VYPR

CVEs

101,977 total · page 1235 of 2,040

  • CVE-2020-19682HigDec 9, 2021
    risk 0.57cvss 8.8epss 0.01

    A Cross Site Request Forgery (CSRF) vulnerability exits in ZZZCMS V1.7.1 via the save_user funciton in save.php.

  • CVE-2021-41265HigDec 9, 2021
    risk 0.46cvss 8.1epss 0.01

    Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to…

  • CVE-2021-40282HigDec 9, 2021
    risk 0.57cvss 8.8epss 0.01

    An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary users.

  • CVE-2021-40281HigDec 9, 2021
    risk 0.57cvss 8.8epss 0.01

    An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary users.

  • CVE-2021-39002HigDec 9, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

  • CVE-2021-38951HigDec 9, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume all available CPU resources. IBM X-Force ID: 211405.

  • CVE-2021-29678HigDec 9, 2021
    risk 0.57cvss 8.7epss 0.01

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files. IBM X-Force ID: 199914.

  • CVE-2021-22568HigDec 9, 2021
    risk 0.00cvss 8.8epss 0.01

    When using the dart pub publish command to publish a package to a third-party package server, the request would be authenticated with an oauth2 access_token that is valid for publishing on pub.dev. Using these obtained credentials, an attacker can impersonate the user on…

  • CVE-2021-20373HigDec 9, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restrictions. IBM X-Force ID: 199521.

  • CVE-2021-40280HigDec 9, 2021
    risk 0.47cvss 7.2epss 0.01

    An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php.

  • CVE-2021-40279HigDec 9, 2021
    risk 0.47cvss 7.2epss 0.01

    An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php.

  • CVE-2021-21955HigDec 9, 2021
    risk 0.49cvss 7.5epss 0.01

    An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attacker can sniff network traffic to trigger this vulnerability.

  • CVE-2021-20145HigDec 9, 2021
    risk 0.49cvss 7.5epss 0.01

    Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same service. An attacker could leverage this to make…

  • CVE-2021-20144HigDec 9, 2021
    risk 0.57cvss 8.8epss 0.04

    An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted…

  • CVE-2021-20143HigDec 9, 2021
    risk 0.57cvss 8.8epss 0.04

    An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted…

  • CVE-2021-20142HigDec 9, 2021
    risk 0.57cvss 8.8epss 0.04

    An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted…

  • CVE-2021-20141HigDec 9, 2021
    risk 0.57cvss 8.8epss 0.04

    An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted…

  • CVE-2021-20140HigDec 9, 2021
    risk 0.58cvss 8.8epss 0.04

    An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted…

  • CVE-2021-20139HigDec 9, 2021
    risk 0.58cvss 8.8epss 0.04

    An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted…

  • CVE-2021-20138HigDec 9, 2021
    risk 0.57cvss 8.8epss 0.04

    An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web interface at /cgi-bin/luci/rc. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted…

  • CVE-2021-41449HigDec 9, 2021
    risk 0.46cvss 7.1epss 0.02

    A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sending a specially crafted…

  • CVE-2021-43071HigDec 9, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the LogReport API controller.

  • CVE-2021-43065HigDec 9, 2021
    risk 0.51cvss 7.8epss 0.00

    A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, version 8.8.9 and below allows attacker to gain higher privileges via the access to sensitive system data.

  • CVE-2021-36194HigDec 9, 2021
    risk 0.57cvss 8.8epss 0.01

    Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted requests.

  • CVE-2021-43811HigDec 8, 2021
    risk 0.00cvss 7.8epss 0.02

    Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses YAML to store model and data configurations on disk. Versions below 2.3.24 use unsafe YAML loading, which can be made to execute arbitrary code embedded in…

  • CVE-2021-43539HigDec 8, 2021
    risk 0.57cvss 8.8epss 0.02

    Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects…

  • CVE-2021-43537HigDec 8, 2021
    risk 0.57cvss 8.8epss 0.02

    An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

  • CVE-2021-43535HigDec 8, 2021
    risk 0.57cvss 8.8epss 0.01

    A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.

  • CVE-2021-43534HigDec 8, 2021
    risk 0.57cvss 8.8epss 0.01

    Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This…

  • CVE-2021-38510HigDec 8, 2021
    risk 0.57cvss 8.8epss 0.01

    The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects…

  • CVE-2021-38504HigDec 8, 2021
    risk 0.57cvss 8.8epss 0.02

    When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

  • CVE-2021-37941HigDec 8, 2021
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious file to an application running with the APM Java agent. Using this vector, a malicious or compromised user account could use the agent to run commands at a…

  • CVE-2021-23862HigDec 8, 2021
    risk 0.47cvss 7.2epss 0.01

    A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue also affects installations of the VRM, DIVAR IP, BVMS with VRM installed, the VIDEOJET decoder (VJD-7513 and VJD-8000).

  • CVE-2021-21957HigDec 8, 2021
    risk 0.48cvss 7.3epss 0.01

    A privilege escalation vulnerability exists in the Remote Server functionality of Dream Report ODS Remote Connector 20.2.16900.0. A specially-crafted command injection can lead to elevated capabilities. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-36719HigDec 8, 2021
    risk 0.57cvss 8.8epss 0.01

    PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulnerable nicUpload.php file to upload a malicious file,Thus taking over the server and running remote code.

  • CVE-2021-43978HigDec 8, 2021
    risk 0.46cvss 7.1epss 0.01

    Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users to access and modify data using the same credentials.

  • CVE-2021-43399HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.01

    The Yubico YubiHSM YubiHSM2 library 2021.08, included in the yubihsm-shell project, does not properly validate the length of some operations including SSH signing requests, and some data operations received from a YubiHSM 2 device.

  • CVE-2021-41025HigDec 8, 2021
    risk 0.48cvss 7.3epss 0.01

    Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 thorugh 6.0.7, including an instance of concurrent execution using shared resource with improper…

  • CVE-2021-41017HigDec 8, 2021
    risk 0.57cvss 8.8epss 0.02

    Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow a remote authenticated attacker to execute arbitrary code or commands via specifically crafted HTTP requests.

  • CVE-2021-36173HigDec 8, 2021
    risk 0.52cvss 8.0epss 0.01

    A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, and 6.0.0 through 6.0.13 may allow an attacker to execute arbitrary code via specially crafted installation images.

  • CVE-2021-41021HigDec 8, 2021
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability in FortiNAC versions 8.8.8 and below and 9.1.2 and below may allow an admin user to escalate the privileges to root via the sudo command.

  • CVE-2021-42110HigDec 8, 2021
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered in Allegro Windows (formerly Popsy Windows) before 3.3.4156.1. A standard user can escalate privileges to SYSTEM if the FTP module is installed, because of DLL hijacking.

  • CVE-2021-41450HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.02

    An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.

  • CVE-2021-42835HigDec 8, 2021
    risk 0.46cvss 7.0epss 0.01

    An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the attacker to interact…

  • CVE-2021-40861HigDec 8, 2021
    risk 0.47cvss 7.2epss 0.02

    A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbitrary SQL queries via the value attribute, with which all data in the database can be extracted and OS command execution is…

  • CVE-2021-40860HigDec 8, 2021
    risk 0.47cvss 7.2epss 0.02

    A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) before 9.0.013.11 allows an attacker to execute arbitrary SQL queries via the ql_expression parameter, with which all data in the database can be extracted and OS command…

  • CVE-2021-37097HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system restart.

  • CVE-2021-37092HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Incomplete Cleanup vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to availability affected.

  • CVE-2021-37075HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Credentials Management Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to confidentiality affected.

  • CVE-2021-37074HigDec 8, 2021
    risk 0.53cvss 8.1epss 0.01

    There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user root privilege escalation.