VYPR

CVEs

101,988 total · page 1209 of 2,040

  • CVE-2021-46519HigJan 27, 2022
    risk 0.51cvss 7.8epss 0.01

    Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjs_array_length at src/mjs_array.c.

  • CVE-2021-46518HigJan 27, 2022
    risk 0.51cvss 7.8epss 0.01

    Cesanta MJS v2.20.0 was discovered to contain a heap buffer overflow via mjs_disown at src/mjs_core.c.

  • CVE-2021-46513HigJan 27, 2022
    risk 0.51cvss 7.8epss 0.01

    Cesanta MJS v2.20.0 was discovered to contain a global buffer overflow via mjs_mk_string at mjs/src/mjs_string.c.

  • CVE-2021-46509HigJan 27, 2022
    risk 0.51cvss 7.8epss 0.01

    Cesanta MJS v2.20.0 was discovered to contain a stack overflow via snquote at mjs/src/mjs_json.c.

  • CVE-2021-46102HigJan 27, 2022
    risk 0.00cvss 7.5epss 0.02

    From version 0.2.14 to 0.2.16 for Solana rBPF, function "relocate" in the file src/elf.rs has an integer overflow bug because the sym.st_value is read directly from ELF file without checking. If the sym.st_value is rather large, an integer overflow is triggered while calculating…

  • CVE-2021-46097HigJan 27, 2022
    risk 0.57cvss 8.8epss 0.02

    Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_log

  • CVE-2021-46088HigJan 27, 2022
    risk 0.47cvss 7.2epss 0.04

    Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.

  • CVE-2022-23181HigJan 27, 2022
    risk 0.46cvss 7.0epss 0.01

    The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the…

  • CVE-2021-44793HigJan 27, 2022
    risk 0.56cvss 8.6epss 0.01

    Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to access the device configuration page and export the data to an external file. The exploitation of this vulnerability might allow a…

  • CVE-2022-22828HigJan 27, 2022
    risk 0.49cvss 7.5epss 0.02

    An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker to access unshared files via a modified base64-encoded filename string.

  • CVE-2021-32849HigJan 26, 2022
    risk 0.58cvss 8.8epss 0.08

    Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is fixed in version 0.9.9. There are no known workarounds.

  • CVE-2021-32840HigJan 26, 2022
    risk 0.41cvss 7.3epss 0.02

    SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. This leads to arbitrary file write that may lead to code execution. The vulnerability was patched in…

  • CVE-2022-23990HigJan 26, 2022
    risk 0.00cvss 7.5epss 0.04

    Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.

  • CVE-2021-46385HigJan 26, 2022
    risk 0.49cvss 7.5epss 0.02

    https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.FormDataAction#queryData. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability…

  • CVE-2021-46114HigJan 26, 2022
    risk 0.57cvss 8.8epss 0.01

    jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.

  • CVE-2022-0368HigJan 26, 2022
    risk 0.00cvss 7.8epss 0.02

    Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

  • CVE-2021-46561HigJan 26, 2022
    risk 0.00cvss 7.2epss 0.01

    controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational administrator to transfer a user account to an arbitrary new organization, and thereby achieve unintended access within the context…

  • CVE-2021-29845HigJan 26, 2022
    risk 0.57cvss 8.8epss 0.01

    IBM Security Guardium Insights 3.0 could allow an authenticated user to perform unauthorized actions due to improper input validation. IBM X-Force ID: 205255.

  • CVE-2021-46383HigJan 26, 2022
    risk 0.49cvss 7.5epss 0.02

    https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.web.DictAction#list. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability…

  • CVE-2021-46118HigJan 26, 2022
    risk 0.47cvss 7.2epss 0.02

    jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.

  • CVE-2021-46116HigJan 26, 2022
    risk 0.47cvss 7.2epss 0.02

    jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function through which attackers can install templates and inject some malicious code.

  • CVE-2021-46115HigJan 26, 2022
    risk 0.47cvss 7.2epss 0.01

    jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attackers can upload templates and inject some malicious code.

  • CVE-2021-46117HigJan 26, 2022
    risk 0.47cvss 7.2epss 0.03

    jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.

  • CVE-2021-45975HigJan 26, 2022
    risk 0.51cvss 7.8epss 0.01

    In ListCheck.exe in Acer Care Center 4.x before 4.00.3038, a vulnerability in the loading mechanism of Windows DLLs could allow a local attacker to perform a DLL hijacking attack. This vulnerability is due to incorrect handling of directory search paths at run time. An attacker…

  • CVE-2022-0361HigJan 26, 2022
    risk 0.00cvss 7.8epss 0.02

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-0359HigJan 26, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2021-44123HigJan 26, 2022
    risk 0.57cvss 8.8epss 0.02

    SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

  • CVE-2021-44122HigJan 26, 2022
    risk 0.57cvss 8.8epss 0.00

    SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public/aiguiller.php, ecrire/public/balises.php, ecrire/balise/formulaire_.php. To exploit the vulnerability, a visitor must visit a malicious website which redirects to the SPIP website. It is…

  • CVE-2021-41766HigJan 26, 2022
    risk 0.46cvss 8.1epss 0.02

    Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the default JMX implementation is hardened…

  • CVE-2022-21944HigJan 26, 2022
    risk 0.51cvss 7.8epss 0.00

    A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SLE-15-SP3, Factory allows local attackers to escalate to root. This issue affects: openSUSE Backports SLE-15-SP3 watchman versions prior to 4.9.0. openSUSE…

  • CVE-2022-23968HigJan 26, 2022
    risk 0.49cvss 7.5epss 0.02

    Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device via a crafted TIFF file in an unauthenticated HTTP POST request. There is a permanent denial of service because image parsing causes a reboot, but image parsing…

  • CVE-2022-0355HigJan 26, 2022
    risk 0.50cvss 8.8epss 0.02

    Improper Removal of Sensitive Information Before Storage or Transfer in NPM simple-get prior to 4.0.1.

  • CVE-2021-46559HigJan 26, 2022
    risk 0.49cvss 7.5epss 0.00

    The firmware on Moxa TN-5900 devices through 3.1 has a weak algorithm that allows an attacker to defeat an inspection mechanism for integrity protection.

  • CVE-2021-36348HigJan 25, 2022
    risk 0.53cvss 8.1epss 0.01

    iDRAC9 versions prior to 5.00.20.00 contain an input injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by supplying specially crafted input data to…

  • CVE-2021-36347HigJan 25, 2022
    risk 0.47cvss 7.2epss 0.02

    iDRAC9 versions prior to 5.00.20.00 and iDRAC8 versions prior to 2.82.82.82 contain a stack-based buffer overflow vulnerability. An authenticated remote attacker with high privileges could potentially exploit this vulnerability to control process execution and gain access to the…

  • CVE-2021-36296HigJan 25, 2022
    risk 0.47cvss 7.2epss 0.03

    Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.

  • CVE-2021-36295HigJan 25, 2022
    risk 0.47cvss 7.2epss 0.03

    Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.

  • CVE-2021-36289HigJan 25, 2022
    risk 0.51cvss 7.8epss 0.00

    Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulnerability to read sensitive information and use it.

  • CVE-2021-43799HigJan 25, 2022
    risk 0.00cvss 8.6epss 0.05

    Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.9, the initial installation (until first reboot, or restart of RabbitMQ) does not successfully limit the default ports which…

  • CVE-2022-23025HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP version 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, when a SIP ALG profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software…

  • CVE-2022-23024HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, when the IPsec application layer gateway (ALG) logging profile is configured on an IPsec ALG virtual server, undisclosed IPsec traffic can cause the Traffic…

  • CVE-2022-23022HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP version 16.1.x before 16.1.2, when an HTTP profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2022-23021HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP version 16.1.x before 16.1.2, when any of the following configurations are configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate: HTTP redirect rule in an LTM policy, BIG-IP APM Access Profile, and Explicit…

  • CVE-2022-23020HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP version 16.1.x before 16.1.2, when the 'Respond on Error' setting is enabled on the Request Logging profile and configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have…

  • CVE-2022-23019HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x and 12.1.x, when a message routing type virtual server is configured with both Diameter Session and Router Profiles, undisclosed traffic can cause an increase in…

  • CVE-2022-23018HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP AFM version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and 13.1.x beginning in 13.1.3.4, when a virtual server is configured with both HTTP protocol security and HTTP Proxy Connect profiles, undisclosed requests can cause the Traffic…

  • CVE-2022-23017HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when a virtual server is configured with a DNS profile with the Rapid Response Mode setting enabled and is configured on a BIG-IP system, undisclosed requests can…

  • CVE-2022-23016HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP SSL Forward Proxy with TLS 1.3 is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of…

  • CVE-2022-23015HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, and 14.1.2.6-14.1.4.4, when a Client SSL profile is configured on a virtual server with Client Certificate Authentication set to request/require and Session Ticket enabled and configured, processing SSL traffic can…

  • CVE-2022-23013HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.01

    On BIG-IP DNS & GTM version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an…