7.8epss 0.01

    The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2020-26007HigMar 20, 2022
    risk 0.51cvss 7.8epss 0.01

    An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2022-25462HigMar 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Yafu v2.0 contains a segmentation fault via the component /factor/avx-ecm/vecarith52.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

  • CVE-2021-44345HigMar 20, 2022
    risk 0.49cvss 7.5epss 0.01

    Beijing Wisdom Vision Technology Industry Co., Ltd One Card Integrated Management System 3.0 is vulnerable to SQL Injection.

  • CVE-2022-24125HigMar 20, 2022
    risk 0.57cvss 8.8epss 0.03

    The matchmaking servers of Bandai Namco FromSoftware Dark Souls III through 2022-03-19 allow remote attackers to send arbitrary push requests to clients via a RequestSendMessageToPlayers request. For example, ability to send a push message to hundreds of thousands of machines is…

  • CVE-2022-0991HigMar 19, 2022
    risk 0.39cvss 7.1epss 0.01

    Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.1.9.

  • CVE-2022-27226HigMar 19, 2022
    risk 0.63cvss 8.8epss 0.31

    A CSRF issue in /api/crontab on iRZ Mobile Routers through 2022-03-16 allows a threat actor to create a crontab entry in the router administration panel. The cronjob will consequently execute the entry on the threat actor's defined interval, leading to remote code execution,…

  • CVE-2022-26267HigMar 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.

  • CVE-2022-26266HigMar 18, 2022
    risk 0.57cvss 8.8epss 0.01

    Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php.

  • CVE-2022-25581HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.01

    Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload. This vulnerability allows attackers to execute code injection via a crafted .txt file.

  • CVE-2022-25389HigMar 18, 2022
    risk 0.49cvss 7.5epss 0.01

    DCN Firewall DCME-520 was discovered to contain an arbitrary file download vulnerability via the path parameter in the file /audit/log/log_management.php.

  • CVE-2022-27245HigMar 18, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in MISP before 2.4.156. app/Model/Server.php does not restrict generateServerSettings to the CLI. This could lead to SSRF.

  • CVE-2022-27243HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in MISP before 2.4.156. app/View/Users/terms.ctp allows Local File Inclusion via the custom terms file setting.

  • CVE-2022-25602HigMar 18, 2022
    risk 0.54cvss 8.3epss 0.01

    Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings change discovered in Responsive Menu WordPress plugin (versions <= 4.1.7).

  • CVE-2022-24092HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.04

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2022-24091HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.04

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2022-22669HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.00

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.3. An application may be able to execute arbitrary code with kernel privileges.

  • CVE-2022-22667HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.01

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 15.4 and iPadOS 15.4. An application may be able to execute arbitrary code with kernel privileges.

  • CVE-2022-22666HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.01

    A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, watchOS 8.5. Processing a maliciously crafted image may lead to heap corruption.

  • CVE-2022-22665HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.01

    A logic issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.3. A malicious application may be able to gain root privileges.

  • CVE-2022-22664HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.

  • CVE-2022-22661HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.01

    A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. An application may be able to execute arbitrary code with kernel privileges.

  • CVE-2022-22657HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.01

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in Logic Pro 10.7.3, GarageBand 10.4.6, macOS Monterey 12.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.

  • CVE-2022-22653HigMar 18, 2022
    risk 0.49cvss 7.5epss 0.01

    A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.4 and iPadOS 15.4. A malicious website may be able to access information about the user and their devices.

  • CVE-2022-22651HigMar 18, 2022
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Monterey 12.3. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

  • CVE-2022-22643HigMar 18, 2022
    risk 0.49cvss 7.5epss 0.01

    This issue was addressed with improved checks. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. A user may send audio and video in a FaceTime call without knowing that they have done so.

  • CVE-2022-22640HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.01

    A memory corruption issue was addressed with improved validation. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3, watchOS 8.5. An application may be able to execute arbitrary code with kernel privileges.

  • CVE-2022-22639HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.08

    A logic issue was addressed with improved state management. This issue is fixed in iOS 15.4 and iPadOS 15.4, macOS Monterey 12.3. An application may be able to gain elevated privileges.

  • CVE-2022-22636HigMar 18, 2022
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4. An application may be able to execute arbitrary code with kernel privileges.