VYPR

CVEs

101,988 total · page 1219 of 2,040

  • CVE-2021-45034HigJan 11, 2022
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20).…

  • CVE-2021-45033HigJan 11, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (All versions < V16.20), CP-8021 MASTER MODULE (All versions < V16.20), CP-8022 MASTER MODULE WITH GPRS (All versions < V16.20). An…

  • CVE-2021-41769HigJan 11, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SIPROTEC 5 6MD85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MD86 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MD89 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6MU85 devices (CPU…

  • CVE-2021-37198HigJan 11, 2022
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS uses…

  • CVE-2021-37197HigJan 11, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.4 (All versions < V10.4.1 only if web components are used). The COMOS Web component of COMOS is…

  • CVE-2022-0144HigJan 11, 2022
    risk 0.39cvss 7.1epss 0.00

    shelljs is vulnerable to Improper Privilege Management

  • CVE-2021-36414HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.01

    A heab-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via media.c, which allows attackers to cause a denial of service or execute arbitrary code via a crafted file.

  • CVE-2021-36412HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.01

    A heap-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via the gp_rtp_builder_do_mpeg12_video function, which allows attackers to possibly have unspecified other impact via a crafted file in the MP4Box command,

  • CVE-2021-36409HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.01

    There is an Assertion `scaling_list_pred_matrix_id_delta==1' failed at sps.cc:925 in libde265 v1.0.8 when decoding file, which allows attackers to cause a Denial of Service (DoS) by running the application with a crafted file or possibly have unspecified other impact.

  • CVE-2022-21668HigJan 10, 2022
    risk 0.45cvss 8.0epss 0.04

    pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside a comment anywhere within a requirements.txt file, which…

  • CVE-2022-21666HigJan 10, 2022
    risk 0.00cvss 7.2epss 0.01

    Useful Simple Open-Source CMS (USOC) is a content management system (CMS) for programmers. Versions prior to Pb2.4Bfx3 allowed Sql injection in usersearch.php only for users with administrative privileges. Users should replace the file `admin/pages/useredit.php` with a newer…

  • CVE-2021-29454HigJan 10, 2022
    risk 0.46cvss 8.1epss 0.02

    Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run arbitrary PHP code by crafting a malicious math string. If a math string was passed through as user…

  • CVE-2021-21408HigJan 10, 2022
    risk 0.50cvss 8.8epss 0.02

    Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.43 and 4.0.3, template authors could run restricted static php methods. Users should upgrade to version 3.1.43 or 4.0.3 to receive a patch.

  • CVE-2020-28679HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.03

    A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.

  • CVE-2022-22121HigJan 10, 2022
    risk 0.00cvss 8.0epss 0.01

    In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula Injection). A low privileged attacker can create a new table to inject payloads in the table rows. When an administrator accesses the User Management endpoint and exports the data as a…

  • CVE-2021-44458HigJan 10, 2022
    risk 0.54cvss 8.3epss 0.00

    Linux users running Lens 5.2.6 and earlier could be compromised by visiting a malicious website. The malicious website could make websocket connections from the victim's browser to Lens and so operate the local terminal feature. This would allow the attacker to execute arbitrary…

  • CVE-2021-25054HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.01

    The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection vulnerability.

  • CVE-2021-25053HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.01

    The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

  • CVE-2021-25052HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.03

    The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

  • CVE-2021-25051HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.01

    The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.

  • CVE-2021-24948HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.02

    The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action, which could allow unauthenticated users to retrieve sensitive information, such as private and draft posts

  • CVE-2021-24862HigJan 10, 2022
    risk 0.56cvss 7.2epss 0.73

    The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue

  • CVE-2021-44586HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in dst-admin v1.3.0. The product has an unauthorized arbitrary file download vulnerability that can expose sensitive information.

  • CVE-2022-22846HigJan 10, 2022
    risk 0.42cvss 7.5epss 0.01

    The dnslib package through 0.9.16 for Python does not verify that the ID value in a DNS reply matches an ID value in a query.

  • CVE-2022-22827HigJan 10, 2022
    risk 0.00cvss 8.8epss 0.03

    storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

  • CVE-2022-22826HigJan 10, 2022
    risk 0.00cvss 8.8epss 0.03

    nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

  • CVE-2022-22825HigJan 10, 2022
    risk 0.00cvss 8.8epss 0.03

    lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

  • CVE-2022-22288HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.

  • CVE-2022-22264HigJan 10, 2022
    risk 0.50cvss 7.7epss 0.00

    Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local attackers to read and write arbitrary files without permission.

  • CVE-2022-21667HigJan 10, 2022
    risk 0.42cvss 7.5epss 0.02

    soketi is an open-source WebSockets server. There is an unhandled case when reading POST requests which results in the server crashing if it could not read the body of a request. In the event that a POST request is sent to any endpoint of the server with an empty body, even…

  • CVE-2022-0133HigJan 10, 2022
    risk 0.00cvss 7.5epss 0.01

    peertube is vulnerable to Improper Access Control

  • CVE-2022-0132HigJan 10, 2022
    risk 0.00cvss 7.5epss 0.01

    peertube is vulnerable to Server-Side Request Forgery (SSRF)

  • CVE-2021-46165HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.00

    Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined.

  • CVE-2021-46164HigJan 10, 2022
    risk 0.58cvss 8.8epss 0.07

    Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module.

  • CVE-2021-46149HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A denial of service (resource consumption) can be accomplished by searching for a very long key in a Language Name Search.

  • CVE-2021-46147HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. MassEditRegex allows CSRF.

  • CVE-2021-45856HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.02

    Accu-Time Systems MAXIMUS 1.0 telnet service suffers from a remote buffer overflow which causes the telnet service to crash

  • CVE-2021-45442HigJan 10, 2022
    risk 0.46cvss 7.1epss 0.00

    A link following denial-of-service vulnerability in Trend Micro Worry-Free Business Security (on prem only) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. This is similar to, but not the same as CVE-2021-44024. Please note: an attacker must…

  • CVE-2021-45441HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.00

    A origin validation error vulnerability in Trend Micro Apex One (on-prem and SaaS) could allow a local attacker drop and manipulate a specially crafted file to issue commands over a certain pipe and elevate to a higher level of privileges. Please note: an attacker must first…

  • CVE-2021-45440HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.00

    A unnecessary privilege vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security 10.0 SP1 (on-prem versions only) could allow a local attacker to abuse an impersonation privilege and elevate to a higher level of privileges. Please note: an attacker must…

  • CVE-2021-45231HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.01

    A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to create a specially crafted file with arbitrary content which could grant local…

  • CVE-2021-44024HigJan 10, 2022
    risk 0.46cvss 7.1epss 0.00

    A link following denial-of-service vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. Please note: an attacker must…

  • CVE-2021-43579HigJan 10, 2022
    risk 0.04cvss 7.8epss 0.07

    A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim converts an HTML document linking to a crafted BMP file.

  • CVE-2021-40039HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2021-40038HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a Double free vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2021-40035HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a Buffer overflow vulnerability due to a boundary error with the Samba server in the file management module in smartphones. Successful exploitation of this vulnerability may affect function stability.

  • CVE-2021-40032HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The bone voice ID TA has a vulnerability in information management,Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-40031HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2021-40029HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a Buffer overflow vulnerability due to a boundary error with the Samba server in the file management module in smartphones. Successful exploitation of this vulnerability may affect function stability.

  • CVE-2021-40028HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The eID module has an out-of-bounds memory write vulnerability,Successful exploitation of this vulnerability may affect data integrity.