VYPR

CVEs

101,988 total · page 1197 of 2,040

  • CVE-2021-42714HigFeb 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Splashtop Remote Client (Business Edition) through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2021-42713HigFeb 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Splashtop Remote Client (Personal Edition) through 3.4.6.1 creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2021-43050HigFeb 15, 2022
    risk 0.55cvss 8.4epss 0.00

    The Auth Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Container Edition contains an easily exploitable vulnerability that allows an unauthenticated attacker with local access to obtain administrative usernames and passwords for the affected system. Affected…

  • CVE-2022-25212HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers to connect to an attacker-specified web server using attacker-specified credentials.

  • CVE-2022-25211HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    A missing permission check in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified web server using attacker-specified credentials.

  • CVE-2022-25209HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    Jenkins Chef Sinatra Plugin 1.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-25208HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.

  • CVE-2022-25207HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.

  • CVE-2022-25206HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified database via JDBC using attacker-specified credentials.

  • CVE-2022-25205HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to connect to an attacker-specified database via JDBC using attacker-specified credentials and to determine if a class is available in the Jenkins instance.

  • CVE-2022-25200HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2022-25199HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    A missing permission check in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials.

  • CVE-2022-25198HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins SCP publisher Plugin 1.8 and earlier allows attackers to connect to an attacker-specified SSH server using attacker-specified credentials.

  • CVE-2022-25194HigFeb 15, 2022
    risk 0.50cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins autonomiq Plugin 1.15 and earlier allows attackers to connect to an attacker-specified URL server using attacker-specified credentials.

  • CVE-2022-25192HigFeb 15, 2022
    risk 0.50cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Snow Commander Plugin 1.10 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2022-25183HigFeb 15, 2022
    risk 0.50cvss 8.8epss 0.02

    Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the names of Pipeline libraries to create cache directories without any sanitization, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins…

  • CVE-2022-25182HigFeb 15, 2022
    risk 0.50cvss 8.8epss 0.02

    A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller JVM using specially crafted library names if a global Pipeline…

  • CVE-2022-25181HigFeb 15, 2022
    risk 0.50cvss 8.8epss 0.02

    A sandbox bypass vulnerability in Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier allows attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM through crafted SCM contents, if a global…

  • CVE-2022-25175HigFeb 15, 2022
    risk 0.50cvss 8.8epss 0.01

    Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.

  • CVE-2022-25174HigFeb 15, 2022
    risk 0.50cvss 8.8epss 0.01

    Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libraries, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM…

  • CVE-2022-25173HigFeb 15, 2022
    risk 0.50cvss 8.8epss 0.01

    Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the…

  • CVE-2022-24226HigFeb 15, 2022
    risk 0.49cvss 7.5epss 0.02

    Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php.

  • CVE-2022-23604HigFeb 15, 2022
    risk 0.00cvss 8.8epss 0.01

    x26-Cogs is a repository of cogs made by Twentysix for the Red Discord bot. Among these cogs is the Defender cog, a tool for Discord server moderation. A vulnerability in the Defender cog prior to version 1.10.0 allows users with admin privileges to issue commands as other users…

  • CVE-2022-21698HigFeb 15, 2022
    risk 0.00cvss 7.5epss 0.06

    client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through…

  • CVE-2021-43734HigFeb 15, 2022
    risk 0.50cvss 7.5epss 0.11

    kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file leak on related host.

  • CVE-2021-42712HigFeb 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Splashtop Streamer through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2021-41552HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection.

  • CVE-2022-23384HigFeb 15, 2022
    risk 0.57cvss 8.8epss 0.01

    YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add

  • CVE-2022-23317HigFeb 15, 2022
    risk 0.49cvss 7.5epss 0.01

    CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by specifying the URL.

  • CVE-2022-0588HigFeb 15, 2022
    risk 0.39cvss 7.1epss 0.01

    Missing Authorization in Packagist librenms/librenms prior to 22.2.0.

  • CVE-2021-43940HigFeb 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated privileges on the local system via a DLL Hijacking vulnerability in the Confluence installer. This vulnerability only affects installations of Confluence…

  • CVE-2022-0580HigFeb 14, 2022
    risk 0.39cvss 7.1epss 0.01

    Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0.

  • CVE-2022-23410HigFeb 14, 2022
    risk 0.51cvss 7.8epss 0.00

    AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be…

  • CVE-2021-46462HigFeb 14, 2022
    risk 0.00cvss 7.5epss 0.02

    njs through 0.7.1, used in NGINX, was discovered to contain a segmentation violation via njs_object_set_prototype in /src/njs_object.c.

  • CVE-2019-25057HigFeb 14, 2022
    risk 0.49cvss 7.5epss 0.01

    In Corda before 4.1, the meaning of serialized data can be modified via an attacker-controlled CustomSerializer.

  • CVE-2021-45348HigFeb 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An Arbitrary File Deletion vulnerability exists in SourceCodester Attendance Management System v1.0 via the csv parameter in admin/pageUploadCSV.php, which can cause a Denial of Service (crash).

  • CVE-2019-16864HigFeb 14, 2022
    risk 0.58cvss 8.8epss 0.08

    CompleteFTPService.exe in the server in EnterpriseDT CompleteFTP before 12.1.4 allows Remote Code Execution by leveraging a Windows user account that has SSH access. The exec command is always run as SYSTEM.

  • CVE-2022-25150HigFeb 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to escalate privileges.

  • CVE-2021-45347HigFeb 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by changing the user name in the cookie to use any password.

  • CVE-2022-22854HigFeb 14, 2022
    risk 0.57cvss 8.8epss 0.01

    An access control issue in hprms/admin/?page=user/list of Hospital Patient Record Management System v1.0 allows attackers to escalate privileges via accessing and editing the user list.

  • CVE-2021-45392HigFeb 14, 2022
    risk 0.50cvss 7.5epss 0.12

    A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in page /goform/setIPv6Status via the prefixDelegate parameter, which causes a Denial of Service.

  • CVE-2021-46371HigFeb 14, 2022
    risk 0.49cvss 7.5epss 0.04

    antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information.

  • CVE-2021-45421HigFeb 14, 2022
    risk 0.49cvss 7.5epss 0.01

    Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to access all the files in the remote directories. Note: the product has not been supported since 2018 and should be removed or…

  • CVE-2022-0572HigFeb 14, 2022
    risk 0.02cvss 7.8epss 0.27

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-0565HigFeb 14, 2022
    risk 0.42cvss 7.6epss 0.01

    Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1.

  • CVE-2022-0214HigFeb 14, 2022
    risk 0.49cvss 7.5epss 0.02

    The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog

  • CVE-2022-0190HigFeb 14, 2022
    risk 0.57cvss 8.8epss 0.01

    The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter of the delete action.

  • CVE-2021-45444HigFeb 14, 2022
    risk 0.51cvss 7.8epss 0.02

    In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.

  • CVE-2022-22765HigFeb 12, 2022
    risk 0.52cvss 8.0epss 0.00

    BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally…

  • CVE-2022-0311HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in Task Manager in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.