VYPR

CVEs

101,977 total · page 1242 of 2,040

  • CVE-2021-40770HigNov 22, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must…

  • CVE-2021-3935HigNov 22, 2021
    risk 0.53cvss 8.1epss 0.01

    When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encryption. This flaw affects PgBouncer versions prior to 1.16.1.

  • CVE-2021-26614HigNov 22, 2021
    risk 0.49cvss 7.5epss 0.02

    ius_get.cgi in IpTime C200 camera allows remote code execution. A remote attacker may send a crafted parameters to the exposed vulnerable web service interface which invokes the arbitrary shell command.

  • CVE-2020-7882HigNov 22, 2021
    risk 0.49cvss 7.5epss 0.01

    Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')

  • CVE-2021-43582HigNov 22, 2021
    risk 0.51cvss 7.8epss 0.01

    A Use-After-Free Remote Vulnerability exists when reading a DWG file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DWG files. The issue results from the lack of validating the existence of an object prior to performing…

  • CVE-2021-43581HigNov 22, 2021
    risk 0.57cvss 8.8epss 0.01

    An Out-of-Bounds Read vulnerability exists when reading a U3D file using Open Design Alliance PRC SDK before 2022.11. The specific issue exists within the parsing of U3D files. Incorrect use of the LibJpeg source manager inside the U3D library, and crafted data in a U3D file,…

  • CVE-2021-43557HigNov 22, 2021
    risk 0.50cvss 7.5epss 0.15

    The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construct a URI to bypass the block list on some occasions. For instance, when the block…

  • CVE-2021-38146HigNov 22, 2021
    risk 0.50cvss 7.5epss 0.12

    The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary files via absolute path traversal in the SearchString JSON field in /home/download POST data.

  • CVE-2021-28710HigNov 21, 2021
    risk 0.57cvss 8.8epss 0.00

    certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translation control structures (page tables) may (and, on suitable hardware, by default will) be shared between CPUs, for second-level translation (EPT), and IOMMUs. These page tables are…

  • CVE-2021-23217HigNov 20, 2021
    risk 0.49cvss 7.5epss 0.00

    NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to instantiate a DMA write operation only within a specific time window timed to corrupt code execution, which may impact confidentiality,…

  • CVE-2021-23201HigNov 20, 2021
    risk 0.49cvss 7.5epss 0.00

    NVIDIA GPU and Tegra hardware contain a vulnerability in an internal microcontroller, which may allow a user with elevated privileges to generate valid microcode by identifying, exploiting, and loading vulnerable microcode. Such an attack could lead to information disclosure,…

  • CVE-2021-36340HigNov 20, 2021
    risk 0.51cvss 7.8epss 0.00

    Dell EMC SCG 5.00.00.10 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulnerability to read sensitive information and use it.

  • CVE-2021-36321HigNov 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an improper input validation vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending specially crafted data to trigger a denial of service.

  • CVE-2021-36320HigNov 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially hijack a session and access the webserver by forging the session ID.

  • CVE-2021-36307HigNov 20, 2021
    risk 0.57cvss 8.8epss 0.01

    Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains a privilege escalation vulnerability. A malicious low privileged user with specific access to the API could potentially exploit this vulnerability to gain admin privileges on the affected system.

  • CVE-2021-36306HigNov 20, 2021
    risk 0.53cvss 8.1epss 0.04

    Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains an authentication bypass vulnerability. A remote unauthenticated attacker could exploit this vulnerability to gain access and perform actions on the affected system.

  • CVE-2021-21898HigNov 19, 2021
    risk 0.57cvss 8.8epss 0.03

    A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-44038HigNov 19, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (with control of the non-root-owned directory /etc/quagga) to escalate their privileges to root upon package installation or update.

  • CVE-2021-43555HigNov 19, 2021
    risk 0.50cvss 7.3epss 0.38

    mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to plant files on the file system in arbitrary locations or…

  • CVE-2021-42254HigNov 19, 2021
    risk 0.51cvss 7.8epss 0.00

    BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2021-22970HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.01

    Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system to be vulnerable toa. SSRF attacks on the private LAN servers by reading files from the local LAN. An attacker can pivot in the private LAN and exploit local…

  • CVE-2021-22968HigNov 19, 2021
    risk 0.47cvss 7.2epss 0.03

    A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Concrete CMS (concrete5) versions 8.5.6 and below.The external file upload feature stages files in the public directory even if they have disallowed file…

  • CVE-2021-22967HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.01

    In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to verify a user has permissions to view files before attaching the files to a message…

  • CVE-2021-22966HigNov 19, 2021
    risk 0.57cvss 8.8epss 0.01

    Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "view" permissions on the bulkupdate page, then users in that group can escalate to being an administrator with a specially crafted curl. Fixed by adding a…

  • CVE-2021-22965HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device.

  • CVE-2021-22951HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.01

    Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. Concrete CMS now checks to see if a file has a password in view_inline and, if it does, the file is not rendered.For version 8.5.6, the…

  • CVE-2021-21900HigNov 19, 2021
    risk 0.57cvss 8.8epss 0.02

    A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-21899HigNov 19, 2021
    risk 0.57cvss 8.8epss 0.03

    A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-41569HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.08

    SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows end-users of the application to access the sample.webcsf1.sas program, which contains user-controlled macro variables that are passed to…

  • CVE-2021-44037HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.01

    Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.

  • CVE-2021-44036HigNov 19, 2021
    risk 0.57cvss 8.8epss 0.00

    Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import.

  • CVE-2021-3962HigNov 19, 2021
    risk 0.00cvss 7.8epss 0.06

    A flaw was found in ImageMagick where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an attacker to create a specially crafted image that leads to a use-after-free vulnerability when processed by ImageMagick. The highest…

  • CVE-2021-39929HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.04

    Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39926HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.07

    Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39925HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.08

    Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39924HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.05

    Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39923HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.02

    Large loop in the PNRP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39922HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.05

    Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-39921HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.03

    NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file

  • CVE-2021-29329HigNov 19, 2021
    risk 0.51cvss 7.8epss 0.01

    OpenSource Moddable v10.5.0 was discovered to contain a stack overflow in the fxBinaryExpressionNodeDistribute function at /moddable/xs/sources/xsTree.c.

  • CVE-2021-29328HigNov 19, 2021
    risk 0.46cvss 7.1epss 0.01

    OpenSource Moddable v10.5.0 was discovered to contain buffer over-read in the fxDebugThrow function at /moddable/xs/sources/xsDebug.c.

  • CVE-2021-29327HigNov 19, 2021
    risk 0.51cvss 7.8epss 0.01

    OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_ArrayBuffer function at /moddable/xs/sources/xsDataView.c.

  • CVE-2021-29326HigNov 19, 2021
    risk 0.51cvss 7.8epss 0.01

    OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fxIDToString function at /moddable/xs/sources/xsSymbol.c.

  • CVE-2021-29325HigNov 19, 2021
    risk 0.51cvss 7.8epss 0.01

    OpenSource Moddable v10.5.0 was discovered to contain a heap buffer overflow in the fx_String_prototype_repeat function at /moddable/xs/sources/xsString.c.

  • CVE-2021-29324HigNov 19, 2021
    risk 0.51cvss 7.8epss 0.01

    OpenSource Moddable v10.5.0 was discovered to contain a stack overflow via the component /moddable/xs/sources/xsScript.c.

  • CVE-2021-39353HigNov 19, 2021
    risk 0.57cvss 8.8epss 0.01

    The Easy Registration Forms WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the ajax_add_form function found in the ~/includes/class-form.php file which made it possible for attackers to inject arbitrary web scripts in versions up…

  • CVE-2021-22053HigNov 19, 2021
    risk 0.58cvss 8.8epss 0.13

    Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-provided data]`, the…

  • CVE-2021-41436HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.05

    An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming…

  • CVE-2021-3973HigNov 19, 2021
    risk 0.00cvss 7.8epss 0.02

    vim is vulnerable to Heap-based Buffer Overflow

  • CVE-2021-3968HigNov 19, 2021
    risk 0.00cvss 8.0epss 0.02

    vim is vulnerable to Heap-based Buffer Overflow