VYPR

CVEs

101,988 total · page 1211 of 2,040

  • CVE-2021-39293HigJan 24, 2022
    risk 0.49cvss 7.5epss 0.07

    In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic. NOTE: this issue exists because of an incomplete fix for CVE-2021-33196.

  • CVE-2022-23850HigJan 23, 2022
    risk 0.51cvss 7.8epss 0.01

    xhtml_translate_entity in xhtml.c in epub2txt (aka epub2txt2) through 2.02 allows a stack-based buffer overflow via a crafted EPUB document.

  • CVE-2021-39480HigJan 21, 2022
    risk 0.49cvss 7.5epss 0.01

    Bingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS).

  • CVE-2022-23837HigJan 21, 2022
    risk 0.42cvss 7.5epss 0.05

    In api.rb in Sidekiq before 5.2.10 and 6.4.0, there is no limit on the number of days when requesting stats for the graph. This overloads the system, affecting the Web UI, and makes it unavailable to users.

  • CVE-2022-22553HigJan 21, 2022
    risk 0.53cvss 8.1epss 0.01

    Dell EMC AppSync versions 3.9 to 4.3 contain an Improper Restriction of Excessive Authentication Attempts Vulnerability that can be exploited from UI and CLI. An adjacent unauthenticated attacker could potentially exploit this vulnerability, leading to password brute-forcing.…

  • CVE-2022-22551HigJan 21, 2022
    risk 0.54cvss 8.3epss 0.00

    DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An Adjacent, unauthenticated attacker could potentially exploit this vulnerability, and hijack the victim session.

  • CVE-2021-46242HigJan 21, 2022
    risk 0.57cvss 8.8epss 0.01

    HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.

  • CVE-2021-36339HigJan 21, 2022
    risk 0.51cvss 7.8epss 0.00

    The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulnerability to get privileged access to the virtual appliance.

  • CVE-2021-23664HigJan 21, 2022
    risk 0.49cvss 8.6epss 0.01

    The package @isomorphic-git/cors-proxy before 2.7.1 are vulnerable to Server-side Request Forgery (SSRF) due to missing sanitization and validation of the redirection action in middleware.js.

  • CVE-2021-23631HigJan 21, 2022
    risk 0.49cvss 7.5epss 0.02

    This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of package convert-svg-to-jpeg. Using a specially crafted SVG file, an attacker could read arbitrary files from the file system and then show the file content as a…

  • CVE-2021-23518HigJan 21, 2022
    risk 0.41cvss 7.3epss 0.02

    The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to…

  • CVE-2021-23460HigJan 21, 2022
    risk 0.42cvss 7.5epss 0.02

    The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types.

  • CVE-2021-44593HigJan 21, 2022
    risk 0.53cvss 8.1epss 0.04

    Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL injection in the username parameter on /admin/login.php.

  • CVE-2021-43355HigJan 21, 2022
    risk 0.48cvss 7.3epss 0.01

    Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authentication by the server. The server should not rely on the correctness of the data because users might not support or block JavaScript…

  • CVE-2021-41835HigJan 21, 2022
    risk 0.47cvss 7.3epss 0.00

    Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be sent in cleartext. Transport layer encryption is offered on Port TCP/443, but the affected service does not perform an automated redirect from the unencrypted…

  • CVE-2021-23236HigJan 21, 2022
    risk 0.49cvss 7.5epss 0.01

    Requests may be used to interrupt the normal operation of the device. When exploited, Fresenius Kabi Agilia Link+ version 3.0 must be rebooted via a hard reset triggered by pressing a button on the rack system.

  • CVE-2021-23233HigJan 21, 2022
    risk 0.48cvss 7.3epss 0.01

    Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical…

  • CVE-2021-23196HigJan 21, 2022
    risk 0.48cvss 7.3epss 0.01

    The web application on Agilia Link+ version 3.0 implements authentication and session management mechanisms exclusively on the client-side and does not protect authentication attributes sufficiently.

  • CVE-2022-0323HigJan 21, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.

  • CVE-2020-4876HigJan 21, 2022
    risk 0.53cvss 8.2epss 0.02

    IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190839.

  • CVE-2020-4875HigJan 21, 2022
    risk 0.53cvss 8.2epss 0.02

    IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 190838.

  • CVE-2022-23220HigJan 21, 2022
    risk 0.00cvss 7.8epss 0.01

    USBView 2.1 before 2.2 allows some local users (e.g., ones logged in via SSH) to execute arbitrary code as root because certain Polkit settings (e.g., allow_any=yes) for pkexec disable the authentication requirement. Code execution can, for example, use the --gtk-module option.…

  • CVE-2020-19861HigJan 21, 2022
    risk 0.49cvss 7.5epss 0.01

    When a zone file in ldns 1.7.1 is parsed, the function ldns_nsec3_salt_data is too trusted for the length value obtained from the zone file. When the memcpy is copied, the 0xfe - ldns_rdf_size(salt_rdf) byte data can be copied, causing heap overflow information leakage.

  • CVE-2020-19858HigJan 21, 2022
    risk 0.00cvss 7.5epss 0.02

    Platinum Upnp SDK through 1.2.0 has a directory traversal vulnerability. The attack could remote attack victim by sending http://ip:port/../privacy.avi URL to compromise a victim's privacy.

  • CVE-2022-22895HigJan 21, 2022
    risk 0.51cvss 7.8epss 0.01

    Jerryscript 3.0.0 was discovered to contain a heap-buffer-overflow via ecma_utf8_string_to_number_by_radix in /jerry-core/ecma/base/ecma-helpers-conversion.c.

  • CVE-2022-22894HigJan 21, 2022
    risk 0.51cvss 7.8epss 0.01

    Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_lcache_lookup in /jerry-core/ecma/base/ecma-lcache.c.

  • CVE-2022-22893HigJan 21, 2022
    risk 0.51cvss 7.8epss 0.01

    Jerryscript 3.0.0 was discovered to contain a stack overflow via vm_loop.lto_priv.304 in /jerry-core/vm/vm.c.

  • CVE-2022-22888HigJan 20, 2022
    risk 0.51cvss 7.8epss 0.01

    Jerryscript 3.0.0 was discovered to contain a stack overflow via ecma_op_object_find_own in /ecma/operations/ecma-objects.c.

  • CVE-2021-46334HigJan 20, 2022
    risk 0.51cvss 7.8epss 0.01

    Moddable SDK v11.5.0 was discovered to contain a stack buffer overflow via the component __interceptor_strcat.

  • CVE-2021-46332HigJan 20, 2022
    risk 0.51cvss 7.8epss 0.01

    Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via xs/sources/xsDataView.c in fxUint8Getter.

  • CVE-2021-46328HigJan 20, 2022
    risk 0.51cvss 7.8epss 0.01

    Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __libc_start_main.

  • CVE-2021-46326HigJan 20, 2022
    risk 0.51cvss 7.8epss 0.01

    Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __asan_memcpy.

  • CVE-2021-46325HigJan 20, 2022
    risk 0.51cvss 7.8epss 0.01

    Espruino 2v10.246 was discovered to contain a stack buffer overflow via src/jsutils.c in vcbprintf.

  • CVE-2021-46324HigJan 20, 2022
    risk 0.51cvss 7.8epss 0.01

    Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.

  • CVE-2020-23315HigJan 20, 2022
    risk 0.49cvss 7.5epss 0.02

    There is an ASSERTION (pFuncBody->GetYieldRegister() == oldYieldRegister) failed in Js::DebugContext::RundownSourcesAndReparse in ChakraCore version 1.12.0.0-beta.

  • CVE-2022-23120HigJan 20, 2022
    risk 0.51cvss 7.8epss 0.06

    A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to escalate privileges and run arbitrary code in the context of root. Please note: an attacker must first obtain access to…

  • CVE-2022-23119HigJan 20, 2022
    risk 0.51cvss 7.5epss 0.22

    A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to read arbitrary files from the file system. Please note: an attacker must first obtain compromised access to the…

  • CVE-2022-21658HigJan 20, 2022
    risk 0.00cvss 7.3epss 0.01

    Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling…

  • CVE-2021-45417HigJan 20, 2022
    risk 0.51cvss 7.8epss 0.00

    AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.

  • CVE-2021-44737HigJan 20, 2022
    risk 0.57cvss 8.8epss 0.01

    PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.

  • CVE-2022-0281HigJan 20, 2022
    risk 0.43cvss 7.5epss 0.12

    Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.

  • CVE-2021-43269HigJan 20, 2022
    risk 0.57cvss 8.8epss 0.01

    In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Advanced, and Gov F1; CrashPlan Cloud; and CrashPlan for…

  • CVE-2022-21699HigJan 19, 2022
    risk 0.46cvss 8.2epss 0.01

    IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing…

  • CVE-2022-23046HigJan 19, 2022
    risk 0.52cvss 7.2epss 0.25

    PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/edit-bgp-mapping-search.php

  • CVE-2021-23843HigJan 19, 2022
    risk 0.57cvss 8.8epss 0.00

    The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices. The tool allows putting a password protection on configured devices to restrict access to the configuration of an AMC2. An attacker can circumvent this…

  • CVE-2022-22769HigJan 19, 2022
    risk 0.52cvss 8.0epss 0.01

    The Web server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, TIBCO EBX Add-ons, TIBCO EBX Add-ons, TIBCO EBX Add-ons, and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged…

  • CVE-2021-38789HigJan 19, 2022
    risk 0.49cvss 7.5epss 0.01

    Allwinner R818 SoC Android Q SDK V1.0 is affected by an incorrect access control vulnerability that does not check the caller's permission, in which a third-party app could change system settings.

  • CVE-2021-42810HigJan 19, 2022
    risk 0.51cvss 7.8epss 0.00

    A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a privileged user on a system where the agent is installed.

  • CVE-2021-38788HigJan 19, 2022
    risk 0.49cvss 7.5epss 0.02

    The Background service in Allwinner R818 SoC Android Q SDK V1.0 is used to manage background applications. Malicious apps can use the interface provided by the service to set the number of applications allowed to run in the background to 0 and add themselves to the whitelist, so…

  • CVE-2021-46104HigJan 19, 2022
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary file information on the server.