VYPR

CVEs

101,990 total · page 1192 of 2,040

  • CVE-2022-25360HigFeb 24, 2022
    risk 0.57cvss 8.8epss 0.01

    WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to upload files to arbitrary locations. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

  • CVE-2022-25293HigFeb 24, 2022
    risk 0.57cvss 8.8epss 0.02

    A systemd stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware OS before 12.7.2_U2,…

  • CVE-2022-25292HigFeb 24, 2022
    risk 0.57cvss 8.8epss 0.02

    A wgagent stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware OS before 12.7.2_U2,…

  • CVE-2022-25291HigFeb 24, 2022
    risk 0.57cvss 8.8epss 0.02

    An integer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to trigger a heap-based buffer overflow and potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware…

  • CVE-2022-25104HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.01

    HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/file-manager/.

  • CVE-2022-25101HigFeb 24, 2022
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in the component /templates/install.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-25099HigFeb 24, 2022
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in the component /languages/index.php of WBCE CMS v1.5.2 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-24610HigFeb 24, 2022
    risk 0.56cvss 8.6epss 0.01

    Settings/network settings/wireless settings on the Alecto DVC-215IP camera version 63.1.1.173 and below shows the Wi-Fi passphrase hidden, but by editing/removing the style of the password field the password becomes visible which grants access to an internal network connected to…

  • CVE-2022-24407HigFeb 24, 2022
    risk 0.58cvss 8.8epss 0.04

    In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.

  • CVE-2022-23986HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.02

    SQL injection vulnerability in the phpUploader v1.2 and earlier allows a remote unauthenticated attacker to obtain the information in the database via unspecified vectors.

  • CVE-2022-23176HigKEVFeb 24, 2022
    risk 0.70cvss 8.8epss 0.13

    WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. This vulnerability impacts Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, and 12.2.x through…

  • CVE-2022-23043HigFeb 24, 2022
    risk 0.40cvss 7.2epss 0.01

    Zenario CMS 9.2 allows an authenticated admin user to bypass the file upload restriction by creating a new 'File/MIME Types' using the '.phar' extension. Then an attacker can upload a malicious file, intercept the request and change the extension to '.phar' in order to run…

  • CVE-2021-4030HigFeb 24, 2022
    risk 0.52cvss 8.0epss 0.00

    A cross-site request forgery vulnerability in the HTTP daemon of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary commands if they coerce or trick a local user to visit a compromised website with malicious scripts.

  • CVE-2021-4029HigFeb 24, 2022
    risk 0.57cvss 8.8epss 0.01

    A command injection vulnerability in the CGI program of the Zyxel ARMOR Z1/Z2 firmware could allow an attacker to execute arbitrary OS commands via a LAN interface.

  • CVE-2021-45746HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.02

    A Directory Traversal vulnerability exists in WeBankPartners wecube-platform 3.2.1 via the file variable in PluginPackageController.java.

  • CVE-2021-44967HigFeb 24, 2022
    risk 0.58cvss 8.8epss 0.13

    A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP…

  • CVE-2021-25636HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.01

    LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice…

  • CVE-2020-27467HigFeb 24, 2022
    risk 0.50cvss 7.5epss 0.16

    A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php.

  • CVE-2019-25058HigFeb 24, 2022
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.

  • CVE-2022-25331HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.03

    Uncaught exceptions that can be generated in Trend Micro ServerProtection 6.0/5.8 Information Server could allow a remote attacker to crash the process.

  • CVE-2022-24680HigFeb 24, 2022
    risk 0.51cvss 7.8epss 0.00

    A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents could allow a local attacker to create a…

  • CVE-2022-24679HigFeb 24, 2022
    risk 0.51cvss 7.8epss 0.00

    A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents could allow a local attacker to create an…

  • CVE-2022-24678HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.02

    An security agent resource exhaustion denial-of-service vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents could allow an attacker to flood a…

  • CVE-2022-24671HigFeb 24, 2022
    risk 0.51cvss 7.8epss 0.00

    A link following privilege escalation vulnerability in Trend Micro Antivirus for Max 11.0.2150 and below could allow a local attacker to modify a file during the update process and escalate their privileges. Please note: an attacker must first obtain the ability to execute…

  • CVE-2022-22336HigFeb 23, 2022
    risk 0.49cvss 7.5epss 0.02

    IBM Sterling External Authentication Server and IBM Sterling Secure Proxy 6.0.3.0, 6.0.2.0, and 3.4.3.2 could allow a remote user to consume resources causing a denial of service due to a resource leak. IBM X-Force ID: 219395.

  • CVE-2022-21705HigFeb 23, 2022
    risk 0.40cvss 7.2epss 0.09

    Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user input was not properly sanitized before rendering. An authenticated user with the permissions to create, modify and delete website pages can exploit this vulnerability to…

  • CVE-2022-20650HigFeb 23, 2022
    risk 0.58cvss 8.8epss 0.15

    A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the NX-API. An attacker…

  • CVE-2022-20624HigFeb 23, 2022
    risk 0.57cvss 8.6epss 0.12

    A vulnerability in the Cisco Fabric Services over IP (CFSoIP) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of incoming…

  • CVE-2022-20623HigFeb 23, 2022
    risk 0.57cvss 8.6epss 0.12

    A vulnerability in the rate limiter for Bidirectional Forwarding Detection (BFD) traffic of Cisco NX-OS Software for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to cause BFD traffic to be dropped on an affected device. This vulnerability is…

  • CVE-2022-0729HigFeb 23, 2022
    risk 0.00cvss 8.8epss 0.02

    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.

  • CVE-2022-0736HigFeb 23, 2022
    risk 0.42cvss 7.5epss 0.02

    Insecure Temporary File in GitHub repository mlflow/mlflow prior to 1.23.1.

  • CVE-2022-0654HigFeb 23, 2022
    risk 0.42cvss 7.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository fgribreau/node-request-retry prior to 7.0.0.

  • CVE-2022-23612HigFeb 22, 2022
    risk 0.00cvss 7.5epss 0.02

    OpenMRS is a patient-based medical record system focusing on giving providers a free customizable electronic medical record system. Affected versions are subject to arbitrary file exfiltration due to failure to sanitize request when satisfying GET requests for `/images` &…

  • CVE-2022-21656HigFeb 22, 2022
    risk 0.00cvss 7.4epss 0.01

    Envoy is an open source edge and service proxy, designed for cloud-native applications. The default_validator.cc implementation used to implement the default certificate validation routines has a "type confusion" bug when processing subjectAltNames. This processing allows, for…

  • CVE-2022-21655HigFeb 22, 2022
    risk 0.00cvss 7.5epss 0.01

    Envoy is an open source edge and service proxy, designed for cloud-native applications. The envoy common router will segfault if an internal redirect selects a route configured with direct response or redirect actions. This will result in a denial of service. As a workaround…

  • CVE-2022-21654HigFeb 22, 2022
    risk 0.00cvss 7.4epss 0.01

    Envoy is an open source edge and service proxy, designed for cloud-native applications. Envoy's tls allows re-use when some cert validation settings have changed from their default configuration. The only workaround for this issue is to ensure that default tls settings are used.…

  • CVE-2021-43826HigFeb 22, 2022
    risk 0.00cvss 7.5epss 0.01

    Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions of Envoy a crash occurs when configured for :ref:`upstream tunneling <envoy_v3_api_field_extensions.filters.network.tcp_proxy.v3.TcpProxy.tunneling_config>` and the…

  • CVE-2021-43824HigFeb 22, 2022
    risk 0.00cvss 7.5epss 0.01

    Envoy is an open source edge and service proxy, designed for cloud-native applications. In affected versions a crafted request crashes Envoy when a CONNECT request is sent to JWT filter configured with regex match. This provides a denial of service attack vector. The only…

  • CVE-2022-23635HigFeb 22, 2022
    risk 0.42cvss 7.5epss 0.02

    Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, `istiod`, is vulnerable to a request processing error, allowing a malicious attacker that sends a specially crafted message which results in the control plane…

  • CVE-2022-23654HigFeb 22, 2022
    risk 0.00cvss 8.1epss 0.01

    Wiki.js is a wiki app built on Node.js. In affected versions an authenticated user with write access on a restricted set of paths can update a page outside the allowed paths by specifying a different target page ID while keeping the path intact. The access control incorrectly…

  • CVE-2022-23652HigFeb 22, 2022
    risk 0.50cvss 8.8epss 0.01

    capsule-proxy is a reverse proxy for Capsule Operator which provides multi-tenancy in Kubernetes. In versions prior to 0.2.1 an attacker with a proper authentication mechanism may use a malicious `Connection` header to start a privilege escalation attack towards the Kubernetes…

  • CVE-2022-23608HigFeb 22, 2022
    risk 0.00cvss 8.1epss 0.04

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions up to and including 2.11.1 when in a dialog set (or forking) scenario, a hash key shared by…

  • CVE-2022-0713HigFeb 22, 2022
    risk 0.00cvss 7.1epss 0.01

    Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.

  • CVE-2021-46699HigFeb 22, 2022
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in Simcenter Femap (All versions < V2022.1.1). Affected application contains a stack based buffer overflow vulnerability while parsing specially crafted BDF files. This could allow an attacker to execute code in the context of the current…

  • CVE-2021-46162HigFeb 22, 2022
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in Simcenter Femap (All versions < V2022.1.1). Affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted NEU files. This could allow an attacker to execute code in the context…

  • CVE-2022-0676HigFeb 22, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.

  • CVE-2022-24295HigFeb 21, 2022
    risk 0.59cvss 8.8epss 0.17

    Okta Advanced Server Access Client for Windows prior to version 1.57.0 was found to be vulnerable to command injection via a specially crafted URL.

  • CVE-2022-22308HigFeb 21, 2022
    risk 0.51cvss 7.8epss 0.01

    IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file include commands and the web application could be tricked into including remote files with malicious code. IBM X-Force ID: 216891.

  • CVE-2021-44142HigFeb 21, 2022
    risk 0.56cvss 8.8epss 0.74

    The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow…

  • CVE-2021-45008HigFeb 21, 2022
    risk 0.57cvss 8.8epss 0.02

    Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users