VYPR

CVEs

101,988 total · page 1217 of 2,040

  • CVE-2022-0198HigJan 13, 2022
    risk 0.39cvss 7.1epss 0.01

    corenlp is vulnerable to Improper Restriction of XML External Entity Reference

  • CVE-2022-0197HigJan 13, 2022
    risk 0.00cvss 8.8epss 0.01

    phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2022-0196HigJan 13, 2022
    risk 0.00cvss 8.8epss 0.01

    phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-43860HigJan 12, 2022
    risk 0.00cvss 8.2epss 0.01

    Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the…

  • CVE-2022-23118HigJan 12, 2022
    risk 0.57cvss 8.8epss 0.02

    Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-specified path on the controller, allowing attackers able to control agent processes to invoke arbitrary OS commands on the controller.

  • CVE-2022-23117HigJan 12, 2022
    risk 0.00cvss 7.5epss 0.01

    Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller.

  • CVE-2022-23116HigJan 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to decrypt secrets stored in Jenkins obtained through another method.

  • CVE-2022-23107HigJan 12, 2022
    risk 0.00cvss 8.1epss 0.02

    Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with Item/Configure permission to write and read specific files with a hard-coded suffix on the Jenkins controller file system.

  • CVE-2022-20619HigJan 12, 2022
    risk 0.39cvss 7.1epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials…

  • CVE-2022-20617HigJan 12, 2022
    risk 0.50cvss 8.8epss 0.02

    Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM…

  • CVE-2021-42559HigJan 12, 2022
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is…

  • CVE-2021-41597HigJan 12, 2022
    risk 0.57cvss 8.8epss 0.01

    SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.

  • CVE-2022-21676HigJan 12, 2022
    risk 0.42cvss 7.5epss 0.03

    Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process. This impacts all the…

  • CVE-2021-42562HigJan 12, 2022
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users having access to read and modify configuration or other components that should only be accessible by admin users.

  • CVE-2021-42561HigJan 12, 2022
    risk 0.59cvss 8.8epss 0.20

    An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a python "os.system" function. This allows attackers to use shell metacharacters (e.g., backticks "``" or dollar parenthesis "$()" ) in order to escape the current…

  • CVE-2021-42560HigJan 12, 2022
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG documents are parsed in an unsafe manner and can be leveraged for XXE attacks (e.g., File Exfiltration, Server Side Request Forgery,…

  • CVE-2021-36417HigJan 12, 2022
    risk 0.51cvss 7.8epss 0.01

    A heap-based buffer overflow vulnerability exists in GPAC v1.0.1 in the gf_isom_dovi_config_get function in MP4Box, which causes a denial of service or execute arbitrary code via a crafted file.

  • CVE-2022-0015HigJan 12, 2022
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authenticated local user to execute programs with elevated privileges. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex…

  • CVE-2021-45445HigJan 12, 2022
    risk 0.49cvss 7.5epss 0.01

    Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop.

  • CVE-2021-44652HigJan 12, 2022
    risk 0.51cvss 7.8epss 0.03

    Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.

  • CVE-2021-44651HigJan 12, 2022
    risk 0.58cvss 8.8epss 0.05

    Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.

  • CVE-2021-4080HigJan 12, 2022
    risk 0.50cvss 8.8epss 0.01

    crater is vulnerable to Unrestricted Upload of File with Dangerous Type

  • CVE-2021-44650HigJan 12, 2022
    risk 0.47cvss 7.2epss 0.05

    Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.

  • CVE-2021-44648HigJan 12, 2022
    risk 0.57cvss 8.8epss 0.02

    GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

  • CVE-2021-3852HigJan 12, 2022
    risk 0.00cvss 7.5epss 0.01

    growi is vulnerable to Authorization Bypass Through User-Controlled Key

  • CVE-2022-21646HigJan 11, 2022
    risk 0.46cvss 8.1epss 0.01

    SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard relationship under the right hand branch of an `exclusion` or within an `intersection` operation will see `Lookup`/`LookupResources` return a resource as…

  • CVE-2021-43999HigJan 11, 2022
    risk 0.57cvss 8.8epss 0.02

    Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML support is enabled, this may allow a malicious user to assume the identity of another Guacamole user.

  • CVE-2022-21932HigJan 11, 2022
    risk 0.49cvss 7.6epss 0.01

    Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability

  • CVE-2022-21922HigJan 11, 2022
    risk 0.57cvss 8.8epss 0.03

    Remote Procedure Call Runtime Remote Code Execution Vulnerability

  • CVE-2022-21920HigJan 11, 2022
    risk 0.57cvss 8.8epss 0.03

    Windows Kerberos Elevation of Privilege Vulnerability

  • CVE-2022-21919HigKEVJan 11, 2022
    risk 0.58cvss 7.0epss 0.03

    Windows User Profile Service Elevation of Privilege Vulnerability

  • CVE-2022-21917HigJan 11, 2022
    risk 0.51cvss 7.8epss 0.04

    HEVC Video Extensions Remote Code Execution Vulnerability

  • CVE-2022-21916HigJan 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2022-21914HigJan 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

  • CVE-2022-21912HigJan 11, 2022
    risk 0.51cvss 7.8epss 0.01

    DirectX Graphics Kernel Remote Code Execution Vulnerability

  • CVE-2022-21911HigJan 11, 2022
    risk 0.49cvss 7.5epss 0.03

    .NET Framework Denial of Service Vulnerability

  • CVE-2022-21910HigJan 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Microsoft Cluster Port Driver Elevation of Privilege Vulnerability

  • CVE-2022-21908HigJan 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2022-21904HigJan 11, 2022
    risk 0.49cvss 7.5epss 0.04

    Windows GDI Information Disclosure Vulnerability

  • CVE-2022-21903HigJan 11, 2022
    risk 0.46cvss 7.0epss 0.01

    Windows GDI Elevation of Privilege Vulnerability

  • CVE-2022-21902HigJan 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows DWM Core Library Elevation of Privilege Vulnerability

  • CVE-2022-21898HigJan 11, 2022
    risk 0.51cvss 7.8epss 0.02

    DirectX Graphics Kernel Remote Code Execution Vulnerability

  • CVE-2022-21897HigJan 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2022-21896HigJan 11, 2022
    risk 0.46cvss 7.0epss 0.01

    Windows DWM Core Library Elevation of Privilege Vulnerability

  • CVE-2022-21895HigJan 11, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows User Profile Service Elevation of Privilege Vulnerability

  • CVE-2022-21893HigJan 11, 2022
    risk 0.53cvss 8.0epss 0.07

    Remote Desktop Protocol Remote Code Execution Vulnerability

  • CVE-2022-21891HigJan 11, 2022
    risk 0.50cvss 7.6epss 0.02

    Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability

  • CVE-2022-21890HigJan 11, 2022
    risk 0.49cvss 7.5epss 0.03

    Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability

  • CVE-2022-21889HigJan 11, 2022
    risk 0.49cvss 7.5epss 0.03

    Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability

  • CVE-2022-21888HigJan 11, 2022
    risk 0.51cvss 7.8epss 0.03

    Windows Modern Execution Server Remote Code Execution Vulnerability