VYPR

CVEs

101,990 total · page 1191 of 2,040

  • CVE-2022-25264HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    In JetBrains TeamCity before 2021.2.3, environment variables of the "password" type could be logged in some cases.

  • CVE-2022-25062HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.03

    TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain an integer overflow via the function dm_checkString. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

  • CVE-2021-44132HigFeb 25, 2022
    risk 0.51cvss 7.8epss 0.03

    A command injection vulnerability in the function formImportOMCIShell of C-DATA ONU4FERW V2.1.13_X139 allows attackers to execute arbitrary commands via a crafted file.

  • CVE-2022-25170HigFeb 25, 2022
    risk 0.51cvss 7.8epss 0.01

    The affected product is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code

  • CVE-2022-23985HigFeb 25, 2022
    risk 0.51cvss 7.8epss 0.02

    The affected product is vulnerable to an out-of-bounds write while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.

  • CVE-2022-23921HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.00

    Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitation of this vulnerability is only possible if the attacker has login access to a machine actively running CIMPLICITY, the CIMPLICITY server is not already…

  • CVE-2022-21798HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which can be easily spoofed and used to log in to make operational changes to the system.

  • CVE-2022-21209HigFeb 25, 2022
    risk 0.51cvss 7.8epss 0.02

    The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.

  • CVE-2021-40043HigFeb 25, 2022
    risk 0.51cvss 7.8epss 0.00

    The laser command injection vulnerability exists on AIS-BW80H-00 versions earlier than AIS-BW80H-00 9.0.3.4(H100SP13C00). The devices cannot effectively defend against external malicious interference. Attackers need the device to be visually exploitable and successful triggering…

  • CVE-2021-37027HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a DoS vulnerability in smartphones. Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2021-26617HigFeb 25, 2022
    risk 0.53cvss 8.1epss 0.01

    This issues due to insufficient verification of the various input values from user’s input. The vulnerability allows remote attackers to execute malicious code in Firstmall via navercheckout_add function.

  • CVE-2021-22489HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a DoS vulnerability in smartphones. Successful exploitation of this vulnerability may affect service availability.

  • CVE-2021-22437HigFeb 25, 2022
    risk 0.46cvss 7.0epss 0.00

    There is a software integer overflow leading to a TOCTOU condition in smartphones. Successful exploitation of this vulnerability may cause random address access.

  • CVE-2021-22395HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a code injection vulnerability in smartphones. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-22319HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause integer overflows.

  • CVE-2022-24346HigFeb 25, 2022
    risk 0.51cvss 7.8epss 0.00

    In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possible.

  • CVE-2022-24345HigFeb 25, 2022
    risk 0.51cvss 7.8epss 0.00

    In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project was possible.

  • CVE-2022-24342HigFeb 25, 2022
    risk 0.57cvss 8.8epss 0.03

    In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.

  • CVE-2022-24341HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user.

  • CVE-2022-24335HigFeb 25, 2022
    risk 0.53cvss 8.1epss 0.01

    JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent registration via XML-RPC.

  • CVE-2022-24327HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.

  • CVE-2022-25374HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may capture sensitive data. Fixed in v202202-1.

  • CVE-2022-0247HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.00

    An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commit d97c05d2301799ed585620a9c5c739d36e7b5d3d or any of the…

  • CVE-2022-24947HigFeb 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later.

  • CVE-2022-24288HigFeb 25, 2022
    risk 0.63cvss 8.8epss 0.78

    In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.

  • CVE-2022-23835HigFeb 25, 2022
    risk 0.53cvss 8.1epss 0.01

    The Visual Voice Mail (VVM) application through 2022-02-24 for Android allows persistent access if an attacker temporarily controls an application that has the READ_SMS permission, and reads an IMAP credentialing message that is (by design) not displayed to the victim within the…

  • CVE-2021-39364HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.01

    Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow command spoofing (for camera control) after ARP cache poisoning has been achieved.

  • CVE-2021-29220HigFeb 24, 2022
    risk 0.47cvss 7.2epss 0.02

    Multiple buffer overflow security vulnerabilities have been identified in HPE iLO Amplifier Pack version(s): Prior to 2.12. These vulnerabilities could be exploited by a highly privileged user to remotely execute code that could lead to a loss of confidentiality, integrity, and…

  • CVE-2021-44664HigFeb 24, 2022
    risk 0.04cvss 8.8epss 0.13

    An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload filters. Attackers can…

  • CVE-2022-24709HigFeb 24, 2022
    risk 0.57cvss 8.8epss 0.01

    @awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed for user interface development. Multiple components in versions before 3.0.367 have been found to not properly neutralize user input and may allow for…

  • CVE-2022-25307HigFeb 24, 2022
    risk 0.47cvss 7.2epss 0.01

    The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers to inject arbitrary web scripts onto several pages…

  • CVE-2022-25306HigFeb 24, 2022
    risk 0.47cvss 7.2epss 0.01

    The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows attackers to inject arbitrary web scripts onto several pages…

  • CVE-2022-25305HigFeb 24, 2022
    risk 0.53cvss 7.2epss 0.79

    The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers to inject arbitrary web scripts onto several pages that…

  • CVE-2022-24232HigFeb 24, 2022
    risk 0.51cvss 7.8epss 0.02

    A local file inclusion in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-21824HigFeb 24, 2022
    risk 0.55cvss 8.2epss 0.22

    Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The…

  • CVE-2022-0546HigFeb 24, 2022
    risk 0.51cvss 7.8epss 0.01

    A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.

  • CVE-2022-0545HigFeb 24, 2022
    risk 0.44cvss 7.8epss 0.01

    An integer overflow in the processing of loaded 2D images leads to a write-what-where vulnerability and an out-of-bounds read vulnerability, allowing an attacker to leak sensitive information or achieve code execution in the context of the Blender process when a specially…

  • CVE-2021-4021HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled resource consumption and DoS.

  • CVE-2021-44531HigFeb 24, 2022
    risk 0.49cvss 7.4epss 0.08

    Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting URI SAN types, which PKIs are…

  • CVE-2021-3610HigFeb 24, 2022
    risk 0.00cvss 7.5epss 0.03

    A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.

  • CVE-2021-26252HigFeb 24, 2022
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service.

  • CVE-2020-14481HigFeb 24, 2022
    risk 0.51cvss 7.8epss 0.00

    The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. If the compromised user has an administrative account, an…

  • CVE-2020-14478HigFeb 24, 2022
    risk 0.46cvss 7.1epss 0.00

    A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local…

  • CVE-2020-10632HigFeb 24, 2022
    risk 0.57cvss 8.8epss 0.00

    Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of important configuration files, which could cause the system to fail or behave in an unpredictable manner.

  • CVE-2022-24707HigFeb 24, 2022
    risk 0.04cvss 7.4epss 0.07

    Anuko Time Tracker is an open source, web-based time tracking application written in PHP. UNION SQL injection and time-based blind injection vulnerabilities existed in Time Tracker Puncher plugin in versions of anuko timetracker prior to 1.20.0.5642. This was happening because…

  • CVE-2022-0732HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.03

    The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.

  • CVE-2022-25838HigFeb 24, 2022
    risk 0.00cvss 8.1epss 0.01

    Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the "OT" part of the "TOTP" concept.

  • CVE-2022-25640HigFeb 24, 2022
    risk 0.00cvss 7.5epss 0.01

    In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_verify message from the handshake, and never present a certificate.

  • CVE-2022-25636HigFeb 24, 2022
    risk 0.00cvss 7.8epss 0.03

    net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload.

  • CVE-2022-25401HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.02

    The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbitrary files.