VYPR

CVEs

101,988 total · page 1202 of 2,040

  • CVE-2021-46153HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.02

    A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). Affected application contains a memory corruption vulnerability while parsing NEU files. This could allow an attacker to execute code in the context of the…

  • CVE-2021-46152HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.02

    A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). Affected application contains a type confusion vulnerability while parsing NEU files. This could allow an attacker to execute code in the context of the current…

  • CVE-2021-46151HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.02

    A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). Affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted NEU files. This could allow an…

  • CVE-2021-44018HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.02

    A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), Solid Edge SE2022 (All versions < SE2022MP1), Teamcenter Visualization V13.1 (All versions < V13.1.0.9), Teamcenter Visualization V13.2 (All versions <…

  • CVE-2021-44016HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.02

    A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), Solid Edge SE2022 (All versions < SE2022MP1), Teamcenter Visualization V13.1 (All versions < V13.1.0.9), Teamcenter Visualization V13.2 (All versions <…

  • CVE-2021-44000HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.02

    A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), Solid Edge SE2022 (All versions < SE2022MP1), Teamcenter Visualization V13.1 (All versions < V13.1.0.9), Teamcenter Visualization V13.2 (All versions <…

  • CVE-2021-40363HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (All versions < V16 Update 5), SIMATIC…

  • CVE-2021-40360HigFeb 9, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIMATIC WinCC V16 (All versions < V16 Update 5), SIMATIC…

  • CVE-2021-37205HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V21.9 < V21.9.4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions…

  • CVE-2021-37204HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open…

  • CVE-2021-37194HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS…

  • CVE-2021-37185HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions >= V21.9 < V21.9.4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions…

  • CVE-2022-0538HigFeb 9, 2022
    risk 0.42cvss 7.5epss 0.04

    Jenkins 2.333 and earlier, LTS 2.319.2 and earlier defines custom XStream converters that have not been updated to apply the protections for the vulnerability CVE-2021-43859 and allow unconstrained resource usage.

  • CVE-2021-46360HigFeb 9, 2022
    risk 0.61cvss 8.8epss 0.09

    Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via uploading a PHP shell through /adminzone/index.php?page=admin-commandr.

  • CVE-2021-46354HigFeb 9, 2022
    risk 0.53cvss 7.5epss 0.13

    Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability to send requests to other systems can allow the vulnerable server to filtrate the real IP of the web…

  • CVE-2021-37852HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.01

    ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attacker to escalate privileges in the context of NT AUTHORITY\SYSTEM.

  • CVE-2022-24676HigFeb 9, 2022
    risk 0.57cvss 8.8epss 0.01

    update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive.

  • CVE-2022-23626HigFeb 8, 2022
    risk 0.52cvss 8.5epss 0.10

    m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions `imagecreatefrom*` and `image*` have not been checked properly. Although PHP issued warnings and the upload function returned `false`, the original file (that could contain a malicious…

  • CVE-2022-0524HigFeb 8, 2022
    risk 0.42cvss 7.5epss 0.02

    Business Logic Errors in GitHub repository publify/publify prior to 9.2.7.

  • CVE-2022-0523HigFeb 8, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.

  • CVE-2022-0522HigFeb 8, 2022
    risk 0.00cvss 7.1epss 0.01

    Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.

  • CVE-2022-0521HigFeb 8, 2022
    risk 0.00cvss 7.1epss 0.01

    Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2.

  • CVE-2022-0520HigFeb 8, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in NPM radare2.js prior to 5.6.2.

  • CVE-2022-0519HigFeb 8, 2022
    risk 0.00cvss 7.1epss 0.01

    Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.

  • CVE-2022-0518HigFeb 8, 2022
    risk 0.00cvss 7.1epss 0.01

    Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.

  • CVE-2021-45326HigFeb 8, 2022
    risk 0.00cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests.

  • CVE-2021-45325HigFeb 8, 2022
    risk 0.00cvss 7.5epss 0.01

    Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.

  • CVE-2022-23331HigFeb 8, 2022
    risk 0.57cvss 8.8epss 0.01

    In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information and can change the administrator password.

  • CVE-2022-21193HigFeb 8, 2022
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in TransmitMail 2.5.0 to 2.6.1 allows a remote unauthenticated attacker to obtain an arbitrary file on the server via unspecified vectors.

  • CVE-2022-21173HigFeb 8, 2022
    risk 0.57cvss 8.8epss 0.00

    Hidden functionality vulnerability in ELECOM LAN routers (WRH-300BK3 firmware v1.05 and earlier, WRH-300WH3 firmware v1.05 and earlier, WRH-300BK3-S firmware v1.05 and earlier, WRH-300DR3-S firmware v1.05 and earlier, WRH-300LB3-S firmware v1.05 and earlier, WRH-300PN3-S…

  • CVE-2022-24450HigFeb 8, 2022
    risk 0.57cvss 8.8epss 0.01

    NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.

  • CVE-2022-23624HigFeb 7, 2022
    risk 0.46cvss 8.1epss 0.01

    Frourio-express is a minimal full stack framework, for TypeScript. Frourio-express users who uses frourio-express version prior to v0.26.0 and integration with class-validator through `validators/` folder are subject to a input validation vulnerability. Validators do not work…

  • CVE-2022-23623HigFeb 7, 2022
    risk 0.46cvss 8.1epss 0.01

    Frourio is a full stack framework, for TypeScript. Frourio users who uses frourio version prior to v0.26.0 and integration with class-validator through `validators/` folder are subject to a input validation vulnerability. Validators do not work properly for request bodies and…

  • CVE-2022-23613HigFeb 7, 2022
    risk 0.00cvss 7.8epss 0.00

    xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability…

  • CVE-2022-21712HigFeb 7, 2022
    risk 0.42cvss 7.5epss 0.01

    twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent`…

  • CVE-2021-3861HigFeb 7, 2022
    risk 0.53cvss 8.2epss 0.00

    The RNDIS USB device class includes a buffer overflow vulnerability. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hvfp-w4h8-gxvj

  • CVE-2021-3835HigFeb 7, 2022
    risk 0.53cvss 8.2epss 0.01

    Buffer overflow in usb device class. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fm6v-8625-99jf

  • CVE-2022-23263HigFeb 7, 2022
    risk 0.50cvss 7.7epss 0.01

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2021-25108HigFeb 7, 2022
    risk 0.39cvss 7.1epss 0.00

    The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing…

  • CVE-2021-25095HigFeb 7, 2022
    risk 0.39cvss 7.1epss 0.01

    The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber to call it and block arbitrary country, or block all of them…

  • CVE-2021-24879HigFeb 7, 2022
    risk 0.57cvss 8.8epss 0.01

    The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some of the filter fields which could allow attackers to make a logged in user having access to the ticket lists dashboard set an…

  • CVE-2021-24839HigFeb 7, 2022
    risk 0.49cvss 7.5epss 0.01

    The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthenticated users to call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action. Other actions…

  • CVE-2021-46389HigFeb 7, 2022
    risk 0.00cvss 7.5epss 0.01

    IIPImage High Resolution Streaming Image Server prior to commit 882925b295a80ec992063deffc2a3b0d803c3195 is affected by an integer overflow in iipsrv.fcgi through malformed HTTP query parameters.

  • CVE-2021-46359HigFeb 7, 2022
    risk 0.49cvss 7.5epss 0.01

    FISCO-BCOS release-3.0.0-rc2 contains a denial of service vulnerability. Some transactions may not be committed successfully, and malicious users may use this to achieve double-spending attacks.

  • CVE-2022-23320HigFeb 7, 2022
    risk 0.49cvss 7.5epss 0.02

    XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive information from the database.

  • CVE-2022-22833HigFeb 6, 2022
    risk 0.53cvss 7.5epss 0.11

    An issue was discovered in Servisnet Tessa 0.0.2. An attacker can obtain sensitive information via a /js/app.js request.

  • CVE-2022-24551HigFeb 6, 2022
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old password. An attacker could reset any local user password (including system/administrator user) using any available user This affects StarWind SAN and NAS…

  • CVE-2021-39280HigFeb 6, 2022
    risk 0.57cvss 8.8epss 0.02

    Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affects 2212X before 1.9.1, 2212S before 1.9.1, 2212G before 1.8, 3220 V3 before 1.5.1, 3420 V3 before 1.5.1, and 2311 through 2022-01-31.

  • CVE-2007-20001HigFeb 6, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in StarWind iSCSI target. An attacker could script standard iSCSI Initiator operation(s) to exhaust the StarWind service socket, which could lead to denial of service. This affects iSCSI SAN (Windows Native) Version 3.2.2 build 2007-02-20.

  • CVE-2022-23206HigFeb 6, 2022
    risk 0.42cvss 7.5epss 0.02

    In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach.