VYPR

CVEs

101,977 total · page 1230 of 2,040

  • CVE-2021-23450HigDec 17, 2021
    risk 0.51cvss 7.5epss 0.30

    All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.

  • CVE-2021-4011HigDec 17, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2021-4010HigDec 17, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2021-4009HigDec 17, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreatePointerBarrier function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2021-4008HigDec 17, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2021-40853HigDec 17, 2021
    risk 0.47cvss 7.2epss 0.01

    TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could exploit this vulnerability to access URL that require privileges without having them. The exploitation of this vulnerability might allow a remote attacker to…

  • CVE-2021-40851HigDec 17, 2021
    risk 0.49cvss 7.5epss 0.01

    TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. The exploitation of this vulnerability might allow a remote attacker to obtain information.

  • CVE-2021-32499HigDec 17, 2021
    risk 0.49cvss 7.5epss 0.01

    SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the command line arguments to pass in any value to the Emulator executable.

  • CVE-2021-32498HigDec 17, 2021
    risk 0.56cvss 8.6epss 0.01

    SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the pathname of the emulator and use path traversal to run an arbitrary executable located on the host system. When the user starts the emulator from SOPAS ET the corresponding executable will be started instead…

  • CVE-2021-32497HigDec 17, 2021
    risk 0.56cvss 8.6epss 0.01

    SICK SOPAS ET before version 4.8.0 allows attackers to wrap any executable file into an SDD and provide this to a SOPAS ET user. When a user starts the emulator the executable is run without further checks.

  • CVE-2021-22054HigKEVDec 17, 2021
    risk 0.69cvss 7.5epss 0.98

    VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without…

  • CVE-2021-20608HigDec 17, 2021
    risk 0.49cvss 7.5epss 0.03

    Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior allows a remote unauthenticated attacker to cause a DoS condition in GX Works2 by getting GX Works2 to read a tampered program file from a Mitsubishi…

  • CVE-2021-0673HigDec 17, 2021
    risk 0.51cvss 7.8epss 0.01

    In Audio Aurisys HAL, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05977326; Issue ID:…

  • CVE-2020-8968HigDec 17, 2021
    risk 0.46cvss 7.1epss 0.00

    Parallels Remote Application Server (RAS) allows a local attacker to retrieve certain profile password in clear text format by uploading a previously stored cyphered file by Parallels RAS. The confidentiality, availability and integrity of the information of the user could be…

  • CVE-2020-18081HigDec 17, 2021
    risk 0.49cvss 7.5epss 0.01

    The checkuser function of SEMCMS 3.8 was discovered to contain a vulnerability which allows attackers to obtain the password in plaintext through a SQL query.

  • CVE-2020-18077HigDec 17, 2021
    risk 0.49cvss 7.5epss 0.01

    A buffer overflow vulnerability in the Virtual Path Mapping component of FTPShell v6.83 allows attackers to cause a denial of service (DoS).

  • CVE-2021-41451HigDec 17, 2021
    risk 0.49cvss 7.5epss 0.02

    A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unauthenticated attacker to send a specially crafted HTTP request and receive a misconfigured HTTP/0.9 response, potentially leading into a cache poisoning attack.

  • CVE-2021-36780HigDec 17, 2021
    risk 0.53cvss 8.1epss 0.00

    A Missing Authentication for Critical Function vulnerability in longhorn of SUSE Longhorn allows attackers to connect to a longhorn-engine replica instance granting it the ability to read and write data to and from a replica that they should not have access to. This issue…

  • CVE-2020-35214HigDec 16, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue in Atomix v3.1.5 allows a malicious Atomix node to remove states of ONOS storage via abuse of primitive operations.

  • CVE-2020-35213HigDec 16, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node.

  • CVE-2020-35211HigDec 16, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to become the lead node in a target cluster via manipulation of the variable terms in RaftContext.

  • CVE-2020-35209HigDec 16, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to join a target cluster via providing configuration information.

  • CVE-2021-44315HigDec 16, 2021
    risk 0.49cvss 7.5epss 0.02

    In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or server.

  • CVE-2021-43837HigDec 16, 2021
    risk 0.48cvss 8.4epss 0.05

    vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli features the ability for rendering templated values. When a secret starts with the prefix `!template!`, vault-cli interprets the rest…

  • CVE-2021-41262HigDec 16, 2021
    risk 0.00cvss 8.8epss 0.01

    Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to SQL injection attacks by users with "member" privilege. Users are advised to upgrade to version 0.9.6 as soon as possible. There…

  • CVE-2021-41261HigDec 16, 2021
    risk 0.00cvss 8.1epss 0.01

    Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 are subject to stored cross site scripting attacks via the preferences footer. The preference footer can only be altered by a site admin. This…

  • CVE-2021-41028HigDec 16, 2021
    risk 0.53cvss 8.2epss 0.00

    A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0.1 and below, 6.4.6 and…

  • CVE-2021-38244HigDec 16, 2021
    risk 0.00cvss 7.5epss 0.01

    A regular expression denial of service (ReDoS) vulnerability exits in cbioportal 3.6.21 and older via a POST request to /ProteinArraySignificanceTest.json.

  • CVE-2021-37262HigDec 16, 2021
    risk 0.49cvss 7.5epss 0.01

    JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.

  • CVE-2021-41260HigDec 16, 2021
    risk 0.00cvss 8.2epss 0.00

    Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions prior to 0.9.6 do not check for Cross Site Request Forgery attacks. All users are advised to upgrade to 0.9.6 as soon as possible. There are no known…

  • CVE-2021-42912HigDec 16, 2021
    risk 0.58cvss 8.8epss 0.11

    FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and…

  • CVE-2021-3960HigDec 16, 2021
    risk 0.46cvss 7.1epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects Bitdefender GravityZone versions prior…

  • CVE-2021-45102HigDec 16, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon using a SciToken, a user may be granted authorizations beyond what the token should allow.

  • CVE-2021-45101HigDec 16, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in HTCondor before 8.8.15, 9.0.x before 9.0.4, and 9.1.x before 9.1.2. Using standard command-line tools, a user with only READ access to an HTCondor SchedD or Collector daemon can discover secrets that could allow them to control other users' jobs and/or…

  • CVE-2021-45100HigDec 16, 2021
    risk 0.00cvss 7.5epss 0.01

    The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it sets the SMB2_GLOBAL_CAP_ENCRYPTION flag when using the SMB 3.1.1 protocol, which is a violation of the…

  • CVE-2021-45099HigDec 16, 2021
    risk 0.57cvss 8.8epss 0.01

    The addon.stdin service in addon-ssh (aka Home Assistant Community Add-on: SSH & Web Terminal) before 10.0.0 has an attack surface that requires social engineering. NOTE: the vendor does not agree that this is a vulnerability; however, addon.stdin was removed as a…

  • CVE-2021-45098HigDec 16, 2021
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an RST TCP packet with random TCP options of the md5header from the client side. After the three-way handshake, it's possible to inject an RST ACK with a random…

  • CVE-2021-44023HigDec 16, 2021
    risk 0.46cvss 7.1epss 0.00

    A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abuse the PC Health Checkup feature of the product to create symlinks that would allow modification of files which could lead to a…

  • CVE-2021-43833HigDec 16, 2021
    risk 0.53cvss 8.1epss 0.01

    eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows any authenticated user to gain access to arbitrary accounts by setting a specially crafted email address. This vulnerability impacts all instances…

  • CVE-2021-45017HigDec 15, 2021
    risk 0.57cvss 8.8epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on the website that uses a google editor; you can specify the menu url address as your malicious url address in the Add Menu column.

  • CVE-2021-45078HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.01

    stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix…

  • CVE-2021-43836HigDec 15, 2021
    risk 0.48cvss 8.5epss 0.02

    Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions an attacker can read arbitrary local files via a PHP file include. In a default configuration this also leads to remote code execution. The problem is patched with the…

  • CVE-2021-43835HigDec 15, 2021
    risk 0.40cvss 7.2epss 0.01

    Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions Sulu users who have access to any subset of the admin UI are able to elevate their privilege. Over the API it was possible for them to give themselves permissions to areas…

  • CVE-2021-43831HigDec 15, 2021
    risk 0.43cvss 7.7epss 0.04

    Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5.0 there is a vulnerability that affects anyone who creates and publicly shares Gradio interfaces. File paths are not restricted and users who receive a Gradio…

  • CVE-2021-43806HigDec 15, 2021
    risk 0.57cvss 8.8epss 0.02

    Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly user settings when constructing the SQL query to browse and search commits in the CVS repositories. A authenticated…

  • CVE-2021-27859HigDec 15, 2021
    risk 0.57cvss 8.8epss 0.02

    A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows an authenticated, remote attacker with read-only privileges to create an account with administrative privileges.…

  • CVE-2021-27857HigDec 15, 2021
    risk 0.49cvss 7.5epss 0.02

    A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, unauthenticated attacker to download a configuration archive. The attacker needs to know or correctly…

  • CVE-2021-27855HigDec 15, 2021
    risk 0.57cvss 8.8epss 0.02

    FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, authenticated attacker with read-only privileges to grant themselves administrative privileges. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory…

  • CVE-2021-43935HigDec 15, 2021
    risk 0.53cvss 8.1epss 0.01

    The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password,…

  • CVE-2021-39653HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    In (TBD) of (TBD), there is a possible way to boot with a hidden debug policy due to a missing warning to the user. This could lead to local escalation of privilege after preparing the device, hiding the warning, and passing the phone to a new user, with no additional execution…