VYPR

CVEs

101,990 total · page 1190 of 2,040

  • CVE-2022-0824HigMar 2, 2022
    risk 0.11cvss 8.8epss 0.97

    Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.

  • CVE-2022-22301HigMar 2, 2022
    risk 0.51cvss 7.8epss 0.00

    An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiAP-C console 5.4.0 through 5.4.3, 5.2.0 through 5.2.1 may allow an authenticated attacker to execute unauthorized commands by running CLI commands with specifically crafted…

  • CVE-2022-24255HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.01

    Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.

  • CVE-2022-24254HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.03

    An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.

  • CVE-2022-24253HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.01

    Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.

  • CVE-2022-24252HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.02

    An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.

  • CVE-2022-24251HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.01

    Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.

  • CVE-2021-41652HigMar 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.

  • CVE-2021-41282HigMar 1, 2022
    risk 0.67cvss 8.8epss 0.87

    diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by executing the netstat utility, and then its output is parsed via the sed utility. Although the…

  • CVE-2022-24718HigMar 1, 2022
    risk 0.49cvss 7.6epss 0.01

    ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.4, a path traversal issue can occur when providing untrusted input to the `svg` property as an argument to the `build(MessagePageOptions)` function. While there is no known…

  • CVE-2021-43077HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.01

    A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthorized code or commands via crafted…

  • CVE-2021-43075HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.02

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthorized code or commands via…

  • CVE-2021-32586HigMar 1, 2022
    risk 0.50cvss 7.7epss 0.01

    An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlying script interpreter via specifically crafted HTTP requests.

  • CVE-2021-36171HigMar 1, 2022
    risk 0.53cvss 8.1epss 0.01

    The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 may allow a remote unauthenticated attacker to predict parts of or the whole newly generated password within a given time frame.

  • CVE-2022-23387HigMar 1, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in taocms 3.0.2. This is a SQL blind injection that can obtain database data through the Comment Update field.

  • CVE-2021-44238HigMar 1, 2022
    risk 0.47cvss 7.2epss 0.02

    AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE) via /aya/module/admin/ust_tab_e.inc.php,

  • CVE-2022-23380HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.01

    There is a SQL injection vulnerability in the background of taocms 3.0.2 in parameter id:action=admin&id=2&ctrl=edit.

  • CVE-2022-23377HigMar 1, 2022
    risk 0.49cvss 7.5epss 0.02

    Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local files.

  • CVE-2022-0777HigMar 1, 2022
    risk 0.42cvss 7.5epss 0.01

    Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.

  • CVE-2021-43619HigMar 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psa_fwu_write caller from SPE or NSPE can overwrite stack memory locations.

  • CVE-2022-25018HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.03

    Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.

  • CVE-2022-22262HigMar 1, 2022
    risk 0.50cvss 7.7epss 0.00

    ROG Live Service’s function for deleting temp files created by installation has an improper link resolution before file access vulnerability. Since this function does not validate the path before deletion, an unauthenticated local attacker can create an unexpected symbolic…

  • CVE-2021-42951HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.02

    A Remote Code Execution (RCE) vulnerability exists in Algorithmia MSOL all versions before October 10 2021 of SaaS. Users can register for an account and are allocated a set number of credits to try the product. Once users authenticate, they can proceed to create a new,…

  • CVE-2022-25412HigFeb 28, 2022
    risk 0.53cvss 8.1epss 0.01

    Maxsite CMS v180 was discovered to contain multiple arbitrary file deletion vulnerabilities in /admin_page/all-files-update-ajax.php via the dir and deletefile parameters.

  • CVE-2022-23906HigFeb 28, 2022
    risk 0.47cvss 7.2epss 0.02

    CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability via the upload avatar function. This vulnerability is exploited via a crafted image file.

  • CVE-2021-41112HigFeb 28, 2022
    risk 0.53cvss 8.1epss 0.01

    Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3.4.5, authenticated users could craft a request to modify or delete System or Project level Calendars, without appropriate authorization. Modifying or removing…

  • CVE-2022-26181HigFeb 28, 2022
    risk 0.51cvss 7.8epss 0.01

    Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:108.

  • CVE-2022-25023HigFeb 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Audio File commit 004065d was discovered to contain a heap-buffer overflow in the function fouBytesToInt():AudioFile.h.

  • CVE-2020-22845HigFeb 28, 2022
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted FTP requests.

  • CVE-2020-22844HigFeb 28, 2022
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow in Mikrotik RouterOS 6.47 allows unauthenticated attackers to cause a denial of service (DOS) via crafted SMB requests.

  • CVE-2021-44342HigFeb 28, 2022
    risk 0.51cvss 7.8epss 0.01

    David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow via function ok_png_transform_scanline() in "/ok_png.c:494".

  • CVE-2021-44331HigFeb 28, 2022
    risk 0.51cvss 7.8epss 0.01

    ARM astcenc 3.2.0 is vulnerable to Buffer Overflow in function encode_ise().

  • CVE-2021-44340HigFeb 28, 2022
    risk 0.51cvss 7.8epss 0.01

    David Brackeen ok-file-formats dev version is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function ok_jpg_generate_huffman_table() in "/ok_jpg.c:403".

  • CVE-2021-44339HigFeb 28, 2022
    risk 0.51cvss 7.8epss 0.01

    David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function ok_png_transform_scanline() in "/ok_png.c:712".

  • CVE-2021-44334HigFeb 28, 2022
    risk 0.51cvss 7.8epss 0.01

    David Brackeen ok-file-formats 97f78ca is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_jpg_convert_YCbCr_to_RGB() in "/ok_jpg.c:513" .

  • CVE-2022-24685HigFeb 28, 2022
    risk 0.49cvss 7.5epss 0.02

    HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fixed in 1.0.18, 1.1.12, and 1.2.6.

  • CVE-2022-23911HigFeb 28, 2022
    risk 0.47cvss 7.2epss 0.01

    The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before using it in a SQL statement when retrieving a testimonial to edit, leading to a SQL Injection

  • CVE-2022-0411HigFeb 28, 2022
    risk 0.57cvss 8.8epss 0.02

    The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a SQL statement via a REST route of the plugin (accessible to any authenticated user), leading to a SQL injection

  • CVE-2022-0383HigFeb 28, 2022
    risk 0.47cvss 7.2epss 0.01

    The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter source, which could allow a high privilege users to perform SQL Injections attacks

  • CVE-2021-24864HigFeb 28, 2022
    risk 0.57cvss 8.8epss 0.01

    The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a SQL statement in the admin dashboard, leading to a SQL Injection issue

  • CVE-2021-24823HigFeb 28, 2022
    risk 0.53cvss 8.1epss 0.01

    The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files

  • CVE-2021-24803HigFeb 28, 2022
    risk 0.57cvss 8.8epss 0.01

    The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin email, as well as creating a new admin account. There is no CSRF protection in place, allowing an attacker to arbitrary change the admin email or create…

  • CVE-2021-24704HigFeb 28, 2022
    risk 0.57cvss 8.8epss 0.01

    In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query with an unsanitized parameter ($id). Only admin can access the page that invokes the function, but because of lack of CSRF…

  • CVE-2021-21708HigFeb 27, 2022
    risk 0.54cvss 8.2epss 0.03

    In PHP versions 7.4.x below 7.4.28, 8.0.x below 8.0.16, and 8.1.x below 8.1.3, when using filter functions with FILTER_VALIDATE_FLOAT filter and min/max limits, if the filter fails, there is a possibility to trigger use of allocated memory after free, which can result it…

  • CVE-2021-3967HigFeb 26, 2022
    risk 0.00cvss 8.8epss 0.01

    Improper Access Control in GitHub repository zulip/zulip prior to 4.10.

  • CVE-2022-26149HigFeb 26, 2022
    risk 0.51cvss 7.2epss 0.09

    MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.

  • CVE-2022-24986HigFeb 26, 2022
    risk 0.51cvss 7.8epss 0.00

    KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be created the first time could potentially intercept the file the following time, enabling that person to run unauthorized commands.

  • CVE-2022-23308HigFeb 26, 2022
    risk 0.00cvss 7.5epss 0.06

    valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

  • CVE-2022-25094HigFeb 26, 2022
    risk 0.59cvss 8.8epss 0.23

    Home Owners Collection Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the parameter "cover" in SystemSettings.php.

  • CVE-2022-21706HigFeb 26, 2022
    risk 0.00cvss 7.2epss 0.01

    Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organizations is vulnerable to an attack…