VYPR

CVEs

101,977 total · page 1245 of 2,040

  • CVE-2021-25965HigNov 16, 2021
    risk 0.00cvss 8.8epss 0.01

    In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an attacker can create a new user role with admin privileges and attacker-controlled credentials, allowing them to take over the…

  • CVE-2021-25940HigNov 16, 2021
    risk 0.00cvss 8.8epss 0.01

    In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Session Expiration. When a user’s password is changed by the administrator, the session isn’t invalidated, allowing a malicious user to still be logged in and perform arbitrary actions within the…

  • CVE-2021-25976HigNov 16, 2021
    risk 0.46cvss 8.1epss 0.00

    In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a post, deleting a media folder etc., when an ID is known.

  • CVE-2021-42386HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function

  • CVE-2021-42385HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function

  • CVE-2021-42384HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the handle_special function

  • CVE-2021-42383HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.02

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function

  • CVE-2021-42382HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function

  • CVE-2021-42381HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the hash_init function

  • CVE-2021-42380HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar function

  • CVE-2021-42379HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the next_input_file function

  • CVE-2021-42378HigNov 15, 2021
    risk 0.47cvss 7.2epss 0.03

    A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_i function

  • CVE-2021-41266HigNov 15, 2021
    risk 0.60cvss 8.6epss 0.47

    Minio console is a graphical user interface for the for MinIO operator. Minio itself is a multi-cloud object storage project. Affected versions are subject to an authentication bypass issue in the Operator Console when an external IDP is enabled. All users on release v0.12.2 and…

  • CVE-2021-41263HigNov 15, 2021
    risk 0.47cvss 8.3epss 0.01

    rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Rails applications using `rails_multisite` alongside Rails' signed/encrypted cookies. Depending on how the application makes use of these cookies, it may be…

  • CVE-2020-12962HigNov 15, 2021
    risk 0.51cvss 7.8epss 0.00

    Escape call interface in the AMD Graphics Driver for Windows may cause privilege escalation.

  • CVE-2020-12903HigNov 15, 2021
    risk 0.51cvss 7.8epss 0.00

    Out of Bounds Write and Read in AMD Graphics Driver for Windows 10 in Escape 0x6002d03 may lead to escalation of privilege or denial of service.

  • CVE-2020-12894HigNov 15, 2021
    risk 0.46cvss 7.1epss 0.00

    Arbitrary Write in AMD Graphics Driver for Windows 10 in Escape 0x40010d may lead to arbitrary write to kernel memory or denial of service.

  • CVE-2020-12893HigNov 15, 2021
    risk 0.51cvss 7.8epss 0.00

    Stack Buffer Overflow in AMD Graphics Driver for Windows 10 in Escape 0x15002a may lead to escalation of privilege or denial of service.

  • CVE-2020-12898HigNov 15, 2021
    risk 0.51cvss 7.8epss 0.00

    Stack Buffer Overflow in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.

  • CVE-2020-12892HigNov 15, 2021
    risk 0.51cvss 7.8epss 0.00

    An untrusted search path in AMD Radeon settings Installer may lead to a privilege escalation or unauthorized code execution.

  • CVE-2021-38984HigNov 15, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212793.

  • CVE-2021-38983HigNov 15, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 212792.

  • CVE-2021-38979HigNov 15, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the software does not also use a salt as part of the input. IBM X-Force ID: 212785.

  • CVE-2021-34992HigNov 15, 2021
    risk 0.58cvss 8.8epss 0.04

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS 6.10. Authentication is required to exploit this vulnerability. The specific flaw exists within Composite.dll. The issue results from the lack of proper validation…

  • CVE-2021-34991HigNov 15, 2021
    risk 0.58cvss 8.8epss 0.06

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6400v2 1.0.4.106_10.0.80 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the UPnP service, which listens on…

  • CVE-2020-12963HigNov 15, 2021
    risk 0.51cvss 7.8epss 0.00

    An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows may allow unprivileged users to compromise the system.

  • CVE-2020-12929HigNov 15, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper parameters validation in some trusted applications of the PSP contained in the AMD Graphics Driver may allow a local attacker to bypass security restrictions and achieve arbitrary code execution .

  • CVE-2020-12902HigNov 15, 2021
    risk 0.51cvss 7.8epss 0.00

    Arbitrary Decrement Privilege Escalation in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.

  • CVE-2020-12900HigNov 15, 2021
    risk 0.51cvss 7.8epss 0.00

    An arbitrary write vulnerability in the AMD Radeon Graphics Driver for Windows 10 potentially allows unprivileged users to gain Escalation of Privileges and cause Denial of Service.

  • CVE-2020-12899HigNov 15, 2021
    risk 0.46cvss 7.1epss 0.00

    Arbitrary Read in AMD Graphics Driver for Windows 10 may lead to KASLR bypass or denial of service.

  • CVE-2020-12895HigNov 15, 2021
    risk 0.51cvss 7.8epss 0.00

    Pool/Heap Overflow in AMD Graphics Driver for Windows 10 in Escape 0x110037 may lead to escalation of privilege, information disclosure or denial of service.

  • CVE-2020-12964HigNov 15, 2021
    risk 0.51cvss 7.8epss 0.00

    A potential privilege escalation/denial of service issue exists in the AMD Radeon Kernel Mode driver Escape 0x2000c00 Call handler. An attacker with low privilege could potentially induce a Windows BugCheck or write to leak information.

  • CVE-2021-42706HigNov 15, 2021
    risk 0.51cvss 7.8epss 0.00

    This vulnerability could allow an attacker to disclose information and execute arbitrary code on affected installations of WebAccess/MHI Designer

  • CVE-2021-43495HigNov 15, 2021
    risk 0.49cvss 7.5epss 0.09

    AlquistManager branch as of commit 280d99f43b11378212652e75f6f3159cde9c1d36 is affected by a directory traversal vulnerability in alquist/IO/input.py. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting…

  • CVE-2021-42839HigNov 15, 2021
    risk 0.57cvss 8.8epss 0.02

    Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user’s permission, remote attackers can upload malicious script and execute arbitrary code to control the system or interrupt services.

  • CVE-2021-43620HigNov 15, 2021
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the fruity crate through 0.2.0 for Rust. Security-relevant validation of filename extensions is plausibly affected. Methods of NSString for conversion to a string may return a partial result. Because they call CStr::from_ptr on a pointer to the string…

  • CVE-2021-43618HigNov 15, 2021
    risk 0.49cvss 7.5epss 0.03

    GNU Multiple Precision Arithmetic Library (GMP) through 6.2.1 has an mpz/inp_raw.c integer overflow and resultant buffer overflow via crafted input, leading to a segmentation fault on 32-bit platforms.

  • CVE-2021-43391HigNov 14, 2021
    risk 0.51cvss 7.8epss 0.02

    An Out-of-Bounds Read vulnerability exists when reading a DXF file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DXF files. Crafted data in a DXF file (an invalid dash counter in line types) can trigger a read past the…

  • CVE-2021-43390HigNov 14, 2021
    risk 0.51cvss 7.8epss 0.02

    An Out-of-Bounds Write vulnerability exists when reading a DGN file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DGN files. Crafted data in a DGN file and lack of proper validation of input data can trigger a write…

  • CVE-2021-43336HigNov 14, 2021
    risk 0.51cvss 7.8epss 0.02

    An Out-of-Bounds Write vulnerability exists when reading a DXF or DWG file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DXF and DWG files. Crafted data in a DXF or DWG file (an invalid number of properties) can trigger a…

  • CVE-2021-43280HigNov 14, 2021
    risk 0.51cvss 7.8epss 0.02

    A stack-based buffer overflow vulnerability exists in the DWF file reading procedure in Open Design Alliance Drawings SDK before 2022.8. The issue results from the lack of proper validation of the length of user-supplied data before copying it to a stack-based buffer. An…

  • CVE-2021-43279HigNov 14, 2021
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds write vulnerability exists in the U3D file reading procedure in Open Design Alliance PRC SDK before 2022.10. Crafted data in a U3D file can trigger a write past the end of an allocated buffer. An attacker can leverage this in conjunction with other…

  • CVE-2021-43278HigNov 14, 2021
    risk 0.51cvss 7.8epss 0.01

    An Out-of-bounds Read vulnerability exists in the OBJ file reading procedure in Open Design Alliance Drawings SDK before 2022.11. The lack of validating the input length can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to…

  • CVE-2021-43277HigNov 14, 2021
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds read vulnerability exists in the U3D file reading procedure in Open Design Alliance PRC SDK before 2022.10. Crafted data in a U3D file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities…

  • CVE-2021-43276HigNov 14, 2021
    risk 0.51cvss 7.8epss 0.01

    An Out-of-bounds Read vulnerability exists in Open Design Alliance ODA Viewer before 2022.8. Crafted data in a DWF file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in…

  • CVE-2021-43275HigNov 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A Use After Free vulnerability exists in the DGN file reading procedure in Open Design Alliance Drawings SDK before 2022.8. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this…

  • CVE-2021-43274HigNov 14, 2021
    risk 0.51cvss 7.8epss 0.01

    A Use After Free Vulnerability exists in the Open Design Alliance Drawings SDK before 2022.11. The specific flaw exists within the parsing of DWF files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An…

  • CVE-2021-41057HigNov 14, 2021
    risk 0.46cvss 7.1epss 0.00

    In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.

  • CVE-2021-26795HigNov 14, 2021
    risk 0.57cvss 8.8epss 0.01

    A SQL Injection vulnerability in /appliance/shiftmgn.php in TalariaX sendQuick Alert Plus Server Admin 4.3 before 8HF11 allows attackers to obtain sensitive information via a Roster Time to Roster Management.

  • CVE-2021-38684HigNov 13, 2021
    risk 0.53cvss 8.1epss 0.01

    A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Multimedia Console. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of Multimedia Console:…