VYPR

CVEs

101,990 total · page 1189 of 2,040

  • CVE-2022-21828HigMar 4, 2022
    risk 0.47cvss 7.2epss 0.04

    A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified attack vector in Incapptic Connect version 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and…

  • CVE-2022-23729HigMar 4, 2022
    risk 0.51cvss 7.8epss 0.00

    When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP-210010.

  • CVE-2021-46381HigMar 4, 2022
    risk 0.56cvss 7.5epss 0.58

    Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].

  • CVE-2021-3743HigMar 4, 2022
    risk 0.00cvss 7.1epss 0.01

    An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest…

  • CVE-2021-23214HigMar 4, 2022
    risk 0.00cvss 8.1epss 0.02

    When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and…

  • CVE-2021-46378HigMar 4, 2022
    risk 0.54cvss 7.5epss 0.32

    DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through an unauthenticated remote configuration download.

  • CVE-2020-18326HigMar 4, 2022
    risk 0.57cvss 8.8epss 0.02

    Cross Site Request Forgery (CSRF) vulnerability exists in Intelliants Subrion CMS v4.2.1 via the Members administrator function, which could let a remote unauthenticated malicious user send an authorised request to victim and successfully create an arbitrary administrator user.

  • CVE-2022-23328HigMar 4, 2022
    risk 0.49cvss 7.5epss 0.01

    A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas price from one account that all fully spend the full balance of the account to a victim Geth node, which can purge all of pending transactions in a victim node's…

  • CVE-2022-23327HigMar 4, 2022
    risk 0.49cvss 7.5epss 0.01

    A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a high gas price in one message, which can purge all of pending transactions in a victim node's memory pool, causing a denial of service (DoS).

  • CVE-2021-3640HigMar 3, 2022
    risk 0.00cvss 7.0epss 0.00

    A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable…

  • CVE-2021-26948HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.01

    Null pointer dereference in the htmldoc v1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service via a crafted html file.

  • CVE-2021-26259HigMar 3, 2022
    risk 0.00cvss 7.8epss 0.01

    A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in render_table_row(),in ps-pdf.cxx may lead to arbitrary code execution and denial of service.

  • CVE-2021-38578HigMar 3, 2022
    risk 0.48cvss 7.4epss 0.01

    Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.

  • CVE-2022-21716HigMar 3, 2022
    risk 0.42cvss 7.5epss 0.04

    Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available…

  • CVE-2022-24724HigMar 3, 2022
    risk 0.58cvss 8.8epss 0.04

    cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 and 0.28.3.gfm.21, an integer overflow in cmark-gfm's table row parsing `table.c:row_from_string` may lead to heap memory corruption when parsing tables who's…

  • CVE-2022-0492HigKEVMar 3, 2022
    risk 0.59cvss 7.8epss 0.06

    A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation…

  • CVE-2021-3609HigMar 3, 2022
    risk 0.00cvss 7.0epss 0.00

    .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege…

  • CVE-2022-26129HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.01

    Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functions, parse_hello_subtlv, parse_ihu_subtlv, and parse_update_subtlv in babeld/message.c.

  • CVE-2022-26128HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong check on the input packet length in the babel_packet_examin function in babeld/message.c.

  • CVE-2022-26127HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in the babel_packet_examin function in babeld/message.c.

  • CVE-2022-26126HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.01

    Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.

  • CVE-2022-26125HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.01

    Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd/isis_tlvs.c.

  • CVE-2022-25031HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.00

    Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate privileges to the system level.

  • CVE-2022-22706HigKEVMar 3, 2022
    risk 0.63cvss 7.8epss 0.01

    Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0.

  • CVE-2022-23648HigMar 3, 2022
    risk 0.44cvss 7.5epss 0.27

    containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration…

  • CVE-2021-40636HigMar 3, 2022
    risk 0.49cvss 7.5epss 0.01

    OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database.

  • CVE-2021-40635HigMar 3, 2022
    risk 0.49cvss 7.5epss 0.01

    OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to extract information from the database.

  • CVE-2021-42950HigMar 3, 2022
    risk 0.57cvss 8.8epss 0.02

    Remote Code Execution (RCE) vulnerability exists in Zepl Notebooks all previous versions before October 25 2021. Users can register for an account and are allocated a set number of credits to try the product. Once users authenticate, they can proceed to create a new organization…

  • CVE-2022-25471HigMar 3, 2022
    risk 0.53cvss 8.1epss 0.01

    An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas via a crafted POST request to /modules/zend_modules/public/Installer/register.

  • CVE-2022-22909HigMar 3, 2022
    risk 0.64cvss 8.8epss 0.45

    HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module.

  • CVE-2021-44343HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.01

    David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function ok_png_read_data() in "/ok_png.c".

  • CVE-2021-44335HigMar 3, 2022
    risk 0.51cvss 7.8epss 0.01

    David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_png_transform_scanline() in "/ok_png.c:533".

  • CVE-2022-25393HigMar 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Simple Bakery Shop Management v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

  • CVE-2022-25115HigMar 2, 2022
    risk 0.51cvss 7.8epss 0.02

    A remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners Collection Management System v1.0 allows attackers to execute arbitrary code via a crafted PNG file.

  • CVE-2022-24722HigMar 2, 2022
    risk 0.46cvss 8.1epss 0.01

    VIewComponent is a framework for building view components in Ruby on Rails. Versions prior to 2.31.2 and 2.49.1 contain a cross-site scripting vulnerability that has the potential to impact anyone using translations with the view_component gem. Data received via user input and…

  • CVE-2021-4076HigMar 2, 2022
    risk 0.00cvss 7.5epss 0.02

    A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.

  • CVE-2021-3738HigMar 2, 2022
    risk 0.57cvss 8.8epss 0.02

    In DCE/RPC it is possible to share the handles (cookies for resource state) between multiple connections via a mechanism called 'association groups'. These handles can reference connections to our sam.ldb database. However while the database was correctly shared, the user…

  • CVE-2021-3715HigMar 2, 2022
    risk 0.00cvss 7.8epss 0.00

    A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their…

  • CVE-2021-38266HigMar 2, 2022
    risk 0.42cvss 7.5epss 0.02

    The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix pack 17 and 7.2 before fix pack 5 does not correctly import users from LDAP, which allows remote attackers to prevent a legitimate user from authenticating by…

  • CVE-2021-23206HigMar 2, 2022
    risk 0.00cvss 7.8epss 0.01

    A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to execute arbitrary code and denial of service.

  • CVE-2021-23192HigMar 2, 2022
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, and chose to fragment it, an attacker could replace later fragments with their own data, bypassing the signature requirements.

  • CVE-2021-23191HigMar 2, 2022
    risk 0.00cvss 7.8epss 0.01

    A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() in image.cxx may result in denial of service.

  • CVE-2021-23180HigMar 2, 2022
    risk 0.00cvss 7.8epss 0.01

    A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to execute arbitrary code and denial of service.

  • CVE-2022-0711HigMar 2, 2022
    risk 0.01cvss 7.5epss 0.17

    A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat…

  • CVE-2021-41002HigMar 2, 2022
    risk 0.53cvss 8.1epss 0.01

    Multiple authenticated remote path traversal vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series,…

  • CVE-2021-41001HigMar 2, 2022
    risk 0.57cvss 8.8epss 0.03

    An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series,…

  • CVE-2021-41000HigMar 2, 2022
    risk 0.57cvss 8.8epss 0.03

    Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series,…

  • CVE-2022-0819HigMar 2, 2022
    risk 0.54cvss 8.8epss 0.41

    Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.

  • CVE-2022-25634HigMar 2, 2022
    risk 0.49cvss 7.5epss 0.02

    Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.

  • CVE-2022-0829HigMar 2, 2022
    risk 0.00cvss 8.1epss 0.01

    Improper Authorization in GitHub repository webmin/webmin prior to 1.990.