VYPR

CVEs

101,988 total · page 1224 of 2,040

  • CVE-2021-43856HigDec 27, 2021
    risk 0.00cvss 8.2epss 0.01

    Wiki.js is a wiki app built on Node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through non-image file uploads for file types that can be viewed directly inline in the browser. By creating a malicious file which can execute inline JS when viewed…

  • CVE-2021-43855HigDec 27, 2021
    risk 0.00cvss 8.2epss 0.01

    Wiki.js is a wiki app built on node.js. Wiki.js 2.5.263 and earlier is vulnerable to stored cross-site scripting through a SVG file upload made via a custom request with a fake MIME type. By creating a crafted SVG file, a malicious Wiki.js user may stage a stored cross-site…

  • CVE-2021-43845HigDec 27, 2021
    risk 0.00cvss 8.2epss 0.04

    PJSIP is a free and open source multimedia communication library. In version 2.11.1 and prior, if incoming RTCP XR message contain block, the data field is not checked against the received packet size, potentially resulting in an out-of-bound read access. This affects all users…

  • CVE-2021-45339HigDec 27, 2021
    risk 0.51cvss 7.8epss 0.00

    Privilege escalation vulnerability in Avast Antivirus prior to 20.4 allows a local user to gain elevated privileges by "hollowing" trusted process which could lead to the bypassing of Avast self-defense.

  • CVE-2021-45338HigDec 27, 2021
    risk 0.51cvss 7.8epss 0.00

    Multiple privilege escalation vulnerabilities in Avast Antivirus prior to 20.4 allow a local user to gain elevated privileges by calling unnecessarily powerful internal methods of the main antivirus service which could lead to the (1) arbitrary file delete, (2) write and (3)…

  • CVE-2021-45337HigDec 27, 2021
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation vulnerability in the Self-Defense driver of Avast Antivirus prior to 20.8 allows a local user with SYSTEM privileges to gain elevated privileges by "hollowing" process wsc_proxy.exe which could lead to acquire antimalware (AM-PPL) protection.

  • CVE-2021-45336HigDec 27, 2021
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation vulnerability in the Sandbox component of Avast Antivirus prior to 20.4 allows a local sandboxed code to gain elevated privileges by using system IPC interfaces which could lead to exit the sandbox and acquire SYSTEM privileges.

  • CVE-2021-45335HigDec 27, 2021
    risk 0.57cvss 8.8epss 0.00

    Sandbox component in Avast Antivirus prior to 20.4 has an insecure permission which could be abused by local user to control the outcome of scans, and therefore evade detection or delete arbitrary system files.

  • CVE-2021-4173HigDec 27, 2021
    risk 0.00cvss 7.8epss 0.02

    vim is vulnerable to Use After Free

  • CVE-2021-24998HigDec 27, 2021
    risk 0.49cvss 7.5epss 0.01

    The Simple JWT Login WordPress plugin before 3.3.0 can be used to create new WordPress user accounts with a randomly generated password. The password is generated using the str_shuffle PHP function that "does not generate cryptographically secure values, and should not be used…

  • CVE-2021-24753HigDec 27, 2021
    risk 0.47cvss 7.2epss 0.01

    The Rich Reviews by Starfish WordPress plugin before 1.9.6 does not properly validate the orderby GET parameter of the pending reviews page before using it in a SQL statement, leading to an authenticated SQL injection issue

  • CVE-2021-45711HigDec 27, 2021
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the simple_asn1 crate 0.6.0 before 0.6.1 for Rust. There is a panic if UTCTime data, supplied by a remote attacker, has a second character greater than 0x7f.

  • CVE-2021-45710HigDec 27, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the tokio crate before 1.8.4, and 1.9.x through 1.13.x before 1.13.1, for Rust. In certain circumstances involving a closed oneshot channel, there is a data race and memory corruption.

  • CVE-2021-45708HigDec 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the abomonation crate through 2021-10-17 for Rust. Because transmute operations are insufficiently constrained, there can be an information leak or ASLR bypass.

  • CVE-2021-45704HigDec 27, 2021
    risk 0.46cvss 8.1epss 0.01

    An issue was discovered in the metrics-util crate before 0.7.0 for Rust. There is a data race and memory corruption because AtomicBucket unconditionally implements the Send and Sync traits.

  • CVE-2021-45702HigDec 27, 2021
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A merge operation may result in a use-after-free.

  • CVE-2021-45700HigDec 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the ckb crate before 0.40.0 for Rust. Attackers can cause a denial of service (Nervos CKB blockchain node crash) via a dead call that is used as a DepGroup.

  • CVE-2021-45699HigDec 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the ckb crate before 0.40.0 for Rust. Remote attackers may be able to conduct a 51% attack against the Nervos CKB blockchain by triggering an inability to allocate memory for the misbehavior HashMap.

  • CVE-2021-45694HigDec 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the rdiff crate through 2021-02-03 for Rust. Window may read from uninitialized memory locations.

  • CVE-2021-45681HigDec 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the derive-com-impl crate before 0.1.2 for Rust. An invalid reference (and memory corruption) can occur because AddRef might not be called before returning a pointer.

  • CVE-2021-45680HigDec 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the vec-const crate before 2.0.0 for Rust. It tries to construct a Vec from a pointer to a const slice, leading to memory corruption.

  • CVE-2020-36511HigDec 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the bite crate through 2020-12-31 for Rust. read::BiteReadExpandedExt::read_framed_max may read from uninitialized memory locations.

  • CVE-2019-25055HigDec 27, 2021
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the libpulse-binding crate before 2.6.0 for Rust. It mishandles a panic that crosses a Foreign Function Interface (FFI) boundary.

  • CVE-2019-25054HigDec 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the pnet crate before 0.27.2 for Rust. There is a segmentation fault (upon attempted dereference of an uninitialized descriptor) because of an erroneous IcmpTransportChannelIterator compiler optimization.

  • CVE-2018-25028HigDec 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the libpulse-binding crate before 1.2.1 for Rust. get_context can cause a use-after-free.

  • CVE-2018-25027HigDec 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the libpulse-binding crate before 1.2.1 for Rust. get_format_info can cause a use-after-free.

  • CVE-2018-25023HigDec 27, 2021
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the smallvec crate before 0.6.13 for Rust. It can create an uninitialized value of any type, including a reference type.

  • CVE-2021-45720HigDec 26, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the lru crate before 0.7.1 for Rust. The iterators have a use-after-free, as demonstrated by an access after a pop operation.

  • CVE-2021-45719HigDec 26, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. update_hook has a use-after-free.

  • CVE-2021-45718HigDec 26, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. rollback_hook has a use-after-free.

  • CVE-2021-45717HigDec 26, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. commit_hook has a use-after-free.

  • CVE-2021-45716HigDec 26, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_collation has a use-after-free.

  • CVE-2021-45715HigDec 26, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_window_function has a use-after-free.

  • CVE-2021-45714HigDec 26, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_aggregate_function has a use-after-free.

  • CVE-2021-45713HigDec 26, 2021
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_scalar_function has a use-after-free.

  • CVE-2021-45712HigDec 26, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the rust-embed crate before 6.3.0 for Rust. A ../ directory traversal can sometimes occur in debug mode.

  • CVE-2021-4168HigDec 26, 2021
    risk 0.50cvss 8.8epss 0.01

    showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-44078HigDec 26, 2021
    risk 0.00cvss 8.1epss 0.01

    An issue was discovered in split_region in uc.c in Unicorn Engine before 2.0.0-rc5. It allows local attackers to escape the sandbox. An attacker must first obtain the ability to execute crafted code in the target sandbox in order to exploit this vulnerability. The specific flaw…

  • CVE-2021-45679HigDec 26, 2021
    risk 0.55cvss 8.4epss 0.01

    Certain NETGEAR devices are affected by privilege escalation. This affects R6900P before 1.3.3.140, R7000 before 1.0.11.126, R7000P before 1.3.3.140, and RS400 before 1.5.1.80.

  • CVE-2021-45661HigDec 26, 2021
    risk 0.46cvss 7.1epss 0.00

    Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RBR50 before 2.5.1.16, RBS50 before…

  • CVE-2021-45660HigDec 26, 2021
    risk 0.46cvss 7.1epss 0.00

    Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RBR50 before 2.5.1.16, RBS50 before…

  • CVE-2021-45659HigDec 26, 2021
    risk 0.46cvss 7.1epss 0.00

    Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RBR50 before 2.5.1.16, RBS50 before…

  • CVE-2021-45658HigDec 26, 2021
    risk 0.46cvss 7.1epss 0.01

    Certain NETGEAR devices are affected by server-side injection. This affects D7800 before 1.0.1.58, DM200 before 1.0.0.66, EX2700 before 1.0.1.56, EX6150v2 before 1.0.1.86, EX6100v2 before 1.0.1.86, EX6200v2 before 1.0.1.78, EX6250 before 1.0.0.110, EX6410 before 1.0.0.110,…

  • CVE-2021-45657HigDec 26, 2021
    risk 0.46cvss 7.1epss 0.00

    Certain NETGEAR devices are affected by server-side injection. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6050 before 1.0.1.26, JR6150 before 1.0.1.26, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6230 before…

  • CVE-2021-45656HigDec 26, 2021
    risk 0.46cvss 7.1epss 0.00

    Certain NETGEAR devices are affected by server-side injection. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6050 before 1.0.1.26, JR6150 before 1.0.1.26, R6120 before 1.0.0.66, R6220 before 1.1.0.100, R6230 before…

  • CVE-2021-45651HigDec 26, 2021
    risk 0.48cvss 7.4epss 0.01

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK50 before 2.7.3.22, RBR50 before 2.7.3.22, and RBS50 before 2.7.3.22.

  • CVE-2021-45649HigDec 26, 2021
    risk 0.51cvss 7.9epss 0.00

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R7000 before 1.0.11.126, R6900P before 1.3.2.126, and R7000P before 1.3.2.126.

  • CVE-2021-45645HigDec 26, 2021
    risk 0.53cvss 8.2epss 0.01

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects RBS50Y before 2.7.0.122, SRK60 before 2.7.0.122, SRR60 before 2.7.0.122, SRS60 before 2.7.0.122, SXK30 before 3.2.33.108, SXR30 before 3.2.33.108, SXS30 before 3.2.33.108, and…

  • CVE-2021-45643HigDec 26, 2021
    risk 0.53cvss 8.2epss 0.00

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6400v2 before 1.0.4.118, R6700v3 before 1.0.4.118, and XR1000 before 1.0.0.58.

  • CVE-2021-45642HigDec 26, 2021
    risk 0.49cvss 7.5epss 0.01

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D7800 before 1.0.1.64, EX6250 before 1.0.0.134, EX7700 before 1.0.0.222, LBR20 before 2.6.3.50, RBS50Y before 2.7.3.22, R8900 before 1.0.5.26, R9000 before 1.0.5.26, XR450 before…