VYPR

CVEs

101,977 total · page 1239 of 2,040

  • CVE-2020-36131HigDec 2, 2021
    risk 0.57cvss 8.8epss 0.02

    AOM v2.0.1 was discovered to contain a stack buffer overflow via the component stats/rate_hist.c.

  • CVE-2020-36129HigDec 2, 2021
    risk 0.57cvss 8.8epss 0.01

    AOM v2.0.1 was discovered to contain a stack buffer overflow via the component src/aom_image.c.

  • CVE-2021-40334HigDec 2, 2021
    risk 0.56cvss 8.6epss 0.01

    Missing Handler vulnerability in the proprietary management protocol (port TCP 5558) of Hitachi Energy FOX61x, XCM20 allows an attacker that exploits the vulnerability by activating SSH on port TCP 5558 to cause disruption to the NMS and NE communication. This issue affects:…

  • CVE-2021-43795HigDec 2, 2021
    risk 0.42cvss 7.5epss 0.02

    Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local file system beyond its restricted directory by sending an HTTP request whose path contains `%2F` (encoded `/`), such as `/files/..%2Fsecrets.txt`, bypassing…

  • CVE-2021-23264HigDec 2, 2021
    risk 0.46cvss 8.1epss 0.01

    Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.

  • CVE-2021-44227HigDec 2, 2021
    risk 0.57cvss 8.8epss 0.01

    In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.

  • CVE-2021-42711HigDec 1, 2021
    risk 0.51cvss 7.8epss 0.00

    Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. This file is executed with SYSTEM privileges when an unprivileged user performs a repair operation.

  • CVE-2020-35012HigDec 1, 2021
    risk 0.47cvss 7.2epss 0.01

    The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection

  • CVE-2021-43137HigDec 1, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.

  • CVE-2021-41039HigDec 1, 2021
    risk 0.49cvss 7.5epss 0.01

    In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, leading to a loss of performance and possible denial of service.

  • CVE-2021-38575HigDec 1, 2021
    risk 0.53cvss 8.1epss 0.02

    NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.

  • CVE-2021-42776HigDec 1, 2021
    risk 0.50cvss 7.7epss 0.01

    CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import.

  • CVE-2021-20400HigDec 1, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196074.

  • CVE-2021-44480HigDec 1, 2021
    risk 0.53cvss 8.1epss 0.01

    Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen to a device's surroundings via a callback in an SMS command, as demonstrated by the 123456 and 523681 default passwords.

  • CVE-2021-20611HigDec 1, 2021
    risk 0.49cvss 7.5epss 0.03

    Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PCPU, MELSEC iQ-R Series R08/16/32/120PSFCPU, MELSEC iQ-R Series…

  • CVE-2021-20610HigDec 1, 2021
    risk 0.49cvss 7.5epss 0.03

    Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PCPU, MELSEC iQ-R Series…

  • CVE-2021-20609HigDec 1, 2021
    risk 0.49cvss 7.5epss 0.03

    Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PCPU, MELSEC iQ-R Series R08/16/32/120PSFCPU, MELSEC iQ-R…

  • CVE-2020-10627HigDec 1, 2021
    risk 0.47cvss 7.3epss 0.00

    Insulet Omnipod Insulin Management System insulin pump product ID 19191 and 40160 is designed to communicate using a wireless RF with an Insulet manufactured Personal Diabetes Manager device. This wireless RF communication protocol does not properly implement authentication or…

  • CVE-2021-32592HigDec 1, 2021
    risk 0.51cvss 7.8epss 0.00

    An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x may allow an attacker to perform a DLL Hijack attack on affected devices via a malicious OpenSSL engine library in the search…

  • CVE-2021-4017HigDec 1, 2021
    risk 0.50cvss 8.8epss 0.01

    showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-3984HigDec 1, 2021
    risk 0.00cvss 7.8epss 0.01

    vim is vulnerable to Heap-based Buffer Overflow

  • CVE-2021-4019HigDec 1, 2021
    risk 0.51cvss 7.8epss 0.02

    vim is vulnerable to Heap-based Buffer Overflow

  • CVE-2021-34599HigDec 1, 2021
    risk 0.48cvss 7.4epss 0.00

    Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS Git does not implement certificate validation by default, so it does not verify that the server provides a valid and trusted HTTPS certificate. Since the…

  • CVE-2021-20864HigDec 1, 2021
    risk 0.57cvss 8.8epss 0.01

    Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware…

  • CVE-2021-20863HigDec 1, 2021
    risk 0.52cvss 8.0epss 0.01

    OS command injection vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03…

  • CVE-2021-20861HigDec 1, 2021
    risk 0.57cvss 8.8epss 0.00

    Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware…

  • CVE-2021-20860HigDec 1, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior,…

  • CVE-2021-20859HigDec 1, 2021
    risk 0.52cvss 8.0epss 0.01

    ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware…

  • CVE-2021-20851HigDec 1, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a remote unauthenticated attacker to hijack the authentication of an administrator via unspecified vectors.

  • CVE-2021-43360HigDec 1, 2021
    risk 0.57cvss 8.8epss 0.02

    Sunnet eHRD e-mail delivery task schedule’s serialization function has inadequate input object validation and restriction, which allows a post-authenticated remote attacker with database access privilege, to execute arbitrary code and control the system or interrupt services.

  • CVE-2021-43359HigDec 1, 2021
    risk 0.57cvss 8.8epss 0.02

    Sunnet eHRD has broken access control vulnerability, which allows a remote attacker to access account management page after being authenticated as a general user, then perform privilege escalation to execute arbitrary code and control the system or interrupt services.

  • CVE-2021-43358HigDec 1, 2021
    risk 0.49cvss 7.5epss 0.02

    Sunnet eHRD has inadequate filtering for special characters in URLs, which allows a remote attacker to perform path traversal attacks without authentication, access restricted paths and download system files.

  • CVE-2021-40809HigDec 1, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Jamf Pro before 10.32.0, aka PI-009921. An account can be granted incorrect privileges in response to authentication that uses specific sign-on workflows.

  • CVE-2021-36330HigNov 30, 2021
    risk 0.53cvss 8.1epss 0.01

    Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to reuse old session artifacts to impersonate a legitimate user.

  • CVE-2021-36328HigNov 30, 2021
    risk 0.57cvss 8.8epss 0.01

    Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions and retrieve sensitive information from the database.

  • CVE-2021-40101HigNov 30, 2021
    risk 0.47cvss 7.2epss 0.03

    An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.

  • CVE-2021-43296HigNov 30, 2021
    risk 0.49cvss 7.5epss 0.03

    Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor.

  • CVE-2021-43284HigNov 30, 2021
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Victure WR1200 devices through 1.0.3. The root SSH password never gets updated from its default value of admin. This enables an attacker to gain control of the device through SSH (regardless of whether the admin password was changed on the web…

  • CVE-2021-43283HigNov 30, 2021
    risk 0.58cvss 8.8epss 0.05

    An issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the web interface of the device, allowing an attacker with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges.…

  • CVE-2021-26612HigNov 30, 2021
    risk 0.53cvss 8.1epss 0.01

    An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method to execute arbitrary command after the file creation included malicious code.

  • CVE-2020-7880HigNov 30, 2021
    risk 0.49cvss 7.5epss 0.02

    The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote attacker to download and execute remote file. It is because of improper parameter validation of StartNeoRS function in ActiveX.

  • CVE-2020-7879HigNov 30, 2021
    risk 0.57cvss 8.8epss 0.01

    This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans setCookie('[COOKIE]') . The value is transferred to the --header option in wget binary, and there…

  • CVE-2021-43771HigNov 30, 2021
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Antivirus for Mac 2021 v11 (Consumer) is vulnerable to an improper access control privilege escalation vulnerability that could allow an attacker to establish a connection that could lead to full local privilege escalation within the application. Please note that an…

  • CVE-2021-42545HigNov 30, 2021
    risk 0.53cvss 8.1epss 0.01

    An insufficient session expiration vulnerability exists in Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27, which allows a remote attacker to reuse, spoof, or steal other user and admin sessions.

  • CVE-2021-42544HigNov 30, 2021
    risk 0.49cvss 7.5epss 0.01

    Missing Rate Limiting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 on the Login Form allows an unauthenticated remote attacker to perform multiple login attempts, which facilitates gaining privileges.

  • CVE-2021-42123HigNov 30, 2021
    risk 0.48cvss 7.3epss 0.01

    Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functions allows an authenticated remote attacker with Upload privileges to upload files with any file type, enabling client-side…

  • CVE-2021-42119HigNov 30, 2021
    risk 0.47cvss 7.3epss 0.01

    Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 via the Search Functionality allows authenticated users with Object Modification privileges to inject arbitrary HTML and JavaScript in object…

  • CVE-2021-42118HigNov 30, 2021
    risk 0.53cvss 8.1epss 0.01

    Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 via the Structure Component allows an authenticated remote attacker with Object Modification privileges to inject arbitrary HTML and JavaScript…

  • CVE-2021-42115HigNov 30, 2021
    risk 0.53cvss 8.1epss 0.01

    Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an unauthenticated remote attacker to escalate privileges from unauthenticated to authenticated user via stealing and injecting the session-…

  • CVE-2021-3769HigNov 30, 2021
    risk 0.00cvss 7.5epss 0.01

    # Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P` on user-supplied strings to print them to the terminal. All of them do that on git information, particularly the branch name, so if the branch has a…