VYPR

CVEs

101,988 total · page 1220 of 2,040

  • CVE-2021-40027HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The bone voice ID TA has a vulnerability in calculating the buffer length,Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-40026HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a Heap-based buffer overflow vulnerability in the AOD module in smartphones. Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2021-40025HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The eID module has a vulnerability that causes the memory to be used without being initialized,Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-40022HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The weaver module has a vulnerability in parameter type verification,Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-40021HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The eID module has an out-of-bounds memory write vulnerability,Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-40020HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is an Out-of-bounds array read vulnerability in the security storage module in smartphones. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-40018HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The eID module has a null pointer reference vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-40014HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The bone voice ID trusted application (TA) has a heap overflow vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-40011HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is an uncontrolled resource consumption vulnerability in the display module. Successful exploitation of this vulnerability may affect integrity.

  • CVE-2021-40005HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The distributed data service component has a vulnerability in data access control. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-40004HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The cellular module has a vulnerability in permission management. Successful exploitation of this vulnerability may affect data confidentiality.

  • CVE-2021-40002HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.00

    The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.

  • CVE-2021-40000HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.00

    The Bluetooth module has an out-of-bounds write vulnerability. Successful exploitation of this vulnerability may result in malicious command execution at the remote end.

  • CVE-2021-39998HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    There is Vulnerability of APIs being concurrently called for multiple times in HwConnectivityExService a in smartphones. Successful exploitation of this vulnerability may cause the system to crash and restart.

  • CVE-2021-38990HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.00

    IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the mount command which could lead to code execution. IBM X-Force ID: 212952.

  • CVE-2021-38957HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 could disclose sensitive information due to hazardous input validation during QR code generation. IBM X-Force ID: 212040.

  • CVE-2021-38921HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify 10.0.0, 10.0.1.0, and 10.0.2.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 210067.

  • CVE-2021-34087HigJan 10, 2022
    risk 0.46cvss 7.1epss 0.01

    In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver can be used for clickjacking. This includes the settings page.

  • CVE-2021-34086HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.01

    In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver hosts APIs vulnerable to CSRF. They do not verify incoming requests.

  • CVE-2021-32998HigJan 10, 2022
    risk 0.48cvss 7.4epss 0.01

    The FANUC R-30iA and R-30iB series controllers are vulnerable to an out-of-bounds write, which may allow an attacker to remotely execute arbitrary code. INIT START/restore from backup required.

  • CVE-2021-32996HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.01

    The FANUC R-30iA and R-30iB series controllers are vulnerable to integer coercion errors, which cause the device to crash. A restart is required.

  • CVE-2021-30360HigJan 10, 2022
    risk 0.51cvss 7.8epss 0.01

    Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE in the repair folder which runs with the Check Point Remote…

  • CVE-2021-23568HigJan 10, 2022
    risk 0.41cvss 7.3epss 0.01

    The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.

  • CVE-2021-22569HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.02

    An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause…

  • CVE-2021-20048HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.02

    A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware…

  • CVE-2021-20046HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.02

    A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (DoS) and potentially results in code execution in the firewall. This vulnerability affected SonicOS Gen 5, Gen 6 and Gen 7 firmware…

  • CVE-2020-9058HigJan 10, 2022
    risk 0.53cvss 8.1epss 0.00

    Z-Wave devices based on Silicon Labs 500 series chipsets using CRC-16 encapsulation, including but likely not limited to the Linear LB60Z-1 version 3.5, Dome DM501 version 4.26, and Jasco ZW4201 version 4.05, do not implement encryption or replay protection.

  • CVE-2020-9057HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.00

    Z-Wave devices based on Silicon Labs 100, 200, and 300 series chipsets do not support encryption, allowing an attacker within radio range to take control of or cause a denial of service to a vulnerable device. An attacker can also capture and replay Z-Wave traffic. Firmware…

  • CVE-2020-29050HigJan 10, 2022
    risk 0.49cvss 7.5epss 0.02

    SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc directory). NOTE: this is…

  • CVE-2022-21664HigJan 6, 2022
    risk 0.41cvss 7.4epss 0.04

    WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version…

  • CVE-2022-21662HigJan 6, 2022
    risk 0.50cvss 8.0epss 0.64

    WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-privileged authenticated users (like author) in WordPress core are able to execute JavaScript/perform stored XSS attack, which can affect high-privileged users.…

  • CVE-2022-21661HigJan 6, 2022
    risk 0.56cvss 8.0epss 0.98

    WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugins or themes that use it in a certain way. This has been…

  • CVE-2021-43045HigJan 6, 2022
    risk 0.00cvss 7.5epss 0.03

    A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to version 1.11.0…

  • CVE-2022-0128HigJan 6, 2022
    risk 0.00cvss 7.8epss 0.02

    vim is vulnerable to Out-of-bounds Read

  • CVE-2021-46079HigJan 6, 2022
    risk 0.47cvss 7.2epss 0.03

    An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious files leading to Html Injection.

  • CVE-2021-46075HigJan 6, 2022
    risk 0.47cvss 7.2epss 0.03

    A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access the admin resources and perform CRUD Operations.

  • CVE-2021-46076HigJan 6, 2022
    risk 0.57cvss 8.8epss 0.03

    Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in multiple endpoints it leading to Code Execution.

  • CVE-2021-45458HigJan 6, 2022
    risk 0.00cvss 7.5epss 0.02

    Apache Kylin provides encryption classes PasswordPlaceholderConfigurer to help users encrypt their passwords. In the encryption algorithm used by this encryption class, the cipher is initialized with a hardcoded key and IV. If users use class PasswordPlaceholderConfigurer to…

  • CVE-2021-45457HigJan 6, 2022
    risk 0.00cvss 7.5epss 0.02

    In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.

  • CVE-2021-44878HigJan 6, 2022
    risk 0.42cvss 7.5epss 0.01

    If an OpenID Connect provider supports the "none" algorithm (i.e., tokens with no signature), pac4j v5.3.0 (and prior) does not refuse it without an explicit configuration on its side or for the "idtoken" response type which is not secure and violates the OpenID Core…

  • CVE-2021-27738HigJan 6, 2022
    risk 0.00cvss 7.5epss 0.03

    All request mappings in `StreamingCoordinatorController.java` handling `/kylin/api/streaming_coordinator/*` REST API endpoints did not include any security checks, which allowed an unauthenticated user to issue arbitrary requests, such as assigning/unassigning of streaming…

  • CVE-2021-44564HigJan 6, 2022
    risk 0.53cvss 8.1epss 0.01

    A security vulnerability originally reported in the SYNC2101 product, and applicable to specific sub-families of SYNC devices, allows an attacker to download the configuration file used in the device and apply a modified configuration file back to the device. The attack requires…

  • CVE-2021-44351HigJan 6, 2022
    risk 0.49cvss 7.5epss 0.02

    An arbitrary file read vulnerability exists in NavigateCMS 2.9 via /navigate/navigate_download.php id parameter.

  • CVE-2021-46143HigJan 6, 2022
    risk 0.00cvss 8.1epss 0.04

    In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.

  • CVE-2022-0121HigJan 6, 2022
    risk 0.00cvss 8.0epss 0.01

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoppscotch hoppscotch/hoppscotch.This issue affects hoppscotch/hoppscotch before 2.1.1.

  • CVE-2021-43947HigJan 6, 2022
    risk 0.47cvss 7.2epss 0.04

    Affected versions of Atlassian Jira Server and Data Center allow remote attackers with administrator privileges to execute arbitrary code via a Remote Code Execution (RCE) vulnerability in the Email Templates feature. This issue bypasses the fix of…

  • CVE-2021-45971HigJan 6, 2022
    risk 0.53cvss 8.2epss 0.00

    An issue was discovered in SdHostDriver in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler…

  • CVE-2021-45970HigJan 5, 2022
    risk 0.53cvss 8.2epss 0.00

    An issue was discovered in IdeBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler that…

  • CVE-2021-45969HigJan 5, 2022
    risk 0.53cvss 8.2epss 0.00

    An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler…

  • CVE-2020-5956HigJan 5, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in SdLegacySmm in Insyde InsydeH2O with kernel 5.1 before 05.15.11, 5.2 before 05.25.11, 5.3 before 05.34.11, and 5.4 before 05.42.11. The software SMI handler allows untrusted external input because it does not verify CommBuffer.