VYPR

CVEs

101,977 total · page 1241 of 2,040

  • CVE-2021-35033HigNov 23, 2021
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in specific versions of Zyxel NBG6818, NBG7815, WSQ20, WSQ50, WSQ60, and WSR30 firmware with pre-configured password management could allow an attacker to obtain root access of the device, if the local attacker dismantles the device and uses a USB-to-UART cable…

  • CVE-2021-43775HigNov 23, 2021
    risk 0.49cvss 8.6epss 0.02

    Aim is an open-source, self-hosted machine learning experiment tracking tool. Versions of Aim prior to 3.1.0 are vulnerable to a path traversal attack. By manipulating variables that reference files with “dot-dot-slash (../)” sequences and its variations or by using absolute…

  • CVE-2021-41281HigNov 23, 2021
    risk 0.42cvss 7.5epss 0.02

    Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an arbitrary directory. No authentication is required for the…

  • CVE-2021-38891HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 209508.

  • CVE-2021-38890HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.02

    IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507.

  • CVE-2021-36314HigNov 23, 2021
    risk 0.46cvss 7.1epss 0.01

    Dell EMC CloudLink 7.1 and all prior versions contain an Arbitrary File Creation Vulnerability. A remote unauthenticated attacker, may potentially exploit this vulnerability, leading to the execution of arbitrary files on the end user system.

  • CVE-2021-36299HigNov 23, 2021
    risk 0.49cvss 7.1epss 0.30

    Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to cause information disclosure or denial of service by…

  • CVE-2021-24892HigNov 23, 2021
    risk 0.00cvss 8.8epss 0.02

    Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead to take over of WordPress's administrator account. To…

  • CVE-2021-24877HigNov 23, 2021
    risk 0.47cvss 7.2epss 0.01

    The MainWP Child WordPress plugin before 4.1.8 does not validate the orderby and order parameter before using them in a SQL statement, leading to an SQL injection exploitable by high privilege users such as admin when the Backup and Staging by WP Time Capsule plugin is installed

  • CVE-2021-24644HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.05

    The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue

  • CVE-2021-24641HigNov 23, 2021
    risk 0.53cvss 8.1epss 0.01

    The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrary image conversion

  • CVE-2021-21561HigNov 23, 2021
    risk 0.51cvss 7.8epss 0.00

    Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE privileges to gain access to sensitive information in the log files.

  • CVE-2021-43019HigNov 23, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe service. An unauthenticated attacker could leverage this vulnerability to remove files and escalate privileges under the context of…

  • CVE-2021-37102HigNov 23, 2021
    risk 0.57cvss 8.8epss 0.01

    There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software constructs part of a command using external special input from users, but the software does not sufficiently validate the user…

  • CVE-2021-37035HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Remote DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the app to exit unexpectedly.

  • CVE-2021-37034HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Unstandardized field names in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-37033HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Injection attack vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

  • CVE-2021-37031HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Remote DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the app to exit unexpectedly.

  • CVE-2021-37030HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Improper permission vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

  • CVE-2021-37026HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

  • CVE-2021-37025HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

  • CVE-2021-37024HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

  • CVE-2021-37019HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

  • CVE-2021-37018HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Data Processing Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

  • CVE-2021-37017HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

  • CVE-2021-37015HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

  • CVE-2021-37012HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Data Processing Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

  • CVE-2021-37010HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.

  • CVE-2021-37009HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Configuration vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.

  • CVE-2021-37008HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

  • CVE-2021-37007HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Out-of-bounds Read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

  • CVE-2021-37006HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.

  • CVE-2021-37005HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

  • CVE-2021-37004HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

  • CVE-2021-37003HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause kernel crash.

  • CVE-2021-35052HigNov 23, 2021
    risk 0.51cvss 7.8epss 0.00

    A component in Kaspersky Password Manager could allow an attacker to elevate a process Integrity level from Medium to High.

  • CVE-2021-39976HigNov 23, 2021
    risk 0.51cvss 7.8epss 0.00

    There is a privilege escalation vulnerability in CloudEngine 5800 V200R020C00SPC600. Due to lack of privilege restrictions, an authenticated local attacker can perform specific operation to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a…

  • CVE-2021-20601HigNov 23, 2021
    risk 0.49cvss 7.5epss 0.02

    Improper input validation vulnerability in GOT2000 series GT27 model all versions, GOT2000 series GT25 model all versions, GOT2000 series GT23 model all versions, GOT2000 series GT21 model all versions, GOT SIMPLE series GS21 model all versions, and GT SoftGOT2000 all versions…

  • CVE-2021-44150HigNov 22, 2021
    risk 0.49cvss 7.5epss 0.01

    The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content.

  • CVE-2021-42707HigNov 22, 2021
    risk 0.51cvss 7.8epss 0.01

    PLC Editor Versions 1.3.8 and prior is vulnerable to an out-of-bounds write while processing project files, which may allow an attacker to execute arbitrary code.

  • CVE-2021-42705HigNov 22, 2021
    risk 0.51cvss 7.8epss 0.01

    PLC Editor Versions 1.3.8 and prior is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code.

  • CVE-2021-38448HigNov 22, 2021
    risk 0.49cvss 7.5epss 0.00

    The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.

  • CVE-2021-43559HigNov 22, 2021
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

  • CVE-2021-43015HigNov 22, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe InCopy version 16.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious GIF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must…

  • CVE-2021-42738HigNov 22, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious MXF file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must…

  • CVE-2021-42737HigNov 22, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must…

  • CVE-2021-42727HigNov 22, 2021
    risk 0.54cvss 7.8epss 0.39

    Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a…

  • CVE-2021-40775HigNov 22, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious SVG file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must…

  • CVE-2021-40772HigNov 22, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must…

  • CVE-2021-40771HigNov 22, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must…