VYPR

CVEs

101,977 total · page 1229 of 2,040

  • CVE-2021-43587HigDec 21, 2021
    risk 0.53cvss 8.2epss 0.00

    Dell PowerPath Management Appliance, versions 3.2, 3.1, 3.0 P01, 3.0, and 2.6, use hard-coded cryptographic key. A local high-privileged malicious user may potentially exploit this vulnerability to gain access to secrets and elevate to gain higher privileges.

  • CVE-2021-24981HigDec 21, 2021
    risk 0.49cvss 7.5epss 0.01

    The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leading to arbitrary PHP shell uploads in the wp-content/plugins directory.

  • CVE-2021-24846HigDec 21, 2021
    risk 0.57cvss 8.8epss 0.01

    The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_ajax AJAX action, available to all authenticated users, does not properly sanitise the sort parameter before using it in a SQL statement, leading to an SQL…

  • CVE-2021-24750HigDec 21, 2021
    risk 0.56cvss 8.8epss 0.38

    The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

  • CVE-2021-24739HigDec 21, 2021
    risk 0.53cvss 8.1epss 0.01

    The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arbitrary private posts made by other users via the Carousel Duplication feature

  • CVE-2021-45451HigDec 21, 2021
    risk 0.49cvss 7.5epss 0.01

    In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.

  • CVE-2021-45450HigDec 21, 2021
    risk 0.49cvss 7.5epss 0.01

    In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.

  • CVE-2021-43844HigDec 20, 2021
    risk 0.57cvss 8.8epss 0.03

    MSEdgeRedirect is a tool to redirect news, search, widgets, weather, and more to a user's default browser. MSEdgeRedirect versions before 0.5.0.1 are vulnerable to Remote Code Execution via specifically crafted URLs. This vulnerability requires user interaction and the…

  • CVE-2021-3860HigDec 20, 2021
    risk 0.57cvss 8.8epss 0.01

    JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged authenticated user due to incomplete validation when performing an SQL query.

  • CVE-2021-44181HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.03

    Adobe Dimension versions 3.4.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious GIF…

  • CVE-2021-44180HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.03

    Adobe Dimension versions 3.4.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious GIF…

  • CVE-2021-44179HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.03

    Adobe Dimension versions 3.4.3 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious GIF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-43747HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-43029HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-43028HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-43026HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-43025HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious SVG file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-43024HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-43023HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious EPS/TIFF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit…

  • CVE-2021-43022HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious PNG file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-43021HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious EXR file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-42138HigDec 20, 2021
    risk 0.47cvss 7.2epss 0.01

    A user of a machine protected by SafeNet Agent for Windows Logon may leverage weak entropy to access the encrypted credentials of any or all the users on that machine.

  • CVE-2021-40784HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-40783HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Premiere Rush version 1.5.16 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-38421HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.01

    Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an out-of-bounds read, which may allow an attacker to read sensitive information from other memory locations or cause a crash.

  • CVE-2021-38419HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.01

    Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an out-of-bounds write, which can result in data corruption, a system crash, or code execution.

  • CVE-2021-38415HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.01

    Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable a heap-based buffer overflow when parsing a specially crafted project file, which may allow an attacker to execute arbitrary code.

  • CVE-2021-38413HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.01

    Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to a stack-based buffer overflow, which may allow an attacker to achieve code execution.

  • CVE-2021-38409HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.01

    Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an access of uninitialized pointer, which may allow an attacker read from or write to unexpected memory locations, leading to a denial-of-service.

  • CVE-2021-38401HigDec 20, 2021
    risk 0.51cvss 7.8epss 0.01

    Fuji Electric V-Server Lite and Tellus Lite V-Simulator prior to v4.0.12.0 is vulnerable to an untrusted pointer dereference, which may allow an attacker to execute arbitrary code and cause the application to crash.

  • CVE-2021-35234HigDec 20, 2021
    risk 0.52cvss 8.0epss 0.03

    Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information.

  • CVE-2021-22057HigDec 20, 2021
    risk 0.57cvss 8.8epss 0.01

    VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify.

  • CVE-2021-22056HigDec 20, 2021
    risk 0.49cvss 7.5epss 0.02

    VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response.

  • CVE-2021-43437HigDec 20, 2021
    risk 0.57cvss 8.8epss 0.01

    In sourcecodetester Engineers Online Portal as of 10-21-21, an attacker can manipulate the Host header as seen by the web application and cause the application to behave in unexpected ways. Very often multiple websites are hosted on the same IP address. This is where the Host…

  • CVE-2020-19316HigDec 20, 2021
    risk 0.50cvss 8.8epss 0.03

    OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.

  • CVE-2021-44224HigDec 20, 2021
    risk 0.60cvss 8.2epss 0.82

    A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server…

  • CVE-2021-41561HigDec 20, 2021
    risk 0.49cvss 7.5epss 0.03

    Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions.

  • CVE-2021-44858HigDec 20, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.

  • CVE-2021-42913HigDec 20, 2021
    risk 0.49cvss 7.5epss 0.02

    The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required.

  • CVE-2021-44162HigDec 20, 2021
    risk 0.49cvss 7.5epss 0.02

    Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbitrary system files without authentication.

  • CVE-2021-4136HigDec 19, 2021
    risk 0.00cvss 7.8epss 0.02

    vim is vulnerable to Heap-based Buffer Overflow

  • CVE-2021-45041HigDec 19, 2021
    risk 0.57cvss 8.8epss 0.02

    SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.

  • CVE-2021-43083HigDec 19, 2021
    risk 0.57cvss 8.8epss 0.02

    Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit this vulnerability, a user would have to…

  • CVE-2021-4131HigDec 18, 2021
    risk 0.50cvss 8.8epss 0.01

    livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-4130HigDec 18, 2021
    risk 0.50cvss 8.8epss 0.00

    snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-41500HigDec 17, 2021
    risk 0.42cvss 7.5epss 0.01

    Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.

  • CVE-2021-41499HigDec 17, 2021
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow Vulnerability exists in ajaxsoundstudio.com n Pyo < 1.03 in the Server_debug function, which allows remote attackers to conduct DoS attacks by deliberately passing on an overlong audio file name.

  • CVE-2021-41498HigDec 17, 2021
    risk 0.42cvss 7.5epss 0.01

    Buffer overflow in ajaxsoundstudio.com Pyo &lt and 1.03 in the Server_jack_init function. which allows attackers to conduct Denial of Service attacks by arbitrary constructing a overlong server name.

  • CVE-2021-41497HigDec 17, 2021
    risk 0.49cvss 7.5epss 0.01

    Null pointer reference in CMS_Conservative_increment_obj in RaRe-Technologies bounter version 1.01 and 1.10, allows attackers to conduct Denial of Service attacks by inputting a huge width of hash bucket.

  • CVE-2021-23797HigDec 17, 2021
    risk 0.49cvss 7.5epss 0.02

    All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is.