VYPR

CVEs

101,977 total · page 1240 of 2,040

  • CVE-2021-3727HigNov 30, 2021
    risk 0.00cvss 7.5epss 0.01

    # Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes from quotationspage.com and hitokoto.cn respectively, do some process on them and then use `print -P` to print them. If these quotes contained the proper symbols,…

  • CVE-2021-3726HigNov 30, 2021
    risk 0.00cvss 7.5epss 0.01

    # Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` to set the terminal title to a user-supplied string. In Oh My Zsh, this function is always used securely, but custom user code could use the `title` function…

  • CVE-2021-3725HigNov 30, 2021
    risk 0.00cvss 7.5epss 0.01

    Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a directory with a carefully-crafted name,…

  • CVE-2021-43790HigNov 30, 2021
    risk 0.48cvss 8.5epss 0.02

    Lucet is a native WebAssembly compiler and runtime. There is a bug in the main branch of `lucet-runtime` affecting all versions published to crates.io that allows a use-after-free in an Instance object that could result in memory corruption, data race, or other related issues.…

  • CVE-2021-44429HigNov 29, 2021
    risk 0.49cvss 7.5epss 0.02

    Serva 4.4.0 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcode 1, a related issue to CVE-2013-0145.

  • CVE-2021-44428HigNov 29, 2021
    risk 0.49cvss 7.5epss 0.03

    Pinkie 2.15 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcode 1.

  • CVE-2021-43783HigNov 29, 2021
    risk 0.48cvss 8.5epss 0.01

    @backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions a malicious actor with write access to a registered scaffolder template is able to manipulate the template in a way that writes files to arbitrary paths on the…

  • CVE-2021-34800HigNov 29, 2021
    risk 0.49cvss 7.5epss 0.01

    Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before build 27147

  • CVE-2021-44198HigNov 29, 2021
    risk 0.51cvss 7.8epss 0.00

    DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035

  • CVE-2021-42364HigNov 29, 2021
    risk 0.57cvss 8.8epss 0.01

    The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_page function found in the ~/stetic.php file, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 1.0.6.

  • CVE-2021-42358HigNov 29, 2021
    risk 0.57cvss 8.8epss 0.01

    The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation in the ~/cfwc-form.php file during contact form submission, which made it possible for attackers to inject arbitrary web scripts in versions up to, and…

  • CVE-2021-24889HigNov 29, 2021
    risk 0.47cvss 7.2epss 0.01

    The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks

  • CVE-2021-24860HigNov 29, 2021
    risk 0.47cvss 7.2epss 0.01

    The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before using them in a SQL statement, leading to a SQL injection issue

  • CVE-2021-24755HigNov 29, 2021
    risk 0.57cvss 8.8epss 0.01

    The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user

  • CVE-2021-24748HigNov 29, 2021
    risk 0.57cvss 8.8epss 0.01

    The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues

  • CVE-2021-38283HigNov 29, 2021
    risk 0.49cvss 7.5epss 0.02

    Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing sensitive information via a predictable /log URI.

  • CVE-2021-38147HigNov 29, 2021
    risk 0.53cvss 7.5epss 0.53

    Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to processexecution/DownloadExcelFile/Domain_Credential_Report_Excel,…

  • CVE-2019-8922HigNov 29, 2021
    risk 0.57cvss 8.8epss 0.01

    A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there is enough space in the destination buffer. The function simply appends all data passed to it. The values of all attributes that are requested are appended to…

  • CVE-2021-44094HigNov 28, 2021
    risk 0.51cvss 7.8epss 0.01

    ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file

  • CVE-2021-43785HigNov 26, 2021
    risk 0.42cvss 7.6epss 0.01

    @joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. In affected versions there are two vectors for XSS attacks: a URL for a custom emoji, and an i18n string. In both of these cases, a value can be crafted such that it can insert a `script` tag into the page…

  • CVE-2021-43776HigNov 26, 2021
    risk 0.48cvss 7.4epss 0.01

    Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a malicious actor to trick another user into visiting a vulnerable URL that executes an XSS attack. This attack can potentially allow the attacker to exfiltrate…

  • CVE-2021-41279HigNov 26, 2021
    risk 0.43cvss 7.7epss 0.02

    BaserCMS is an open source content management system with a focus on Japanese language support. In affected versions users with upload privilege may upload crafted zip files capable of path traversal on the host operating system. This is a vulnerability that needs to be…

  • CVE-2021-35533HigNov 26, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-5-104 function of Hitachi Energy RTU500 series allows an attacker to cause the receiving RTU500 CMU of which the BCI is enabled to reboot when receiving a…

  • CVE-2021-26615HigNov 26, 2021
    risk 0.51cvss 7.8epss 0.01

    ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW function because of an integer overflow.

  • CVE-2021-26611HigNov 26, 2021
    risk 0.53cvss 8.1epss 0.01

    HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to operate the IP Camera.(reboot, factory reset, snapshot etc..)

  • CVE-2020-7881HigNov 26, 2021
    risk 0.49cvss 7.5epss 0.01

    The vulnerability function is enabled when the streamer service related to the AfreecaTV communicated through web socket using 21201 port. A stack-based buffer overflow leading to remote code execution was discovered in strcpy() operate by "FanTicket" field. It is because of…

  • CVE-2021-36807HigNov 26, 2021
    risk 0.57cvss 8.8epss 0.01

    An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.

  • CVE-2021-38686HigNov 26, 2021
    risk 0.57cvss 8.8epss 0.01

    An improper authentication vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of QVR: QVR FW 5.1.6 build…

  • CVE-2021-44223HigNov 25, 2021
    risk 0.55cvss 8.1epss 0.29

    WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the…

  • CVE-2021-22957HigNov 24, 2021
    risk 0.57cvss 8.8epss 0.01

    A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s account.This vulnerability is fixed in…

  • CVE-2021-38873HigNov 24, 2021
    risk 0.51cvss 7.8epss 0.02

    IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 208396.

  • CVE-2021-36916HigNov 24, 2021
    risk 0.56cvss 8.6epss 0.02

    The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The function "hmwp_get_user_ip" tries to retrieve the IP address from multiple headers, including IP address…

  • CVE-2021-34424HigNov 24, 2021
    risk 0.49cvss 7.5epss 0.02

    A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before…

  • CVE-2021-21980HigNov 24, 2021
    risk 0.49cvss 7.5epss 0.05

    The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.

  • CVE-2021-41192HigNov 24, 2021
    risk 0.01cvss 8.1epss 0.08

    Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without explicitly specifying the `REDASH_COOKIE_SECRET` or `REDASH_SECRET_KEY` environment variables, a default value is used for both that is the same across all…

  • CVE-2021-31822HigNov 24, 2021
    risk 0.51cvss 7.8epss 0.00

    When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured. This could lead to a local unprivileged user modifying the contents of the systemd service file to gain privileged access.

  • CVE-2021-20846HigNov 24, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operation via a specially crafted web page.

  • CVE-2021-20845HigNov 24, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary operation via a specially crafted web page.

  • CVE-2021-20835HigNov 24, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper authorization in handler for custom URL scheme vulnerability in Android App 'Mercari (Merpay) - Marketplace and Mobile Payments App' (Japan version) versions prior to 4.49.1 allows a remote attacker to lead a user to access an arbitrary website and the website launches…

  • CVE-2021-28709HigNov 24, 2021
    risk 0.51cvss 7.8epss 0.00

    issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them…

  • CVE-2021-28705HigNov 24, 2021
    risk 0.51cvss 7.8epss 0.00

    issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them…

  • CVE-2021-42306HigNov 24, 2021
    risk 0.53cvss 8.1epss 0.03

    An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential  on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a…

  • CVE-2021-28708HigNov 24, 2021
    risk 0.57cvss 8.8epss 0.00

    PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily…

  • CVE-2021-28707HigNov 24, 2021
    risk 0.57cvss 8.8epss 0.00

    PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily…

  • CVE-2021-28706HigNov 24, 2021
    risk 0.56cvss 8.6epss 0.02

    guests may exceed their designated memory limit When a guest is permitted to have close to 16TiB of memory, it may be able to issue hypercalls to increase its memory allocation beyond the administrator established limit. This is a result of a calculation done with 32-bit…

  • CVE-2021-28704HigNov 24, 2021
    risk 0.57cvss 8.8epss 0.00

    PoD operations on misaligned GFNs T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily…

  • CVE-2021-38003HigKEVNov 23, 2021
    risk 0.72cvss 8.8epss 0.36

    Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-38001HigNov 23, 2021
    risk 0.59cvss 8.8epss 0.27

    Type confusion in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-37998HigNov 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Garbage Collection in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-37997HigNov 23, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in Sign-In in Google Chrome prior to 95.0.4638.69 allowed a remote attacker who convinced a user to sign into Chrome to potentially exploit heap corruption via a crafted HTML page.