VYPR

CVEs

101,977 total · page 1247 of 2,040

  • CVE-2021-3058HigNov 10, 2021
    risk 0.57cvss 8.8epss 0.02

    An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than…

  • CVE-2021-3056HigNov 10, 2021
    risk 0.57cvss 8.8epss 0.01

    A memory corruption vulnerability in Palo Alto Networks PAN-OS GlobalProtect Clientless VPN enables an authenticated attacker to execute arbitrary code with root user privileges during SAML authentication. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.20;…

  • CVE-2021-43564HigNov 10, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the jobfair (aka Job Fair) extension before 1.0.13 and 2.x before 2.0.2 for TYPO3. The extension fails to protect or obfuscate filenames of uploaded files. This allows unauthenticated users to download files with sensitive data by simply guessing the…

  • CVE-2021-43563HigNov 10, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The Access Control in the bundled media browser is broken, which allows an unauthenticated attacker to perform requests to the pixx.io API for the configured API user. This…

  • CVE-2021-41426HigNov 10, 2021
    risk 0.57cvss 8.8epss 0.01

    Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm.

  • CVE-2021-40503HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.00

    An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient privileges on the local client-side PC to obtain an equivalent of the user’s password. With this highly sensitive data leaked, the…

  • CVE-2021-40502HigNov 10, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. Authenticated attackers will be able to access and edit data from b2b units they do not belong to.

  • CVE-2021-40501HigNov 10, 2021
    risk 0.53cvss 8.1epss 0.01

    SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authenticated business user, resulting in escalation of privileges. That means this business user is able to read and modify data beyond the vulnerable system.…

  • CVE-2021-43562HigNov 10, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image download to the configured pixx.io DAM URL, resulting in SSRF. As a result, an attacker can download various content from a remote…

  • CVE-2021-39474HigNov 10, 2021
    risk 0.47cvss 7.2epss 0.02

    Vulnerability in the product Docsis 3.0 UBC1319BA00 Router supported affected version 1319010201r009. The vulnerability allows an attacker with privileges and network access through the ping.cmd component to execute commands on the device.

  • CVE-2021-34598HigNov 10, 2021
    risk 0.49cvss 7.5epss 0.01

    In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active

  • CVE-2021-31853HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.00

    DLL Search Order Hijacking Vulnerability in McAfee Drive Encryption (MDE) prior to 7.3.0 HF2 (7.3.0.183) allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.

  • CVE-2021-43209HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.05

    3D Viewer Remote Code Execution Vulnerability

  • CVE-2021-43208HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.04

    3D Viewer Remote Code Execution Vulnerability

  • CVE-2021-42322HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.00

    Visual Studio Code Elevation of Privilege Vulnerability

  • CVE-2021-42321HigKEVNov 10, 2021
    risk 0.85cvss 8.8epss 0.90

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2021-42316HigNov 10, 2021
    risk 0.57cvss 8.8epss 0.02

    Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability

  • CVE-2021-42298HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.05

    Microsoft Defender Remote Code Execution Vulnerability

  • CVE-2021-42296HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.01

    Microsoft Word Remote Code Execution Vulnerability

  • CVE-2021-42292HigKEVNov 10, 2021
    risk 0.65cvss 7.8epss 0.32

    Microsoft Excel Security Feature Bypass Vulnerability

  • CVE-2021-42291HigNov 10, 2021
    risk 0.49cvss 7.5epss 0.03

    Active Directory Domain Services Elevation of Privilege Vulnerability

  • CVE-2021-42287HigKEVNov 10, 2021
    risk 0.73cvss 7.5epss 0.74

    Active Directory Domain Services Elevation of Privilege Vulnerability

  • CVE-2021-42286HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.00

    Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability

  • CVE-2021-42285HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2021-42283HigNov 10, 2021
    risk 0.57cvss 8.8epss 0.00

    NTFS Elevation of Privilege Vulnerability

  • CVE-2021-42282HigNov 10, 2021
    risk 0.49cvss 7.5epss 0.03

    Active Directory Domain Services Elevation of Privilege Vulnerability

  • CVE-2021-42278HigKEVNov 10, 2021
    risk 0.72cvss 7.5epss 0.70

    Active Directory Domain Services Elevation of Privilege Vulnerability

  • CVE-2021-42276HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.02

    Microsoft Windows Media Foundation Remote Code Execution Vulnerability

  • CVE-2021-42275HigNov 10, 2021
    risk 0.57cvss 8.8epss 0.02

    Microsoft COM for Windows Remote Code Execution Vulnerability

  • CVE-2021-41378HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.01

    Windows NTFS Remote Code Execution Vulnerability

  • CVE-2021-41377HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.00

    Windows Fast FAT File System Driver Elevation of Privilege Vulnerability

  • CVE-2021-41372HigNov 10, 2021
    risk 0.49cvss 7.6epss 0.01

    A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities…

  • CVE-2021-41370HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.00

    NTFS Elevation of Privilege Vulnerability

  • CVE-2021-41367HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.00

    NTFS Elevation of Privilege Vulnerability

  • CVE-2021-41366HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.00

    Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability

  • CVE-2021-41356HigNov 10, 2021
    risk 0.49cvss 7.5epss 0.03

    Windows Denial of Service Vulnerability

  • CVE-2021-40442HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.02

    Microsoft Excel Remote Code Execution Vulnerability

  • CVE-2021-38666HigNov 10, 2021
    risk 0.58cvss 8.8epss 0.13

    Remote Desktop Client Remote Code Execution Vulnerability

  • CVE-2021-38665HigNov 10, 2021
    risk 0.49cvss 7.4epss 0.06

    Remote Desktop Protocol Client Information Disclosure Vulnerability

  • CVE-2021-36957HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.00

    Windows Desktop Bridge Elevation of Privilege Vulnerability

  • CVE-2021-37158HigNov 10, 2021
    risk 0.00cvss 8.8epss 0.02

    An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS commands by starting a Counter-Strike server and using the map field to enter a Bash command.

  • CVE-2021-37157HigNov 10, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. $HOME/OGP/Cfg/Config.pm has the root password in cleartext.

  • CVE-2021-20119HigNov 9, 2021
    risk 0.46cvss 7.1epss 0.00

    The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrator password.

  • CVE-2020-28419HigNov 9, 2021
    risk 0.57cvss 8.8epss 0.02

    During installation with certain driver software or application packages an arbitrary code execution could occur.

  • CVE-2021-43174HigNov 9, 2021
    risk 0.49cvss 7.5epss 0.01

    NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows…

  • CVE-2021-43173HigNov 9, 2021
    risk 0.49cvss 7.5epss 0.01

    In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall validation. While Routinator has a configurable…

  • CVE-2021-43172HigNov 9, 2021
    risk 0.00cvss 7.5epss 0.01

    NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously generating a new child CA that only…

  • CVE-2021-43182HigNov 9, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains Hub before 2021.1.13415, a DoS via user information is possible.

  • CVE-2021-43180HigNov 9, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible.

  • CVE-2021-43203HigNov 9, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.