VYPR

CVEs

101,988 total · page 1221 of 2,040

  • CVE-2021-43816HigJan 5, 2022
    risk 0.45cvss 8.0epss 0.02

    containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod scheduled to the node may bind mount,…

  • CVE-2021-38918HigJan 5, 2022
    risk 0.49cvss 7.5epss 0.01

    IBM PowerVM Hypervisor FW860, FW940, FW950, and FW1010, through a specific sequence of VM management operations could lead to a violation of the isolation between peer VMs. IBM X-Force ID: 210019.

  • CVE-2022-22111HigJan 5, 2022
    risk 0.50cvss 8.8epss 0.01

    In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator’s. This allows the attacker to gain access to the…

  • CVE-2022-22110HigJan 5, 2022
    risk 0.42cvss 7.5epss 0.01

    In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his password could change it to a weak password, such as those with a length of a single character. This may allow an attacker to…

  • CVE-2021-45116HigJan 5, 2022
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variable resolution logic, the dictsort template filter was potentially vulnerable to information disclosure, or an unintended method…

  • CVE-2021-45115HigJan 5, 2022
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. UserAttributeSimilarityValidator incurred significant overhead in evaluating a submitted password that was artificially large in relation to the comparison values. In a situation where…

  • CVE-2021-41388HigJan 4, 2022
    risk 0.51cvss 7.8epss 0.00

    Netskope client prior to 89.x on macOS is impacted by a local privilege escalation vulnerability. The XPC implementation of nsAuxiliarySvc process does not perform validation on new connections before accepting the connection. Thus any low privileged user can connect and call…

  • CVE-2021-22045HigJan 4, 2022
    risk 0.51cvss 7.8epss 0.05

    VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device…

  • CVE-2022-21650HigJan 4, 2022
    risk 0.00cvss 7.6epss 0.01

    Convos is an open source multi-user chat that runs in a web browser. You can't use SVG extension in Convos' chat window, but you can upload a file with an .html extension. By uploading an SVG file with an html extension the upload filter can be bypassed. This causes Stored XSS.…

  • CVE-2022-21649HigJan 4, 2022
    risk 0.00cvss 7.6epss 0.01

    Convos is an open source multi-user chat that runs in a web browser. Characters starting with "https://" in the chat window create an tag. Stored XSS vulnerability using onfocus and autofocus occurs because escaping exists for "<" or ">" but escaping for double quotes does…

  • CVE-2022-21648HigJan 4, 2022
    risk 0.46cvss 8.2epss 0.01

    Latte is an open source template engine for PHP. Versions since 2.8.0 Latte has included a template sandbox and in affected versions it has been found that a sandbox escape exists allowing for injection into web pages generated from Latte. This may lead to XSS attacks. The issue…

  • CVE-2022-21647HigJan 4, 2022
    risk 0.46cvss 7.7epss 0.38

    CodeIgniter is an open source PHP full-stack web framework. Deserialization of Untrusted Data was found in the `old()` function in CodeIgniter4. Remote attackers may inject auto-loadable arbitrary objects with this vulnerability, and possibly execute existing PHP code on the…

  • CVE-2021-43852HigJan 4, 2022
    risk 0.50cvss 8.8epss 0.01

    OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an attacker could inject properties into existing JavaScript language construct prototypes, such as objects. Later this injection may lead to JS code execution by…

  • CVE-2021-3845HigJan 4, 2022
    risk 0.00cvss 7.5epss 0.01

    ws-scrcpy is vulnerable to External Control of File Name or Path

  • CVE-2022-20012HigJan 4, 2022
    risk 0.51cvss 7.8epss 0.00

    In mdp driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05836478; Issue ID: ALPS05836478.

  • CVE-2021-45912HigJan 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An unauthenticated Named Pipe channel in Controlup Real-Time Agent (cuAgent.exe) before 8.5 potentially allows an attacker to run OS commands via the ProcessActionRequest WCF method.

  • CVE-2021-40148HigJan 4, 2022
    risk 0.49cvss 7.5epss 0.01

    In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00716585; Issue ID:…

  • CVE-2021-45980HigJan 4, 2022
    risk 0.51cvss 7.8epss 0.02

    Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via getURL in the JavaScript API.

  • CVE-2021-45979HigJan 4, 2022
    risk 0.51cvss 7.8epss 0.02

    Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL in the JavaScript API.

  • CVE-2021-45978HigJan 4, 2022
    risk 0.51cvss 7.8epss 0.01

    Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via xfa.host.gotoURL in the XFA API.

  • CVE-2021-45913HigJan 4, 2022
    risk 0.47cvss 7.2epss 0.01

    A hardcoded key in ControlUp Real-Time Agent (cuAgent.exe) before 8.2.5 may allow a potential attacker to run OS commands via a WCF channel.

  • CVE-2021-3842HigJan 4, 2022
    risk 0.42cvss 7.5epss 0.01

    nltk is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-31833HigJan 4, 2022
    risk 0.46cvss 7.1epss 0.00

    Potential product security bypass vulnerability in McAfee Application and Change Control (MACC) prior to version 8.3.4 allows a locally logged in attacker to circumvent the application solidification protection provided by MACC, permitting them to run applications that would…

  • CVE-2021-40110HigJan 4, 2022
    risk 0.49cvss 7.5epss 0.03

    In Apache James, using Jazzer fuzzer, we identified that an IMAP user can craft IMAP LIST commands to orchestrate a Denial Of Service using a vulnerable Regular expression. This affected Apache James prior to 3.6.1 We recommend upgrading to Apache James 3.6.1 or higher , which…

  • CVE-2021-34797HigJan 4, 2022
    risk 0.49cvss 7.5epss 0.03

    Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "javax.net.ssl", or…

  • CVE-2021-39989HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    The HwNearbyMain module has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability may cause a process to restart.

  • CVE-2021-39988HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    The HwNearbyMain module has a NULL Pointer Dereference vulnerability.Successful exploitation of this vulnerability may cause a process to restart.

  • CVE-2021-39987HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    The HwNearbyMain module has a Data Processing Errors vulnerability.Successful exploitation of this vulnerability may cause a process to restart.

  • CVE-2021-39985HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    The HwNearbyMain module has a Improper Validation of Array Index vulnerability.Successful exploitation of this vulnerability may cause a process to restart.

  • CVE-2021-39984HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    Huawei idap module has a Out-of-bounds Read vulnerability.Successful exploitation of this vulnerability may cause Denial of Service.

  • CVE-2021-39983HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    The HwNearbyMain module has a Data Processing Errors vulnerability.Successful exploitation of this vulnerability may cause a process to restart.

  • CVE-2021-39978HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    Telephony application has a SQL Injection vulnerability.Successful exploitation of this vulnerability may cause privacy and security issues.

  • CVE-2021-39977HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    The HwNearbyMain module has a NULL Pointer Dereference vulnerability.Successful exploitation of this vulnerability may cause a process to restart.

  • CVE-2021-39975HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    Hilinksvc has a Data Processing Errors vulnerability.Successful exploitation of this vulnerability may cause denial of service attacks.

  • CVE-2021-39974HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    There is an Out-of-bounds read in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-39973HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a Null pointer dereference in Smartphones.Successful exploitation of this vulnerability may cause the kernel to break down.

  • CVE-2021-39972HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    MyHuawei-App has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability could compromise confidentiality.

  • CVE-2021-39971HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    Password vault has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability could compromise confidentiality.

  • CVE-2021-39970HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    HwPCAssistant has a Improper Input Validation vulnerability.Successful exploitation of this vulnerability may create any file with the system app permission.

  • CVE-2021-39969HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    There is an Unauthorized file access vulnerability in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-39968HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    Changlian Blocklist has a Business Logic Errors vulnerability .Successful exploitation of this vulnerability may expand the attack surface of the message class.

  • CVE-2021-39967HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a Vulnerability of obtaining broadcast information improperly due to improper broadcast permission settings in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-39966HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    There is an Uninitialized AOD driver structure in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-38576HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.

  • CVE-2021-37134HigJan 3, 2022
    risk 0.53cvss 8.1epss 0.00

    Location-related APIs exists a Race Condition vulnerability.Successful exploitation of this vulnerability may use Higher Permissions for invoking the interface of location-related components.

  • CVE-2021-37133HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    There is an Unauthorized file access vulnerability in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-37126HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Successful exploitation of this vulnerability may cause the directory is traversed.

  • CVE-2021-37125HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Successful exploitation of this vulnerability may cause confidentiality is affected.

  • CVE-2021-37119HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a Service logic vulnerability in Smartphone.Successful exploitation of this vulnerability may cause WLAN DoS.

  • CVE-2021-37117HigJan 3, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a Service logic vulnerability in Smartphone.Successful exploitation of this vulnerability may cause WLAN DoS.