VYPR

CVEs

101,977 total · page 1233 of 2,040

  • CVE-2020-23545HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.54 allows a user-mode write access violation starting at FORMATS!ReadXPM_W+0x0000000000000531.

  • CVE-2019-19138HigDec 15, 2021
    risk 0.49cvss 7.5epss 0.02

    Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity.

  • CVE-2021-43326HigDec 15, 2021
    risk 0.54cvss 7.8epss 0.01

    Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.

  • CVE-2021-43325HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.00

    Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a CVE-2021-43326 regression.

  • CVE-2021-40827HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.01

    Clementine Music Player through 1.3.1 (when a GLib 2.0.0 DLL is used) is vulnerable to a Read Access Violation on Block Data Move, affecting the MP3 file parsing functionality at memcpy+0x265. The vulnerability is triggered when the user opens a crafted MP3 file or loads a…

  • CVE-2021-40826HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.01

    Clementine Music Player through 1.3.1 is vulnerable to a User Mode Write Access Violation, affecting the MP3 file parsing functionality at clementine+0x3aa207. The vulnerability is triggered when the user opens a crafted MP3 file or loads a remote stream URL that is mishandled…

  • CVE-2021-41870HigDec 15, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can bypass a client-side file-type check and upload arbitrary .php files.

  • CVE-2021-4110HigDec 15, 2021
    risk 0.00cvss 7.5epss 0.02

    mruby is vulnerable to NULL Pointer Dereference

  • CVE-2021-43830HigDec 14, 2021
    risk 0.00cvss 7.4epss 0.01

    OpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection in the budgets module. For authenticated users with the "Edit budgets" permission, the request to reassign work packages to another budget unsufficiently…

  • CVE-2021-43829HigDec 14, 2021
    risk 0.05cvss 7.4epss 0.59

    PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.7.7 PatrowlManager unrestrictly handle upload files in the findings import feature. This vulnerability is capable of uploading dangerous type of file to server leading to XSS…

  • CVE-2021-43828HigDec 14, 2021
    risk 0.49cvss 7.5epss 0.01

    PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) has been found in PatrowlManager. All imports findings file is placed under /media/imports/<owner_id>/<tmp_file> In that, owner_id…

  • CVE-2021-43051HigDec 14, 2021
    risk 0.46cvss 7.1epss 0.01

    The Spotfire Server component of TIBCO Software Inc.'s TIBCO Spotfire Server, TIBCO Spotfire Server, and TIBCO Spotfire Server contains a difficult to exploit vulnerability that allows malicious custom API clients with network access to execute internal API operations outside of…

  • CVE-2021-39183HigDec 14, 2021
    risk 0.53cvss 8.2epss 0.01

    Owncast is an open source, self-hosted live video streaming and chat server. In affected versions inline scripts are executed when Javascript is parsed via a paste action. This issue is patched in 0.0.9 by blocking unsafe-inline Content Security Policy and specifying the…

  • CVE-2021-4044HigDec 14, 2021
    risk 0.53cvss 7.5epss 0.50

    Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by…

  • CVE-2021-43820HigDec 14, 2021
    risk 0.00cvss 7.4epss 0.01

    Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize access to library data. To improve performance, the token is cached in memory in seaf-server. Upon receiving a token from sync client or SeaDrive client, the server…

  • CVE-2021-43807HigDec 14, 2021
    risk 0.42cvss 7.5epss 0.01

    Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast versions prior to 9.10 allow HTTP method spoofing, allowing to change the assumed HTTP method via URL parameter. This allows attackers to turn HTTP GET requests into PUT requests or an HTTP…

  • CVE-2021-43388HigDec 14, 2021
    risk 0.49cvss 7.5epss 0.01

    Unisys Cargo Mobile Application before 1.2.29 uses cleartext to store sensitive information, which might be revealed in a backup. The issue is addressed by ensuring that the allowBackup flag (in the manifest) is False.

  • CVE-2021-38950HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when SharedBindingsUserId is set to effective. IBM X-ForceID: 211404.

  • CVE-2021-44549HigDec 14, 2021
    risk 0.48cvss 7.4epss 0.02

    Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "man in the middle" attacks additional server identity checks must be performed when accessing mail servers. For compatibility…

  • CVE-2021-44233HigDec 14, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for an authenticated user, which could lead to escalation of privileges.

  • CVE-2021-44232HigDec 14, 2021
    risk 0.50cvss 7.7epss 0.01

    SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided by normal user, leading to full server directory access. The attacker can see the whole filesystem structure but cannot overwrite, delete, or corrupt arbitrary…

  • CVE-2021-41067HigDec 14, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Listary through 6. Improper implementation of the update process leads to the download of software updates with a /check-update HTTP-based connection. This can be exploited with MITM techniques. Together with the lack of package validation, it can lead…

  • CVE-2021-41066HigDec 14, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Listary through 6. When Listary is configured as admin, Listary will not ask for permissions again if a user tries to access files on the system from Listary itself (it will bypass UAC protection; there is no privilege validation of the current user…

  • CVE-2021-41065HigDec 14, 2021
    risk 0.47cvss 7.3epss 0.01

    An issue was discovered in Listary through 6. An attacker can create a \\.\pipe\Listary.listaryService named pipe and wait for a privileged user to open a session on the Listary installed host. Listary will automatically access the named pipe and the attacker will be able to…

  • CVE-2021-39312HigDec 14, 2021
    risk 0.58cvss 7.5epss 0.78

    The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/resources/examples.php file.

  • CVE-2021-38182HigDec 14, 2021
    risk 0.57cvss 8.8epss 0.01

    Due to insufficient input validation of Kyma, authenticated users can pass a Header of their choice and escalate privileges which can completely compromise the cluster.

  • CVE-2021-4007HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.00

    Rapid7 Insight Agent, versions 3.0.1 to 3.1.2.34, suffer from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent versions 3.0.1 to 3.1.2.34 start, the Python interpreter attempts to load python3.dll at "C:\DLLs\python3.dll,"…

  • CVE-2021-3376HigDec 14, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Cuppa CMS Versions Before 31 Jan 2021 allows authenticated attackers to gain escalated privileges via a crafted POST request using the user_group_id_field parameter.

  • CVE-2021-4104HigDec 14, 2021
    risk 0.55cvss 7.5epss 0.81

    JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests…

  • CVE-2021-44522HigDec 14, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.85 (All versions), Siveillance Identity V1.5 (All versions), Siveillance Identity V1.6 (All versions < V1.6.284.0). Affected applications…

  • CVE-2021-44450HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V12.8.1.1), JTTK (All versions < V10.8.1.1). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing JT files. An attacker could leverage this…

  • CVE-2021-44449HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V12.8.1.1), JTTK (All versions < V10.8.1.1). JTTK library in affected products contains an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an…

  • CVE-2021-44447HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.0.3.0), JTTK (All versions < V11.0.3.0). JTTK library in affected products contains a use-after-free vulnerability that could be triggered while parsing specially crafted JT files. An attacker could leverage…

  • CVE-2021-44446HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.0.3.0), JTTK (All versions < V11.0.3.0). JTTK library in affected products contains an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an…

  • CVE-2021-44445HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted JT files. This could allow…

  • CVE-2021-44443HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products contains an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an…

  • CVE-2021-44442HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted JT files. This could allow…

  • CVE-2021-44441HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products contains an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an…

  • CVE-2021-44440HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to memory corruption condition while parsing specially crafted JT files. An attacker could leverage this vulnerability…

  • CVE-2021-44439HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing specially crafted JT files. An attacker…

  • CVE-2021-44438HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could…

  • CVE-2021-44437HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could…

  • CVE-2021-44435HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to stack based buffer overflow while parsing specially crafted JT files. An attacker could leverage this vulnerability…

  • CVE-2021-44434HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could…

  • CVE-2021-44433HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products contains a use after free vulnerability that could be triggered while parsing specially crafted JT files. An attacker could leverage…

  • CVE-2021-44432HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to stack based buffer overflow while parsing specially crafted JT files. An attacker could leverage this vulnerability…

  • CVE-2021-44430HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could…

  • CVE-2021-44165HigDec 14, 2021
    risk 0.47cvss 7.2epss 0.03

    A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.41), POWER METER SICAM Q100 (All versions < V2.41), POWER METER SICAM Q100 (All versions < V2.41), POWER METER SICAM Q100 (All versions < V2.41). The affected firmware contains a buffer overflow…

  • CVE-2021-44014HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.02

    A vulnerability has been identified in JT Open (All versions < V11.1.1.0), JT Utilities (All versions < V13.1.1.0), Solid Edge (All versions < V2023). The Jt1001.dll contains a use-after-free vulnerability that could be triggered while parsing specially crafted JT files. An…

  • CVE-2021-44013HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.02

    A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The DL180pdfl.dll contains an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an…