VYPR

CVEs

101,988 total · page 1213 of 2,040

  • CVE-2021-41807HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.

  • CVE-2021-39946HigJan 18, 2022
    risk 0.57cvss 8.7epss 0.01

    Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

  • CVE-2021-29632HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.01

    In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, 13.0-RELEASE before p6, and 12.2-RELEASE before p12, certain conditions involving use of the highlight buffer while text is scrolling on the console, console data may overwrite data structures…

  • CVE-2020-14110HigJan 18, 2022
    risk 0.51cvss 7.8epss 0.00

    AX3600 router sensitive information leaked.There is an unauthorized interface through luci to obtain sensitive information and log in to the web background.

  • CVE-2020-14107HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.01

    A stack overflow in the HTTP server of Cast can be exploited to make the app crash in LAN.

  • CVE-2022-23307HigJan 18, 2022
    risk 0.61cvss 8.8epss 0.52

    CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.

  • CVE-2022-23302HigJan 18, 2022
    risk 0.62cvss 8.8epss 0.62

    JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a…

  • CVE-2022-0263HigJan 18, 2022
    risk 0.44cvss 7.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.

  • CVE-2022-0261HigJan 18, 2022
    risk 0.00cvss 7.8epss 0.02

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2021-41550HigJan 18, 2022
    risk 0.47cvss 7.2epss 0.01

    Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.

  • CVE-2021-38696HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.02

    SoftVibe SARABAN for INFOMA 1.1 has Incorrect Access Control vulnerability, that allows attackers to access signature files on the application without any authentication.

  • CVE-2021-38785HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.02

    There is a NULL pointer deference in the Allwinner R818 SoC Android Q SDK V1.0 camera driver /dev/cedar_dev that could use the ioctl cmd IOCTL_GET_IOMMU_ADDR to cause a system crash.

  • CVE-2021-38784HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.02

    There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that could executable a malicious file to cause a system crash.

  • CVE-2021-38694HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.01

    SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection.

  • CVE-2021-38783HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.02

    There is a Out-of-Bound Write in the Allwinner R818 SoC Android Q SDK V1.0 camera driver "/dev/cedar_dev" through iotcl cmd IOCTL_SET_PROC_INFO and IOCTL_COPY_PROC_INFO, which could cause a system crash or EoP.

  • CVE-2021-33965HigJan 18, 2022
    risk 0.57cvss 8.8epss 0.03

    China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the parameter mesh_enable and mesh_device have a command injection vulnerability. An attacker can use the vulnerability to execute remote…

  • CVE-2021-45394HigJan 18, 2022
    risk 0.50cvss 8.8epss 0.02

    An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious tag in the converted HTML document.

  • CVE-2021-33964HigJan 18, 2022
    risk 0.57cvss 8.8epss 0.03

    China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives parameters by POST request, and the parameter firewall_level has a command injection vulnerability. An attacker can use the vulnerability to execute remote…

  • CVE-2022-0242HigJan 17, 2022
    risk 0.40cvss 7.2epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.

  • CVE-2021-38965HigJan 17, 2022
    risk 0.57cvss 8.8epss 0.02

    IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 212346.

  • CVE-2022-0258HigJan 17, 2022
    risk 0.50cvss 8.8epss 0.02

    pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

  • CVE-2022-0240HigJan 17, 2022
    risk 0.00cvss 7.5epss 0.01

    mruby is vulnerable to NULL Pointer Dereference

  • CVE-2021-4164HigJan 17, 2022
    risk 0.50cvss 8.8epss 0.01

    calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-25036HigJan 17, 2022
    risk 0.50cvss 8.8epss 0.03

    The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered during an internal audit by the Jetpack Scan team, and may grant bad actors access to protected REST API endpoints they shouldn’t have access to. This could…

  • CVE-2022-0180HigJan 17, 2022
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker to hijack the authentication of administrators and conduct arbitrary operations via a specially crafted web page.

  • CVE-2021-44537HigJan 15, 2022
    risk 0.51cvss 7.8epss 0.03

    ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.

  • CVE-2021-33828HigJan 15, 2022
    risk 0.57cvss 8.8epss 0.01

    The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection.

  • CVE-2021-33827HigJan 15, 2022
    risk 0.47cvss 7.2epss 0.02

    The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.

  • CVE-2021-42555HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 26.2 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.

  • CVE-2021-35969HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 26 allows temporary remote Denial of Service (abort) because of missing call-setup input validation.

  • CVE-2021-33499HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 2 of 2).

  • CVE-2021-33498HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 26 allows remote denial of service because of missing H.264 input validation (issue 1 of 2).

  • CVE-2021-32545HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 26 allows remote denial of service because of missing RTMP input validation.

  • CVE-2022-23095HigJan 15, 2022
    risk 0.51cvss 7.8epss 0.01

    Open Design Alliance Drawings SDK before 2022.12.1 mishandles the loading of JPG files. Unchecked input data from a crafted JPG file leads to memory corruption. An attacker can leverage this vulnerability to execute code in the context of the current process.

  • CVE-2021-44049HigJan 15, 2022
    risk 0.51cvss 7.8epss 0.00

    CyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Procmon64.exe in the user's Temp directory.

  • CVE-2022-23094HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.03

    Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.

  • CVE-2021-46170HigJan 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in JerryScript commit a6ab5e9. There is an Use-After-Free in lexer_compare_identifier_to_string in js-lexer.c file.

  • CVE-2022-22531HigJan 14, 2022
    risk 0.53cvss 8.1epss 0.01

    The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to run arbitrary script code, resulting in sensitive information being disclosed…

  • CVE-2022-22530HigJan 14, 2022
    risk 0.53cvss 8.1epss 0.01

    The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to inject dangerous content or malicious code which could result in critical…

  • CVE-2022-21137HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.09

    Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allow an attacker to execute arbitrary code.

  • CVE-2022-0130HigJan 14, 2022
    risk 0.53cvss 8.1epss 0.02

    Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated attacker to execute code under special circumstances. An attacker would first have to stage a specific file type in the web server…

  • CVE-2021-46020HigJan 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An untrusted pointer dereference in mrb_vm_exec() of mruby v3.0.0 can lead to a segmentation fault or application crash.

  • CVE-2021-45773HigJan 14, 2022
    risk 0.49cvss 7.5epss 0.01

    A NULL pointer dereference in CS104_IPAddress_setFromString at src/iec60870/cs104/cs104_slave.c of lib60870 commit 0d5e76e can lead to a segmentation fault or application crash.

  • CVE-2021-45769HigJan 14, 2022
    risk 0.49cvss 7.5epss 0.01

    A NULL pointer dereference in AcseConnection_parseMessage at src/mms/iso_acse/acse.c of libiec61850 v1.5.0 can lead to a segmentation fault or application crash.

  • CVE-2021-45406HigJan 14, 2022
    risk 0.57cvss 8.8epss 0.02

    In SalonERP 3.0.1, a SQL injection vulnerability allows an attacker to inject payload using 'sql' parameter in SQL query while generating a report. Upon successfully discovering the login admin password hash, it can be decrypted to obtain the plain-text password.

  • CVE-2021-45068HigJan 14, 2022
    risk 0.52cvss 7.8epss 0.12

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2021-45064HigJan 14, 2022
    risk 0.52cvss 7.8epss 0.12

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current…

  • CVE-2021-45062HigJan 14, 2022
    risk 0.52cvss 7.8epss 0.17

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current…

  • CVE-2021-45061HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.08

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2021-45060HigJan 14, 2022
    risk 0.51cvss 7.8epss 0.09

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An…