VYPR

CVEs

101,988 total · page 1223 of 2,040

  • CVE-2021-44466HigDec 30, 2021
    risk 0.47cvss 7.3epss 0.00

    Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software is installed with a non-default installation directory off of the system root, the installer fails to properly set ACLs. This allows lower privileged users to…

  • CVE-2021-20175HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By default, all communication to/from the device's SOAP Interface (port 5000) is sent via HTTP, which causes potentially sensitive information (such as usernames and…

  • CVE-2021-20174HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default, all communication to/from the device's web interface is sent via HTTP, which causes potentially sensitive information (such as usernames and passwords) to be…

  • CVE-2021-20173HigDec 30, 2021
    risk 0.57cvss 8.8epss 0.03

    Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the device. By triggering a system update check via the SOAP interface, the device is susceptible to command injection via preconfigured values.

  • CVE-2021-20172HigDec 30, 2021
    risk 0.51cvss 7.8epss 0.00

    All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The installer of the macOS version of Netgear Genie handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which the…

  • CVE-2021-20170HigDec 30, 2021
    risk 0.57cvss 8.8epss 0.01

    Netgear RAX43 version 1.0.3.96 makes use of hardcoded credentials. It does not appear that normal users are intended to be able to manipulate configuration backups due to the fact that they are encrypted. This encryption is accomplished via a password-protected zip file with a…

  • CVE-2021-20167HigDec 30, 2021
    risk 0.53cvss 8.0epss 0.09

    Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable to command injection in the name parameter.

  • CVE-2021-20166HigDec 30, 2021
    risk 0.57cvss 8.8epss 0.02

    Netgear RAX43 version 1.0.3.96 contains a buffer overrun vulnerability. The URL parsing functionality in the cgi-bin endpoint of the router containers a buffer overrun issue that can redirection control flow of the applicaiton.

  • CVE-2021-20165HigDec 30, 2021
    risk 0.57cvss 8.8epss 0.01

    Trendnet AC2600 TEW-827DRU version 2.08B01 does not properly implement csrf protections. Most pages lack proper usage of CSRF protections or mitigations. Additionally, pages that do make use of CSRF tokens are trivially bypassable as the server does not appear to validate them…

  • CVE-2021-20160HigDec 30, 2021
    risk 0.57cvss 8.8epss 0.03

    Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the device. The username parameter used when configuring smb functionality for the device is vulnerable to command injection as root.

  • CVE-2021-20159HigDec 30, 2021
    risk 0.57cvss 8.8epss 0.03

    Trendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to command injection. The system log functionality of the firmware allows for command injection as root by supplying a malformed parameter.

  • CVE-2021-20157HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.02

    It is possible for an unauthenticated, malicious user to force the device to reboot due to a hidden administrative command.

  • CVE-2021-20154HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Trendnet AC2600 TEW-827DRU version 2.08B01 contains an security flaw in the web interface. HTTPS is not enabled on the device by default. This results in cleartext transmission of sensitive information such as passwords.

  • CVE-2021-20134HigDec 30, 2021
    risk 0.55cvss 8.4epss 0.08

    Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vulnerability that allows a remote, authenticated attacker to set an arbitrary file on the router's filesystem as the log file used by either Quagga service (zebra…

  • CVE-2021-20132HigDec 30, 2021
    risk 0.58cvss 8.8epss 0.04

    Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 use default hard-coded credentials, which can allow a remote attacker to gain administrative access to the zebra or ripd those services. Both are running with root privileges on the router (i.e., as the…

  • CVE-2021-45379HigDec 30, 2021
    risk 0.00cvss 8.8epss 0.01

    Glewlwyd 2.0.0, fixed in 2.6.1 is affected by an incorrect access control vulnerability. One user can attempt to log in as another user without its password.

  • CVE-2021-43861HigDec 30, 2021
    risk 0.40cvss 7.2epss 0.01

    Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Prior to version 8.13.8, malicious diagrams can run javascript code at diagram readers' machines. Users should upgrade…

  • CVE-2021-4188HigDec 30, 2021
    risk 0.00cvss 7.5epss 0.01

    mruby is vulnerable to NULL Pointer Dereference

  • CVE-2021-43876HigDec 29, 2021
    risk 0.57cvss 8.8epss 0.02

    Microsoft SharePoint Elevation of Privilege Vulnerability

  • CVE-2021-4187HigDec 29, 2021
    risk 0.00cvss 7.8epss 0.02

    vim is vulnerable to Use After Free

  • CVE-2021-45885HigDec 29, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific update-migration scenario, the first SSH password change does not properly clear the old password.

  • CVE-2021-23727HigDec 29, 2021
    risk 0.42cvss 7.5epss 0.04

    This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata…

  • CVE-2021-36722HigDec 29, 2021
    risk 0.46cvss 7.1epss 0.01

    Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing…

  • CVE-2021-38688HigDec 29, 2021
    risk 0.46cvss 7.1epss 0.01

    An improper authentication vulnerability has been reported to affect Android App Qfile. If exploited, this vulnerability allows attackers to compromise app and access information We have already fixed this vulnerability in the following versions of Qfile: Qfile 3.0.0.1105 and…

  • CVE-2021-38687HigDec 29, 2021
    risk 0.53cvss 8.1epss 0.01

    A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Surveillance Station: QTS…

  • CVE-2021-35034HigDec 29, 2021
    risk 0.48cvss 7.4epss 0.01

    An insufficient session expiration vulnerability in the CGI program of the Zyxel NBG6604 firmware could allow a remote attacker to access the device if the correct token can be intercepted.

  • CVE-2021-44161HigDec 29, 2021
    risk 0.57cvss 8.8epss 0.01

    Changing MOTP (Mobile One Time Password) system’s specific function parameter has insufficient validation for user input. A attacker in local area network can perform SQL injection attack to read, modify or delete backend database without authentication.

  • CVE-2021-44160HigDec 29, 2021
    risk 0.48cvss 7.3epss 0.01

    Carinal Tien Hospital Health Report System’s login page has improper authentication, a remote attacker can acquire another general user’s privilege by modifying the cookie parameter without authentication. The attacker can then perform limited operations on the system or…

  • CVE-2020-22061HigDec 28, 2021
    risk 0.51cvss 7.8epss 0.00

    SUPERAntispyware v8.0.0.1050 was discovered to contain an issue in the component saskutil64.sys. This issue allows attackers to arbitrarily write data to the device via IOCTL 0x9C402140.

  • CVE-2021-43556HigDec 28, 2021
    risk 0.51cvss 7.8epss 0.02

    FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code.

  • CVE-2021-43554HigDec 28, 2021
    risk 0.51cvss 7.8epss 0.02

    FATEK WinProladder Versions 3.30_24518 and prior are vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

  • CVE-2021-42583HigDec 28, 2021
    risk 0.49cvss 7.5epss 0.01

    A Broken or Risky Cryptographic Algorithm exists in Max Mazurov Maddy before 0.5.2, which is an unnecessary risk that may result in the exposure of sensitive information.

  • CVE-2018-17875HigDec 28, 2021
    risk 0.57cvss 8.8epss 0.03

    A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands via unspecified vectors.

  • CVE-2021-20873HigDec 28, 2021
    risk 0.53cvss 8.1epss 0.01

    Yappli is an application development platform which provides the function to access a requested URL using Custom URL Scheme. When Android apps are developed with Yappli versions since v7.3.6 and prior to v9.30.0, they are vulnerable to improper authorization in Custom URL Scheme…

  • CVE-2021-45911HigDec 28, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow in the main function. It allows an attacker to write 2 bytes outside the boundaries of the buffer.

  • CVE-2021-45910HigDec 28, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an attacker to write data outside of the allocated buffer. The attacker has control over a part of the address that data is written to, control over the written…

  • CVE-2021-45909HigDec 28, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow vulnerability in the DecodeLZW function. It allows an attacker to write a large amount of arbitrary data outside the boundaries of a buffer.

  • CVE-2021-45908HigDec 28, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a while loop. An attacker has little influence over the data written to the stack, making it unlikely that the flow of control can be subverted.

  • CVE-2021-45907HigDec 28, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a for loop. An attacker has little influence over the data written to the stack, making it unlikely that the flow of control can be subverted.

  • CVE-2020-21236HigDec 27, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in /damicms-master/admin.php?s=/Article/doedit of DamiCMS v6.0 allows attackers to compromise and impersonate user accounts via obtaining a user's session cookie.

  • CVE-2021-45896HigDec 27, 2021
    risk 0.57cvss 8.8epss 0.02

    Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of Import Config File.

  • CVE-2021-45884HigDec 27, 2021
    risk 0.00cvss 7.5epss 0.03

    In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fallback are enabled, additional DNS requests are issued outside of the proxying extension using the system's DNS settings, resulting in information disclosure.…

  • CVE-2021-43858HigDec 27, 2021
    risk 0.03cvss 8.8epss 0.35

    MinIO is a Kubernetes native application for cloud storage. Prior to version `RELEASE.2021-12-27T07-23-18Z`, a malicious client can hand-craft an HTTP API call that allows for updating policy for a user and gaining higher privileges. The patch in version…

  • CVE-2020-20948HigDec 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable.

  • CVE-2020-20945HigDec 27, 2021
    risk 0.57cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to arbitrarily add administrator accounts.

  • CVE-2021-33017HigDec 27, 2021
    risk 0.53cvss 8.1epss 0.00

    The standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) requires authentication, but the product has an alternate path or channel that does not require authentication.

  • CVE-2021-32993HigDec 27, 2021
    risk 0.53cvss 8.1epss 0.00

    IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

  • CVE-2021-23244HigDec 27, 2021
    risk 0.51cvss 7.8epss 0.01

    ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But some apps in whitelist is not installed, attacker can disguise app with the same package name to obtain dangerous permission.

  • CVE-2021-21751HigDec 27, 2021
    risk 0.53cvss 8.1epss 0.01

    ZTE BigVideo analysis product has an input verification vulnerability. Due to the inconsistency between the front and back verifications when configuring the large screen page, an attacker with high privileges could exploit this vulnerability to tamper with the URL and cause…

  • CVE-2021-21750HigDec 27, 2021
    risk 0.51cvss 7.8epss 0.00

    ZTE BigVideo Analysis product has a privilege escalation vulnerability. Due to improper management of the timed task modification privilege, an attacker with ordinary user permissions could exploit this vulnerability to gain unauthorized access.