VYPR

CVEs

101,977 total · page 1244 of 2,040

  • CVE-2021-41164HigNov 17, 2021
    risk 0.53cvss 8.2epss 0.01

    CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization,…

  • CVE-2021-33106HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Integer overflow in the Safestring library maintained by Intel(R) may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33095HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Unquoted search path in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before version 1.0.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33094HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Keyboard LED Service driver pack before version 1.0.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33093HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit Serial IO driver pack before version 30.100.2104.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33092HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit HID Event Filter driver pack before version 2.2.1.383 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33091HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Insecure inherited permissions in the installer for the Intel(R) NUC M15 Laptop Kit audio driver pack before version 1.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33090HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissionsin the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC10i3FN, NUC10i5FN, NUC10i7FN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33089HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper access control in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC8i3BE, NUC8i5BE, NUC8i7BE before version 1.78.4.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33088HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the installer for the Intel(R) NUC M15 Laptop Kit Integrated Sensor Hub driver pack before version 5.4.1.4449 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-0121HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper access control in the installer for some Intel(R) Iris(R) Xe MAX Dedicated Graphics Drivers for Windows 10 before version 27.20.100.9466 may allow authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-0096HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper authentication in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN, NUC7i7DN before version 1.78.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-42362HigNov 17, 2021
    risk 0.60cvss 8.8epss 0.80

    The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can…

  • CVE-2021-42360HigNov 17, 2021
    risk 0.49cvss 7.6epss 0.01

    On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capability, which includes Contributor-level users, to import blocks onto any page using the astra-page-elementor-batch-process AJAX action. An attacker could craft…

  • CVE-2021-35528HigNov 17, 2021
    risk 0.47cvss 7.2epss 0.00

    Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. A successful exploitation may lead to…

  • CVE-2021-33481HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.01

    A stack-based buffer overflow vulnerability was discovered in gocr through 0.53-20200802 in try_to_divide_boxes() in pgm2asc.c.

  • CVE-2021-33479HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.01

    A stack-based buffer overflow vulnerability was discovered in gocr through 0.53-20200802 in measure_pitch() in pgm2asc.c.

  • CVE-2021-40745HigNov 17, 2021
    risk 0.49cvss 7.5epss 0.04

    Adobe Campaign version 21.2.1 (and earlier) is affected by a Path Traversal vulnerability that could lead to reading arbitrary server files. By leveraging an exposed XML file, an unauthenticated attacker can enumerate other files on the server.

  • CVE-2021-42955HigNov 17, 2021
    risk 0.47cvss 7.3epss 0.00

    Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user can reset the password of the Remote Access Plus Server…

  • CVE-2021-42954HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is vulnerable to weak file permissions by allowing full control for Windows Everyone user group (non-admin or any guest users),…

  • CVE-2021-42956HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.01

    Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user, so memory dump can be done by non-admin also. Remotely,…

  • CVE-2021-24847HigNov 17, 2021
    risk 0.57cvss 8.8epss 0.01

    The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, available to any authenticated user, does not properly sanitise the offset parameter before using it in a SQL statement, leading an SQL injection when the…

  • CVE-2021-24804HigNov 17, 2021
    risk 0.57cvss 8.8epss 0.01

    The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attackers to make a logged in admin changed them. Settings such as HMAC verification secret, account registering and default user roles can be updated, which could…

  • CVE-2021-24772HigNov 17, 2021
    risk 0.57cvss 8.8epss 0.01

    The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records admin dashboard before using it in a SQL statement, leading to an SQL injection issue.

  • CVE-2021-24758HigNov 17, 2021
    risk 0.57cvss 8.8epss 0.01

    The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GET parameters before using them in SQL statement in the admin dashboard, leading to SQL injections

  • CVE-2021-3939HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus…

  • CVE-2021-43012HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Prelude version 10.1 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction…

  • CVE-2021-43011HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Prelude version 10.1 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction…

  • CVE-2021-42731HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.05

    Adobe InDesign versions 16.4 (and earlier) are affected by a Buffer Overflow vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of…

  • CVE-2021-42725HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-42723HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Bridge version 11.1.1 (and earlier) is affected by an out-of-bounds read vulnerability when parsing a crafted SGI file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context…

  • CVE-2021-42721HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.04

    Acrobat Bridge versions 11.1.1 and earlier are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2021-43013HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Media Encoder version 15.4.1 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user…

  • CVE-2021-42726HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.02

    Adobe Bridge version 11.1.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious M4A file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this…

  • CVE-2021-26335HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper input and range checking in the AMD Secure Processor (ASP) boot loader image header may allow an attacker to use attacker-controlled values prior to signature validation potentially resulting in arbitrary code execution.

  • CVE-2021-26331HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.00

    AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution.

  • CVE-2021-26323HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.00

    Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity.

  • CVE-2021-26315HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.00

    When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when encrypted firmware images are used.

  • CVE-2020-21627HigNov 16, 2021
    risk 0.49cvss 7.5epss 0.01

    Ruijie RG-UAC commit 9071227 was discovered to contain a vulnerability in the component /current_action.php?action=reboot, which allows attackers to cause a denial of service (DoS) via unspecified vectors.

  • CVE-2020-12961HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.00

    A potential vulnerability exists in AMD Platform Security Processor (PSP) that may allow an attacker to zero any privileged register on the System Management Network which may lead to bypassing SPI ROM protections.

  • CVE-2020-12951HigNov 16, 2021
    risk 0.46cvss 7.0epss 0.00

    Race condition in ASP firmware could allow less privileged x86 code to perform ASP SMM (System Management Mode) operations.

  • CVE-2020-12946HigNov 16, 2021
    risk 0.46cvss 7.1epss 0.00

    Insufficient input validation in ASP firmware for discrete TPM commands could allow a potential loss of integrity and denial of service.

  • CVE-2020-12944HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.00

    Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution.

  • CVE-2021-43046HigNov 16, 2021
    risk 0.49cvss 7.5epss 0.01

    The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain an easily exploitable vulnerability that allows an unauthenticated attacker with network access to obtain session tokens for the affected system. A successful attack using…

  • CVE-2021-41258HigNov 16, 2021
    risk 0.00cvss 7.3epss 0.01

    Kirby is an open source file structured CMS. In affected versions Kirby's blocks field stores structured data for each block. This data is then used in block snippets to convert the blocks to HTML for use in your templates. We recommend to escape HTML special characters to…

  • CVE-2021-41252HigNov 16, 2021
    risk 0.41cvss 7.3epss 0.01

    Kirby is an open source file structured CMS ### Impact Kirby's writer field stores its formatted content as HTML code. Unlike with other field types, it is not possible to escape HTML special characters against cross-site scripting (XSS) attacks, otherwise the formatting would…

  • CVE-2021-26338HigNov 16, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting in a potential lack of system resources.

  • CVE-2021-26326HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.00

    Failure to validate VM_HSAVE_PA during SNP_INIT may result in a loss of memory integrity.

  • CVE-2021-26322HigNov 16, 2021
    risk 0.49cvss 7.5epss 0.01

    Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.

  • CVE-2021-25985HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.01

    In Factor (App Framework & Headless CMS) v1.0.4 to v1.8.30, improperly invalidate a user’s session even after the user logs out of the application. In addition, user sessions are stored in the browser’s local storage, which by default does not have an expiration time. This…