VYPR

CVEs

101,988 total · page 1196 of 2,040

  • CVE-2021-46247HigFeb 17, 2022
    risk 0.49cvss 7.5epss 0.01

    The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from ASUS CMAX6000 v1.02.00.

  • CVE-2022-24683HigFeb 17, 2022
    risk 0.42cvss 7.5epss 0.02

    HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.

  • CVE-2021-39034HigFeb 17, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM MQ 9.1 LTS is vulnerable to a denial of service attack caused by an issue within the channel process. IBM X-Force ID: 213964.

  • CVE-2022-23632HigFeb 17, 2022
    risk 0.00cvss 7.4epss 0.02

    Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer security (TLS) configuration when the host header is a fully qualified domain name (FQDN). For a request, the TLS configuration choice can be different than the…

  • CVE-2022-20653HigFeb 17, 2022
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected…

  • CVE-2022-23318HigFeb 17, 2022
    risk 0.46cvss 7.1epss 0.01

    A heap-buffer-overflow in pcf2bdf, versions >= 1.05 allows an attacker to trigger unsafe memory access via a specially crafted PCF font file. This out-of-bound read may lead to an application crash, information disclosure via program memory or other context-dependent impact.

  • CVE-2022-0629HigFeb 17, 2022
    risk 0.00cvss 7.8epss 0.02

    Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2021-46368HigFeb 17, 2022
    risk 0.51cvss 7.8epss 0.00

    TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges.

  • CVE-2022-25271HigFeb 16, 2022
    risk 0.49cvss 7.5epss 0.01

    Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker…

  • CVE-2022-24985HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.02

    Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to bypass authentication and access the administrative section of other forms hosted on the same web server. This is relevant only when an organization hosts more than one of these forms…

  • CVE-2022-24983HigFeb 16, 2022
    risk 0.49cvss 7.5epss 0.03

    Forms generated by JQueryForm.com before 2022-02-05 allow remote attackers to obtain the URI to any uploaded file by capturing the POST response. When chained with CVE-2022-24984, this could lead to unauthenticated remote code execution on the underlying web server. This occurs…

  • CVE-2022-25265HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.01

    In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable regions of a file.

  • CVE-2022-25255HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.00

    In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.

  • CVE-2022-23644HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.01

    BookWyrm is a decentralized social network for tracking reading habits and reviewing books. The functionality to load a cover via url is vulnerable to a server-side request forgery attack. Any BookWyrm instance running a version prior to v0.3.0 is susceptible to attack from a…

  • CVE-2021-3760HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in the Linux kernel. A use-after-free vulnerability in the NFC stack can lead to a threat to confidentiality, integrity, and system availability.

  • CVE-2021-3752HigFeb 16, 2022
    risk 0.46cvss 7.1epss 0.02

    A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this…

  • CVE-2021-3578HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly…

  • CVE-2021-3560HigKEVFeb 16, 2022
    risk 0.60cvss 7.8epss 0.22

    It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest…

  • CVE-2022-23804HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.02

    A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can…

  • CVE-2022-23803HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.02

    A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadXYCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can…

  • CVE-2022-23203HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.05

    Adobe Photoshop versions 22.5.4 (and earlier) and 23.1 (and earlier) are affected by a buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user…

  • CVE-2022-23202HigFeb 16, 2022
    risk 0.46cvss 7.0epss 0.02

    Adobe Creative Cloud Desktop version 2.7.0.13 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-23200HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.03

    Adobe After Effects versions 22.1.1 (and earlier) and 18.4.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-23188HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.04

    Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a buffer overflow vulnerability due to insecure handling of a crafted malicious file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation…

  • CVE-2022-23186HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.02

    Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim…

  • CVE-2022-22945HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.00

    VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary commands on the operating system as root.

  • CVE-2021-4134HigFeb 16, 2022
    risk 0.47cvss 7.2epss 0.01

    The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.php file which allows attackers with administrative level permissions to inject arbitrary SQL…

  • CVE-2021-4106HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in Snow Inventory Java Scanner allows an attacker to run malicious code at a higher level of privileges. This issue affects: SNOW Snow Inventory Java Scanner 1.0

  • CVE-2021-3551HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager.…

  • CVE-2021-39301HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.00

    Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

  • CVE-2021-39300HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.00

    Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

  • CVE-2021-39299HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.00

    Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

  • CVE-2021-39298HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.00

    A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.

  • CVE-2021-39297HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.00

    Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.

  • CVE-2021-23682HigFeb 16, 2022
    risk 0.00cvss 7.3epss 0.02

    This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the result object is not properly sanitized leading to a…

  • CVE-2021-22050HigFeb 16, 2022
    risk 0.49cvss 7.5epss 0.02

    ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to ESXi may exploit this issue to create a denial-of-service condition by overwhelming rhttpproxy service with multiple requests.

  • CVE-2021-22043HigFeb 16, 2022
    risk 0.49cvss 7.5epss 0.01

    VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handled. A malicious actor with access to settingsd, may exploit this issue to escalate their privileges by writing arbitrary files.

  • CVE-2021-22042HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.00

    VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A malicious actor with privileges within the VMX process only, may be able to access settingsd service running as a high privileged user.

  • CVE-2021-21958HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom Office 2020 11.0.0.2353. A specially-crafted malformed file can lead to memory corruption and potential arbitrary code execution. An attacker can provide a malicious file to…

  • CVE-2020-6922HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

  • CVE-2020-6921HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

  • CVE-2020-6919HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

  • CVE-2020-6918HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

  • CVE-2020-6917HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.01

    Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.

  • CVE-2021-26726HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.01

    A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: Valmet DNA versions from Collection 2012 until Collection 2021.

  • CVE-2021-45391HigFeb 16, 2022
    risk 0.49cvss 7.5epss 0.02

    A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in the goform/setIPv6Status binary file /usr/sbin/httpd via the conType parameter, which causes a Denial of Service.

  • CVE-2022-25242HigFeb 16, 2022
    risk 0.57cvss 8.8epss 0.00

    In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).

  • CVE-2022-25241HigFeb 16, 2022
    risk 0.60cvss 8.8epss 0.03

    In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).

  • CVE-2021-35380HigFeb 15, 2022
    risk 0.55cvss 7.5epss 0.39

    A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain access to the files on the remote system by gaining access to the relative path of the file they want to download…

  • CVE-2022-23639HigFeb 15, 2022
    risk 0.00cvss 8.1epss 0.01

    crossbeam-utils provides atomics, synchronization primitives, scoped threads, and other utilities for concurrent programming in Rust. crossbeam-utils prior to version 0.8.7 incorrectly assumed that the alignment of `{i,u}64` was always the same as `Atomic{I,U}64`. However, the…