VYPR

CVEs

101,988 total · page 1210 of 2,040

  • CVE-2022-23012HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP versions 15.1.x before 15.1.4.1 and 14.1.x before 14.1.4.5, when the HTTP/2 profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical…

  • CVE-2022-23011HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On certain hardware BIG-IP platforms, in version 15.1.x before 15.1.4 and 14.1.x before 14.1.3, virtual servers may stop responding while processing TCP traffic due to an issue in the SYN Cookie Protection feature. Note: Software versions which have reached End of Technical…

  • CVE-2022-23010HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile and an HTTP profile are configured on a virtual server, undisclosed requests can cause an increase in memory resource…

  • CVE-2022-23009HigJan 25, 2022
    risk 0.47cvss 7.2epss 0.01

    On BIG-IQ Centralized Management 8.x before 8.1.0, an authenticated administrative role user on a BIG-IQ managed BIG-IP device can access other BIG-IP devices managed by the same BIG-IQ system. Note: Software versions which have reached End of Technical Support (EoTS) are not…

  • CVE-2022-0335HigJan 25, 2022
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk.

  • CVE-2022-0270HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Prior to v0.6.1, bored-agent failed to sanitize incoming kubernetes impersonation headers allowing a user to override assigned user name and groups.

  • CVE-2021-4133HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.

  • CVE-2021-41598HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.01

    A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during a GitHub App's user-authorization web flow than was displayed to the user during approval. To exploit this vulnerability, an attacker would need to…

  • CVE-2021-40167HigJan 25, 2022
    risk 0.51cvss 7.8epss 0.08

    A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current…

  • CVE-2021-40159HigJan 25, 2022
    risk 0.51cvss 7.8epss 0.02

    An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current process.

  • CVE-2021-40158HigJan 25, 2022
    risk 0.51cvss 7.8epss 0.03

    A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the…

  • CVE-2022-0351HigJan 25, 2022
    risk 0.00cvss 7.8epss 0.01

    Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.

  • CVE-2021-39031HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.02

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and could result in in granting permission to…

  • CVE-2021-46086HigJan 25, 2022
    risk 0.49cvss 7.5epss 0.01

    xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examination system. There is an unsafe vulnerability in the functional method of submitting examination papers. An attacker can use burpuite to modify parameters in…

  • CVE-2021-43863HigJan 25, 2022
    risk 0.00cvss 7.5epss 0.02

    The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. The Nextcloud Android app uses content providers to manage its data. Prior to version 3.18.1, the providers `FileContentProvider` and `DiskLruImageCacheFileProvider` have security…

  • CVE-2021-34869HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.00

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific…

  • CVE-2021-34868HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.00

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific…

  • CVE-2021-34867HigJan 25, 2022
    risk 0.53cvss 8.2epss 0.00

    This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-49160. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific…

  • CVE-2021-34866HigJan 25, 2022
    risk 0.51cvss 7.8epss 0.01

    This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists…

  • CVE-2021-34865HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.03

    This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the mini_httpd service, which listens on TCP port 80…

  • CVE-2022-23033HigJan 25, 2022
    risk 0.51cvss 7.8epss 0.00

    arm: guest_physmap_remove_page not removing the p2m mappings The functions to remove one or more entries from a guest p2m pagetable on Arm (p2m_remove_mapping, guest_physmap_remove_page, and p2m_set_entry with mfn set to INVALID_MFN) do not actually clear the pagetable entry if…

  • CVE-2022-23945HigJan 25, 2022
    risk 0.42cvss 7.5epss 0.04

    Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

  • CVE-2022-23223HigJan 25, 2022
    risk 0.42cvss 7.5epss 0.04

    On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later.

  • CVE-2021-46113HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.03

    In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service.

  • CVE-2021-45845HigJan 25, 2022
    risk 0.00cvss 7.8epss 0.02

    The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted FCStd document.

  • CVE-2021-45844HigJan 25, 2022
    risk 0.51cvss 7.8epss 0.01

    Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.

  • CVE-2021-45803HigJan 25, 2022
    risk 0.57cvss 8.8epss 0.01

    MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when viewing reservation.

  • CVE-2021-45342HigJan 25, 2022
    risk 0.51cvss 7.8epss 0.02

    A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.

  • CVE-2021-45341HigJan 25, 2022
    risk 0.58cvss 8.8epss 0.07

    A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.

  • CVE-2022-23935HigJan 25, 2022
    risk 0.01cvss 7.8epss 0.08

    lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.

  • CVE-2021-46483HigJan 25, 2022
    risk 0.51cvss 7.8epss 0.01

    Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c.

  • CVE-2021-46482HigJan 25, 2022
    risk 0.51cvss 7.8epss 0.01

    Jsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c.

  • CVE-2021-44988HigJan 25, 2022
    risk 0.51cvss 7.8epss 0.01

    Jerryscript v3.0.0 and below was discovered to contain a stack overflow via ecma_find_named_property in ecma-helpers.c.

  • CVE-2022-22554HigJan 24, 2022
    risk 0.53cvss 8.2epss 0.00

    Dell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local attacker with user privleges could potentially exploit this vulnerability leading to the disclosure of user passwords.

  • CVE-2022-21711HigJan 24, 2022
    risk 0.00cvss 7.1epss 0.01

    elfspirit is an ELF static analysis and injection framework that parses, manipulates, and camouflages ELF files. When analyzing the ELF file format in versions prior to 1.1, there is an out-of-bounds read bug, which can lead to application crashes or information leakage. By…

  • CVE-2021-45222HigJan 24, 2022
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in COINS Construction Cloud 11.12. Due to logical flaws in the human ressources interface, it is vulnerable to privilege escalation by HR personnel.

  • CVE-2021-36343HigJan 24, 2022
    risk 0.49cvss 7.5epss 0.00

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

  • CVE-2021-36342HigJan 24, 2022
    risk 0.49cvss 7.5epss 0.00

    Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

  • CVE-2021-4088HigJan 24, 2022
    risk 0.55cvss 8.4epss 0.02

    SQL injection vulnerability in Data Loss Protection (DLP) ePO extension 11.8.x prior to 11.8.100, 11.7.x prior to 11.7.101, and 11.6.401 allows a remote authenticated attacker to inject unfiltered SQL into the DLP part of the ePO database. This could lead to remote code…

  • CVE-2021-44981HigJan 24, 2022
    risk 0.57cvss 8.8epss 0.04

    In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec(''); function without properly sanitizing any shell arguments, therefore remote code execution is possible. Additionally, as the media server is…

  • CVE-2022-0269HigJan 24, 2022
    risk 0.45cvss 8.0epss 0.01

    Cross-Site Request Forgery (CSRF) in Packagist yetiforce/yetiforce-crm prior to 6.3.0.

  • CVE-2021-25076HigJan 24, 2022
    risk 0.55cvss 8.8epss 0.17

    The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in a SQL statement in the Subscribers dashboard, leading to an SQL injection. Due to the lack of sanitisation and escaping, this could also lead to Reflected…

  • CVE-2021-25073HigJan 24, 2022
    risk 0.57cvss 8.8epss 0.01

    The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, allowing attackers to make a logged in admin delete them via a CSRF attack

  • CVE-2021-25045HigJan 24, 2022
    risk 0.47cvss 7.2epss 0.01

    The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in a SQL statement when editing a forum, leading to an SQL injection issue

  • CVE-2021-24936HigJan 24, 2022
    risk 0.52cvss 8.0epss 0.01

    The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise and escape some of them, which could allow attackers to make a logged in admin change them and perform Cross-Site Scripting attacks

  • CVE-2021-24906HigJan 24, 2022
    risk 0.49cvss 7.5epss 0.01

    The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, which could allow unauthenticated users to disable the plugin (and therefore the protection offered) via a crafted request

  • CVE-2021-24865HigJan 24, 2022
    risk 0.40cvss 7.2epss 0.01

    The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters before using them in a SQL statement, leading to a SQL Injection issue

  • CVE-2021-24858HigJan 24, 2022
    risk 0.47cvss 7.2epss 0.01

    The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before using it in a SQL statement, when retrieving the setting to edit in the admin dashboard, leading to an authenticated SQL Injection

  • CVE-2021-24696HigJan 24, 2022
    risk 0.57cvss 8.8epss 0.01

    The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3)…

  • CVE-2022-23858HigJan 24, 2022
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in the REST API. An improperly handled REST API call could allow any logged user to elevate privileges up to the system account. This affects StarWind Command Center build 6003 v2.