VYPR

CVEs

101,988 total · page 1206 of 2,040

  • CVE-2022-0366HigFeb 2, 2022
    risk 0.57cvss 8.8epss 0.01

    An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Capsule8 Console between versions 4.6.0 and 4.9.1.

  • CVE-2021-41018HigFeb 2, 2022
    risk 0.57cvss 8.8epss 0.03

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.

  • CVE-2021-39066HigFeb 2, 2022
    risk 0.57cvss 8.8epss 0.01

    IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session identifier gives an attacker the opportunity to steal authenticated sessions. IBM X-Force ID: 215040.

  • CVE-2021-39044HigFeb 2, 2022
    risk 0.57cvss 8.8epss 0.00

    IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 214210.

  • CVE-2021-43073HigFeb 2, 2022
    risk 0.57cvss 8.8epss 0.01

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.

  • CVE-2021-42753HigFeb 2, 2022
    risk 0.53cvss 8.1epss 0.01

    An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.x, 6.1.x, 6.0.x, 5.9.x and 5.8.x may allow an authenticated attacker to perform an arbitrary file and…

  • CVE-2021-41016HigFeb 2, 2022
    risk 0.51cvss 7.8epss 0.01

    A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version 7.0.1 and below, 4.2.3 and below, 4.1.7 and below allows an authenticated attacker to execute privileged shell commands via CLI commands including special…

  • CVE-2021-42638HigFeb 1, 2022
    risk 0.53cvss 8.1epss 0.05

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.

  • CVE-2022-23601HigFeb 1, 2022
    risk 0.46cvss 8.1epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony form component provides a CSRF protection mechanism by using a random token injected in the form and using the session to store and control the token submitted by the…

  • CVE-2022-0417HigFeb 1, 2022
    risk 0.00cvss 7.8epss 0.02

    Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.

  • CVE-2021-43848HigFeb 1, 2022
    risk 0.00cvss 7.4epss 0.03

    h2o is an open source http server. In code prior to the `8c0eca3` commit h2o may attempt to access uninitialized memory. When receiving QUIC frames in certain order, HTTP/3 server-side implementation of h2o can be misguided to treat uninitialized memory as HTTP/3 frames that…

  • CVE-2021-25093HigFeb 1, 2022
    risk 0.49cvss 7.5epss 0.01

    The Link Library WordPress plugin before 7.2.8 does not have authorisation in place when deleting links, allowing unauthenticated users to delete arbitrary links via a crafted request

  • CVE-2021-24919HigFeb 1, 2022
    risk 0.57cvss 8.8epss 0.02

    The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injection

  • CVE-2021-24763HigFeb 1, 2022
    risk 0.57cvss 8.8epss 0.01

    The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF checks in the save_global_setting AJAX action, allowing unauthenticated users to edit surveys and modify settings. Given the lack of sanitisation and escaping in the settings, this could…

  • CVE-2022-23597HigFeb 1, 2022
    risk 0.00cvss 8.3epss 0.01

    Element Desktop is a Matrix client for desktop platforms with Element Web at its core. Element Desktop before 1.9.7 is vulnerable to a remote program execution bug with user interaction. The exploit is non-trivial and requires clicking on a malicious link, followed by another…

  • CVE-2022-23596HigFeb 1, 2022
    risk 0.42cvss 7.5epss 0.02

    Junrar is an open source java RAR archive library. In affected versions A carefully crafted RAR archive can trigger an infinite loop while extracting said archive. The impact depends solely on how the application uses the library, and whether files can be provided by malignant…

  • CVE-2021-43859HigFeb 1, 2022
    risk 0.42cvss 7.5epss 0.08

    XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service…

  • CVE-2021-41040HigFeb 1, 2022
    risk 0.00cvss 7.5epss 0.01

    In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-received data.

  • CVE-2022-23602HigFeb 1, 2022
    risk 0.00cvss 7.7epss 0.01

    Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create a new thread/post with an include referencing a file local to the host operating system. Nimforum will render the file if able. This can also be done silently…

  • CVE-2021-46669HigFeb 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.

  • CVE-2022-24266HigJan 31, 2022
    risk 0.49cvss 7.5epss 0.06

    Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.

  • CVE-2022-24265HigJan 31, 2022
    risk 0.49cvss 7.5epss 0.07

    Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.

  • CVE-2022-24264HigJan 31, 2022
    risk 0.49cvss 7.5epss 0.07

    Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.

  • CVE-2021-46459HigJan 31, 2022
    risk 0.49cvss 7.5epss 0.01

    Victor CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component admin/users.php?source=add_user. These vulnerabilities can be exploited through a crafted POST request via the user_name, user_firstname,user_lastname, or user_email parameters.

  • CVE-2021-42635HigJan 31, 2022
    risk 0.53cvss 8.1epss 0.06

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.

  • CVE-2021-42631HigJan 31, 2022
    risk 0.53cvss 8.1epss 0.06

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution.

  • CVE-2021-46458HigJan 31, 2022
    risk 0.49cvss 7.5epss 0.01

    Victor CMS v1.0 was discovered to contain a SQL injection vulnerability in the component admin/posts.php?source=add_post. This vulnerability can be exploited through a crafted POST request via the post_title parameter.

  • CVE-2021-28962HigJan 31, 2022
    risk 0.47cvss 7.2epss 0.01

    Stormshield Network Security (SNS) before 4.2.2 allows a read-only administrator to gain privileges via CLI commands.

  • CVE-2021-46101HigJan 31, 2022
    risk 0.49cvss 7.5epss 0.01

    In Git for windows through 2.34.1 when using git pull to update the local warehouse, git.cmd can be run directly.

  • CVE-2021-44255HigJan 31, 2022
    risk 0.47cvss 7.2epss 0.03

    Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup file containing a malicious python pickle file which will execute arbitrary code on the server.

  • CVE-2021-34805HigJan 31, 2022
    risk 0.51cvss 7.5epss 0.27

    An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal.

  • CVE-2021-27971HigJan 31, 2022
    risk 0.51cvss 7.8epss 0.00

    Alps Alpine Touchpad Driver 10.3201.101.215 is vulnerable to DLL Injection.

  • CVE-2022-0413HigJan 30, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-0408HigJan 30, 2022
    risk 0.00cvss 7.8epss 0.02

    Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-0407HigJan 30, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-24124HigJan 29, 2022
    risk 0.01cvss 7.5epss 0.59

    The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.

  • CVE-2022-24122HigJan 29, 2022
    risk 0.00cvss 7.8epss 0.01

    kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.

  • CVE-2022-0393HigJan 28, 2022
    risk 0.00cvss 7.1epss 0.01

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-0392HigJan 28, 2022
    risk 0.00cvss 7.8epss 0.02

    Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.

  • CVE-2021-44419HigJan 28, 2022
    risk 0.50cvss 7.7epss 0.01

    A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetMdAlarm param is not object. An attacker can send an HTTP request to trigger this…

  • CVE-2021-44418HigJan 28, 2022
    risk 0.50cvss 7.7epss 0.01

    A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetMdState param is not object. An attacker can send an HTTP request to trigger this…

  • CVE-2021-44417HigJan 28, 2022
    risk 0.50cvss 7.7epss 0.01

    A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetAlarm param is not object. An attacker can send an HTTP request to trigger this…

  • CVE-2021-44416HigJan 28, 2022
    risk 0.50cvss 7.7epss 0.01

    A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. Disconnect param is not object. An attacker can send an HTTP request to trigger this…

  • CVE-2021-44415HigJan 28, 2022
    risk 0.50cvss 7.7epss 0.01

    A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. ModifyUser param is not object. An attacker can send an HTTP request to trigger this…

  • CVE-2021-44414HigJan 28, 2022
    risk 0.50cvss 7.7epss 0.01

    A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. DelUser param is not object. An attacker can send an HTTP request to trigger this…

  • CVE-2021-44413HigJan 28, 2022
    risk 0.50cvss 7.7epss 0.01

    A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. AddUser param is not object. An attacker can send an HTTP request to trigger this…

  • CVE-2021-44412HigJan 28, 2022
    risk 0.50cvss 7.7epss 0.01

    A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetRec param is not object. An attacker can send an HTTP request to trigger this…

  • CVE-2021-44411HigJan 28, 2022
    risk 0.50cvss 7.7epss 0.01

    A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. Search param is not object. An attacker can send an HTTP request to trigger this…

  • CVE-2021-44410HigJan 28, 2022
    risk 0.50cvss 7.7epss 0.01

    A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. UpgradePrepare param is not object. An attacker can send an HTTP request to trigger…

  • CVE-2021-44409HigJan 28, 2022
    risk 0.50cvss 7.7epss 0.01

    A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. TestWifi param is not object. An attacker can send an HTTP request to trigger this…