VYPR

CVEs

101,977 total · page 1234 of 2,040

  • CVE-2021-44006HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll contains an out of bounds write past the end of an allocated structure while parsing specially crafted TIFF files. This could allow…

  • CVE-2021-44005HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The Tiff_Loader.dll contains an out of bounds write past the end of an allocated structure while parsing specially crafted TIFF files. This could allow…

  • CVE-2021-44002HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.02

    A vulnerability has been identified in JT Open (All versions < V11.1.1.0), JT Utilities (All versions < V13.1.1.0), Solid Edge (All versions < V2023). The Jt1001.dll contains an out of bounds write past the end of an allocated structure while parsing specially crafted JT files.…

  • CVE-2021-44001HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.02

    A vulnerability has been identified in JT2Go (All versions < V13.2.0.5), Teamcenter Visualization (All versions < V13.2.0.5). The DL180pdfl.dll contains an out of bounds write past the end of an allocated structure while parsing specially crafted PDF files. This could allow an…

  • CVE-2021-42027HigDec 14, 2021
    risk 0.48cvss 7.4epss 0.00

    A vulnerability has been identified in SINUMERIK Edge (All versions < V3.2). The affected software does not properly validate the server certificate when initiating a TLS connection. This could allow an attacker to spoof a trusted entity by interfering in the communication path…

  • CVE-2021-42024HigDec 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < 2021.3.1). The starview+.exe application lacks proper validation of user-supplied data when parsing scene files. This could result in an out of bounds write past the end of an allocated structure.…

  • CVE-2021-41547HigDec 14, 2021
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been identified in Teamcenter Active Workspace V4.3 (All versions < V4.3.11), Teamcenter Active Workspace V5.0 (All versions < V5.0.10), Teamcenter Active Workspace V5.1 (All versions < V5.1.6), Teamcenter Active Workspace V5.2 (All versions < V5.2.3). The…

  • CVE-2021-41272HigDec 13, 2021
    risk 0.00cvss 7.5epss 0.01

    Besu is an Ethereum client written in Java. Starting in version 21.10.0, changes in the implementation of the SHL, SHR, and SAR operations resulted in the introduction of a signed type coercion error in values that represent negative values for 32 bit signed integers. Smart…

  • CVE-2021-43822HigDec 13, 2021
    risk 0.48cvss 8.5epss 0.01

    Jackalope Doctrine-DBAL is an implementation of the PHP Content Repository API (PHPCR) using a relational database to persist data. In affected versions users can provoke SQL injections if they can specify a node name or query. Upgrade to version 1.7.4 to resolve this issue. If…

  • CVE-2021-43817HigDec 13, 2021
    risk 0.53cvss 8.2epss 0.01

    Collabora Online is a collaborative online office suite based on LibreOffice technology. In affected versions a reflected XSS vulnerability was found in Collabora Online. An attacker could inject unescaped HTML into a variable as they created the Collabora Online iframe, and…

  • CVE-2021-43814HigDec 13, 2021
    risk 0.00cvss 7.7epss 0.01

    Rizin is a UNIX-like reverse engineering framework and command-line toolset. In versions up to and including 0.3.1 there is a heap-based out of bounds write in parse_die() when reversing an AMD64 ELF binary with DWARF debug info. When a malicious AMD64 ELF binary is opened by a…

  • CVE-2021-43801HigDec 13, 2021
    risk 0.00cvss 7.5epss 0.02

    Mercurius is a GraphQL adapter for Fastify. Any users from Mercurius@8.10.0 to 8.11.1 are subjected to a denial of service attack by sending a malformed JSON to `/graphql` unless they are using a custom error handler. The vulnerability has been fixed in…

  • CVE-2021-39057HigDec 13, 2021
    risk 0.53cvss 8.1epss 0.00

    IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force…

  • CVE-2021-39050HigDec 13, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM i2 Analyst's Notebook 9.2.0, 9.2.1, and 9.2.2 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges. IBM X-Force ID: 214440.

  • CVE-2021-39049HigDec 13, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM i2 Analyst's Notebook 9.2.0, 9.2.1, and 9.2.2 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local attacker could overflow a buffer and gain lower level privileges. IBM X-Force ID: 214439.

  • CVE-2021-43818HigDec 13, 2021
    risk 0.46cvss 8.2epss 0.02

    lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a…

  • CVE-2021-39064HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Copy Data Management 2.2.13 and earlier has weak authentication and password rules and incorrectly handles default credentials for the Spectrum Copy Data Management Admin console. IBM X-Force ID: 214957.

  • CVE-2021-39058HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 214617.

  • CVE-2021-39053HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to obtain sensitive information, caused by the improper handling of requests for Spectrum Copy Data Management Admin Console. By sending a specially-crafted request, a remote attacker could…

  • CVE-2021-38947HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Spectrum Copy Data Management 2.2.13 and earlier uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 211242.

  • CVE-2020-16156HigDec 13, 2021
    risk 0.51cvss 7.8epss 0.01

    CPAN 2.28 allows Signature Verification Bypass.

  • CVE-2020-16154HigDec 13, 2021
    risk 0.51cvss 7.8epss 0.01

    The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.

  • CVE-2021-43983HigDec 13, 2021
    risk 0.51cvss 7.8epss 0.03

    WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to multiple stack-based buffer overflow instances while parsing project files, which may allow an attacker to execute arbitrary code.

  • CVE-2021-40008HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a memory leak vulnerability in CloudEngine 12800 V200R019C00SPC800, CloudEngine 5800 V200R019C00SPC800, CloudEngine 6800 V200R019C00SPC800 and CloudEngine 7800 V200R019C00SPC800. The software does not sufficiently track and release allocated memory while parse a series…

  • CVE-2021-39944HigDec 13, 2021
    risk 0.46cvss 7.1epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to…

  • CVE-2021-44965HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in /admin/includes/* directory for PHPGURUKUL Employee Record Management System 1.2 The attacker can retrieve and download sensitive information from the vulnerable server.

  • CVE-2021-24970HigDec 13, 2021
    risk 0.47cvss 7.2epss 0.06

    The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue

  • CVE-2021-24945HigDec 13, 2021
    risk 0.52cvss 8.0epss 0.01

    The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked…

  • CVE-2021-24861HigDec 13, 2021
    risk 0.47cvss 7.2epss 0.01

    The Quotes Collection WordPress plugin through 2.5.2 does not validate and escape the bulkcheck parameter before using it in a SQL statement, leading to a SQL injection

  • CVE-2021-24848HigDec 13, 2021
    risk 0.57cvss 8.8epss 0.01

    The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection

  • CVE-2021-24747HigDec 13, 2021
    risk 0.47cvss 7.2epss 0.01

    The SEO Booster WordPress plugin before 3.8 allows for authenticated SQL injection via the "fn_my_ajaxified_dataloader_ajax" AJAX request as the $_REQUEST['order'][0]['dir'] parameter is not properly escaped leading to blind and error-based SQL injections.

  • CVE-2021-20865HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.02

    Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may allow a user to browse unauthorized data via unspecified vectors.

  • CVE-2021-44154HigDec 13, 2021
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered in Reprise RLM 14.2. By using an admin account, an attacker can write a payload to /goform/edit_opt, which will then be triggered when running the diagnostics (via /goform/diagnostics_doit), resulting in a buffer overflow.

  • CVE-2021-44153HigDec 13, 2021
    risk 0.47cvss 7.2epss 0.02

    An issue was discovered in Reprise RLM 14.2. When editing the license file, it is possible for an admin user to enable an option to run arbitrary executables, as demonstrated by an ISV demo "C:\Windows\System32\calc.exe" entry. An attacker can exploit this to run a malicious…

  • CVE-2021-44151HigDec 13, 2021
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in Reprise RLM 14.2. As the session cookies are small, an attacker can hijack any existing sessions by bruteforcing the 4 hex-character session cookie on the Windows version (the Linux version appears to have 8 characters). An attacker can obtain the…

  • CVE-2021-40857HigDec 13, 2021
    risk 0.57cvss 8.8epss 0.02

    Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.

  • CVE-2021-40856HigDec 13, 2021
    risk 0.53cvss 7.5epss 0.51

    Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.

  • CVE-2018-25021HigDec 13, 2021
    risk 0.00cvss 7.5epss 0.02

    The TCP Server module in toxcore before 0.2.8 doesn't free the TCP priority queue under certain conditions, which allows a remote attacker to exhaust the system's memory, causing a denial of service (DoS).

  • CVE-2021-41805HigDec 12, 2021
    risk 0.60cvss 8.8epss 0.35

    HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.

  • CVE-2021-41242HigDec 10, 2021
    risk 0.00cvss 8.1epss 0.01

    OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providing a filename that contains a relative path as a parameter in some REST methods, it is possible to create directory structures and…

  • CVE-2021-26340HigDec 10, 2021
    risk 0.55cvss 8.4epss 0.00

    A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM).

  • CVE-2021-23463HigDec 10, 2021
    risk 0.46cvss 8.1epss 0.03

    The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource()…

  • CVE-2021-27984HigDec 10, 2021
    risk 0.53cvss 8.1epss 0.03

    In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.

  • CVE-2021-31745HigDec 10, 2021
    risk 0.49cvss 7.5epss 0.01

    Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular…

  • CVE-2021-37935HigDec 10, 2021
    risk 0.49cvss 7.5epss 0.01

    An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login…

  • CVE-2021-29214HigDec 10, 2021
    risk 0.47cvss 7.2epss 0.01

    A security vulnerability has been identified in HPE StoreServ Management Console (SSMC). An authenticated SSMC administrator could exploit the vulnerability to inject code and elevate their privilege in SSMC. The scope of this vulnerability is limited to SSMC. Note: The arrays…

  • CVE-2021-37189HigDec 10, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.

  • CVE-2021-37188HigDec 10, 2021
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firmware (because the bootloader does not verify that it is authentic), changing the behavior of the gateway.

  • CVE-2021-43803HigDec 10, 2021
    risk 0.45cvss 7.5epss 0.45

    Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to a server crash. In order to be affected by this issue, the deployment must use Next.js versions above 11.1.0 and below 12.0.5, Node.js above 15.0.0, and next…

  • CVE-2021-43982HigDec 9, 2021
    risk 0.51cvss 7.8epss 0.10

    Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.