VYPR

CVEs

101,988 total · page 1228 of 2,040

  • CVE-2021-4058HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4057HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.02

    Use after free in file API in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4056HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Type confusion in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4055HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in extensions in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

  • CVE-2021-4053HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in UI in Google Chrome on Linux prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-4052HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in web apps in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

  • CVE-2021-38017HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2021-38016HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

  • CVE-2021-38015HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Inappropriate implementation in input in Google Chrome prior to 96.0.4664.45 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

  • CVE-2021-38014HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Out of bounds write in Swiftshader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-38012HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-38011HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-38008HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in media in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-38007HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-38006HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-38005HigDec 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in loader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-20593HigDec 22, 2021
    risk 0.52cvss 8.0epss 0.00

    A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account.

  • CVE-2021-43853HigDec 22, 2021
    risk 0.50cvss 8.7epss 0.01

    Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package are vulnerable to JavaScript object injection which may result in cross site scripting when leveraged by a malicious user. The affected core relates to…

  • CVE-2021-44544HigDec 22, 2021
    risk 0.50cvss 7.5epss 0.09

    DIAEnergie Version 1.7.5 and prior is vulnerable to multiple cross-site scripting vulnerabilities when arbitrary code is injected into the parameter “name” of the script “HandlerEnergyType.ashx”.

  • CVE-2021-44471HigDec 22, 2021
    risk 0.49cvss 7.5epss 0.01

    DIAEnergie Version 1.7.5 and prior is vulnerable to stored cross-site scripting when an unauthenticated user injects arbitrary code into the parameter “name” of the script “DIAE_HandlerAlarmGroup.ashx”.

  • CVE-2021-23228HigDec 22, 2021
    risk 0.49cvss 7.5epss 0.01

    DIAEnergie Version 1.7.5 and prior is vulnerable to a reflected cross-site scripting attack through error pages that are returned by “.NET Request.QueryString”.

  • CVE-2021-21953HigDec 22, 2021
    risk 0.53cvss 8.1epss 0.01

    An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted man-in-the-middle attack can lead to increased privileges.

  • CVE-2021-21936HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.01

    A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘health_alt_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery.

  • CVE-2021-21917HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at '‘ord’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done…

  • CVE-2021-21916HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at 'description_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This…

  • CVE-2021-21915HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.01

    An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This…

  • CVE-2021-21912HigDec 22, 2021
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a…

  • CVE-2021-21911HigDec 22, 2021
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a…

  • CVE-2021-21910HigDec 22, 2021
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a…

  • CVE-2021-21909HigDec 22, 2021
    risk 0.53cvss 8.1epss 0.01

    Specially-crafted command line arguments can lead to arbitrary file deletion in the del .cnt|.log file delete command. An attacker can provide malicious inputs to trigger this vulnerability

  • CVE-2021-21906HigDec 22, 2021
    risk 0.47cvss 7.2epss 0.01

    Stack-based buffer overflow vulnerability exists in how the CMA readfile function of Garrett Metal Detectors iC Module CMA Version 5.0 is used at various locations. The Garrett iC Module exposes an authenticated CLI over TCP port 6877. This interface is used by a secondary GUI…

  • CVE-2021-21905HigDec 22, 2021
    risk 0.47cvss 7.2epss 0.01

    Stack-based buffer overflow vulnerability exists in how the CMA readfile function of Garrett Metal Detectors iC Module CMA Version 5.0 is used at various locations. The Garrett iC Module exposes an authenticated CLI over TCP port 6877. This interface is used by a secondary GUI…

  • CVE-2021-21904HigDec 22, 2021
    risk 0.47cvss 7.2epss 0.03

    A directory traversal vulnerability exists in the CMA CLI setenv command of Garrett Metal Detectors’ iC Module CMA Version 5.0. An attacker can provide malicious input to trigger this vulnerability

  • CVE-2021-21902HigDec 22, 2021
    risk 0.53cvss 8.1epss 0.02

    An authentication bypass vulnerability exists in the CMA run_server_6877 functionality of Garrett Metal Detectors iC Module CMA Version 5.0. A properly-timed network connection can lead to authentication bypass via session hijacking. An attacker can send a sequence of requests…

  • CVE-2021-21901HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.02

    A stack-based buffer overflow vulnerability exists in the CMA check_udp_crc function of Garrett Metal Detectors’ iC Module CMA Version 5.0. A specially-crafted packet can lead to a stack-based buffer overflow during a call to memcpy. An attacker can send a malicious packet to…

  • CVE-2021-21895HigDec 22, 2021
    risk 0.47cvss 7.2epss 0.02

    A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to FsTFtp file overwrite. An attacker can make an authenticated HTTP request to trigger this…

  • CVE-2021-21885HigDec 22, 2021
    risk 0.47cvss 7.2epss 0.02

    A directory traversal vulnerability exists in the Web Manager FsMove functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP request can lead to local file inclusion. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2021-21882HigDec 22, 2021
    risk 0.58cvss 8.8epss 0.06

    An OS command injection vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this…

  • CVE-2021-21880HigDec 22, 2021
    risk 0.47cvss 7.2epss 0.02

    A directory traversal vulnerability exists in the Web Manager FsCopyFile functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to local file inclusion. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2021-21879HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.04

    A directory traversal vulnerability exists in the Web Manager File Upload functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary file overwrite. An attacker can make an authenticated HTTP request to trigger this…

  • CVE-2021-45266HigDec 22, 2021
    risk 0.49cvss 7.5epss 0.01

    A null pointer dereference vulnerability exists in gpac 1.1.0 via the lsr_read_anim_values_ex function, which causes a segmentation fault and application crash.

  • CVE-2021-43804HigDec 22, 2021
    risk 0.00cvss 7.3epss 0.02

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming RTCP BYE message contains a reason's length, this declared length is not…

  • CVE-2021-43630HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.02

    Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticated malicious user can compromise the databases system and in some cases leverage this vulnerability to get remote code execution on…

  • CVE-2021-37706HigDec 22, 2021
    risk 0.00cvss 7.3epss 0.05

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an ERROR-CODE attribute, the header length is not…

  • CVE-2021-45419HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.00

    Certain Starcharge products are affected by Improper Input Validation. The affected products include: Nova 360 Cabinet <= 1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0 and Titan 180 Premium <= 1.3.0.0.6 - Fixed: 1.3.0.0.9.

  • CVE-2021-44733HigDec 22, 2021
    risk 0.00cvss 7.0epss 0.01

    A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.

  • CVE-2021-45418HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.02

    Certain Starcharge products are vulnerable to Directory Traversal via main.cgi. The affected products include: Nova 360 Cabinet <=1.3.0.0.6 - Fixed: 1.3.0.0.9 and Titan 180 Premium <=1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0.

  • CVE-2021-36750HigDec 22, 2021
    risk 0.54cvss 8.1epss 0.14

    ENC DataVault before 7.2 and VaultAPI v67 mishandle key derivation, making it easier for attackers to determine the passwords of all DataVault users (across USB drives sold under multiple brand names).

  • CVE-2021-43851HigDec 22, 2021
    risk 0.00cvss 8.1epss 0.01

    Anuko Time Tracker is an open source, web-based time tracking application written in PHP. SQL injection vulnerability exist in multiple files in Time Tracker version 1.19.33.5606 and prior due to not properly checking of the "group" and "status" parameters in POST requests.…

  • CVE-2021-44860HigDec 21, 2021
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds read vulnerability exists when reading a TIF file using Open Design Alliance Drawings SDK before 2022.12. The specific issue exists after loading TIF files. An unchecked input data from a crafted TIF file leads to an out-of-bounds read. An attacker can leverage…