VYPR

CVEs

101,977 total · page 1248 of 2,040

  • CVE-2021-43196HigNov 9, 2021
    risk 0.49cvss 7.5epss 0.01

    In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.

  • CVE-2021-43189HigNov 9, 2021
    risk 0.48cvss 7.3epss 0.01

    In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.

  • CVE-2021-43188HigNov 9, 2021
    risk 0.48cvss 7.3epss 0.01

    In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.

  • CVE-2019-18912HigNov 9, 2021
    risk 0.51cvss 7.8epss 0.00

    A potential security vulnerability has been identified for certain HP printers and MFPs with Troy solutions. For affected printers with FutureSmart Firmware bundle version 4.9 or 4.9.0.1 the potential vulnerability may cause instability in the solution.

  • CVE-2019-18916HigNov 9, 2021
    risk 0.51cvss 7.8epss 0.00

    A potential security vulnerability has been identified for HP LaserJet Solution Software (for certain HP LaserJet Printers) which may lead to unauthorized elevation of privilege on the client.

  • CVE-2021-43114HigNov 9, 2021
    risk 0.00cvss 7.5epss 0.01

    FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.

  • CVE-2021-42021HigNov 9, 2021
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in Siveillance Video DLNA Server (2019 R1), Siveillance Video DLNA Server (2019 R2), Siveillance Video DLNA Server (2019 R3), Siveillance Video DLNA Server (2020 R1), Siveillance Video DLNA Server (2020 R2), Siveillance Video DLNA Server (2020…

  • CVE-2021-40366HigNov 9, 2021
    risk 0.48cvss 7.4epss 0.00

    A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V11.34). The web server of affected devices transmits data without TLS encryption. This could allow an unauthenticated remote attacker in a…

  • CVE-2021-40359HigNov 9, 2021
    risk 0.50cvss 7.7epss 0.01

    A vulnerability has been identified in OpenPCS 7 V8.2 (All versions), OpenPCS 7 V9.0 (All versions < V9.0 Upd4), OpenPCS 7 V9.1 (All versions), SIMATIC BATCH V8.2 (All versions), SIMATIC BATCH V9.0 (All versions), SIMATIC BATCH V9.1 (All versions), SIMATIC NET PC Software V14…

  • CVE-2021-37207HigNov 9, 2021
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in SENTRON powermanager V3 (All versions). The affected application assigns improper access rights to a specific folder containing configuration files. This could allow an authenticated local attacker to inject arbitrary code and escalate…

  • CVE-2021-31890HigNov 9, 2021
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions <…

  • CVE-2021-31889HigNov 9, 2021
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0). Malformed TCP packets with a corrupted SACK…

  • CVE-2021-31888HigNov 9, 2021
    risk 0.57cvss 8.8epss 0.02

    A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE…

  • CVE-2021-31887HigNov 9, 2021
    risk 0.57cvss 8.8epss 0.02

    A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE…

  • CVE-2021-31885HigNov 9, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE…

  • CVE-2021-31883HigNov 9, 2021
    risk 0.46cvss 7.1epss 0.01

    A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). When processing a DHCP ACK message, the DHCP client application does not validate the length of the Vendor option(s), leading to…

  • CVE-2021-31881HigNov 9, 2021
    risk 0.46cvss 7.1epss 0.01

    A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). When processing a DHCP OFFER message, the DHCP client application does not validate the length of the Vendor option(s), leading…

  • CVE-2021-31346HigNov 9, 2021
    risk 0.53cvss 8.2epss 0.02

    A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions <…

  • CVE-2021-31345HigNov 9, 2021
    risk 0.49cvss 7.5epss 0.02

    A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions). The total length of an UDP payload (set in the IP header) is unchecked. This may lead to…

  • CVE-2020-23572HigNov 8, 2021
    risk 0.57cvss 8.8epss 0.01

    BEESCMS v4.0 was discovered to contain an arbitrary file upload vulnerability via the component /admin/upload.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.

  • CVE-2021-24844HigNov 8, 2021
    risk 0.47cvss 7.2epss 0.01

    The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL statement in the admin dashboard, leading to an SQL Injection issue

  • CVE-2021-24835HigNov 8, 2021
    risk 0.57cvss 8.8epss 0.01

    The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible WordPress plugin before 6.5.12, when used in combination with another WCFM - WooCommerce Multivendor plugin such as WCFM - WooCommerce Multivendor Marketplace, does not escape the…

  • CVE-2021-24829HigNov 8, 2021
    risk 0.57cvss 8.8epss 0.01

    The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issue

  • CVE-2021-24791HigNov 8, 2021
    risk 0.47cvss 7.2epss 0.05

    The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" request parameters before using them in a SQL statement when viewing the Snippets admin dashboard, leading to SQL injections

  • CVE-2021-24695HigNov 8, 2021
    risk 0.49cvss 7.5epss 0.02

    The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and…

  • CVE-2021-24669HigNov 8, 2021
    risk 0.57cvss 8.8epss 0.01

    The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter of the mzldr shortcode, which allows users with a role as low as Contributor to perform SQL injection.

  • CVE-2021-24647HigNov 8, 2021
    risk 0.53cvss 8.1epss 0.10

    The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing…

  • CVE-2021-24631HigNov 8, 2021
    risk 0.57cvss 8.8epss 0.02

    The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in a SQL statement, available to users as low as editor, leading to an authenticated SQL Injection

  • CVE-2021-24630HigNov 8, 2021
    risk 0.57cvss 8.8epss 0.02

    The Schreikasten WordPress plugin through 0.14.18 does not sanitise or escape the id GET parameter before using it in SQL statements in the comments dashboard from various actions, leading to authenticated SQL Injections which can be exploited by users as low as author

  • CVE-2021-24629HigNov 8, 2021
    risk 0.47cvss 7.2epss 0.01

    The Post Content XMLRPC WordPress plugin through 1.0 does not sanitise or escape multiple GET/POST parameters before using them in SQL statements in the admin dashboard, leading to an authenticated SQL Injections

  • CVE-2021-24628HigNov 8, 2021
    risk 0.47cvss 7.2epss 0.01

    The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL statement, when deleting a form in the admin dashboard, leading to an authenticated SQL injection

  • CVE-2021-24627HigNov 8, 2021
    risk 0.47cvss 7.2epss 0.07

    The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in a SQL statement, to select data to be displayed in the admin dashboard, leading to an authenticated SQL injection

  • CVE-2021-24626HigNov 8, 2021
    risk 0.57cvss 8.8epss 0.01

    The Chameleon CSS WordPress plugin through 1.2 does not have any CSRF and capability checks in all its AJAX calls, allowing any authenticated user, such as subscriber to call them and perform unauthorised actions. One of AJAX call, remove_css, also does not sanitise or escape…

  • CVE-2021-24625HigNov 8, 2021
    risk 0.47cvss 7.2epss 0.01

    The SpiderCatalog WordPress plugin through 1.7.3 does not sanitise or escape the 'parent' and 'ordering' parameters from the admin dashboard before using them in a SQL statement, leading to a SQL injection when adding a category

  • CVE-2021-24575HigNov 8, 2021
    risk 0.57cvss 8.8epss 0.01

    The School Management System – WPSchoolPress WordPress plugin before 2.1.10 does not properly sanitize or use prepared statements before using POST variable in SQL queries, leading to SQL injection in multiple actions available to various authenticated users, from simple…

  • CVE-2021-24537HigNov 8, 2021
    risk 0.47cvss 7.2epss 0.02

    The Similar Posts WordPress plugin through 3.1.5 allow high privilege users to execute arbitrary PHP code in an hardened environment (ie with DISALLOW_FILE_EDIT, DISALLOW_FILE_MODS and DISALLOW_UNFILTERED_HTML set to true) via the 'widget_rrm_similar_posts_condition' widget…

  • CVE-2021-39182HigNov 8, 2021
    risk 0.42cvss 7.5epss 0.01

    EnroCrypt is a Python module for encryption and hashing. Prior to version 1.1.4, EnroCrypt used the MD5 hashing algorithm in the hashing file. Beginners who are unfamiliar with hashes can face problems as MD5 is considered an insecure hashing algorithm. The vulnerability is…

  • CVE-2021-28022HigNov 8, 2021
    risk 0.49cvss 7.5epss 0.01

    Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate information via specially crafted HQL-compatible time-based SQL queries.

  • CVE-2021-41772HigNov 8, 2021
    risk 0.49cvss 7.5epss 0.03

    Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.

  • CVE-2021-41771HigNov 8, 2021
    risk 0.49cvss 7.5epss 0.04

    ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.

  • CVE-2021-42372HigNov 8, 2021
    risk 0.58cvss 8.8epss 0.06

    A shell command injection in the HW Events SNMP community in XoruX LPAR2RRD and STOR2RRD before 7.30 allows authenticated remote attackers to execute arbitrary shell commands as the user running the service.

  • CVE-2021-42370HigNov 8, 2021
    risk 0.49cvss 7.5epss 0.01

    A password mismanagement situation exists in XoruX LPAR2RRD and STOR2RRD before 7.30 because cleartext information is present in HTML password input fields in the device properties. (Viewing the passwords requires configuring a web browser to display HTML password input fields.)

  • CVE-2021-42076HigNov 8, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Barrier before 2.3.4. An attacker can cause memory exhaustion in the barriers component (aka the server-side implementation of Barrier) and barrierc by sending long TCP messages.

  • CVE-2021-42075HigNov 8, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Barrier before 2.3.4. The barriers component (aka the server-side implementation of Barrier) does not correctly close file descriptors for established TCP connections. An unauthenticated remote attacker can thus cause file descriptor exhaustion in the…

  • CVE-2021-42074HigNov 8, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Barrier before 2.3.4. An unauthenticated attacker can cause a segmentation fault in the barriers component (aka the server-side implementation of Barrier) by quickly opening and closing TCP connections while sending a Hello message for each TCP session.

  • CVE-2021-42073HigNov 8, 2021
    risk 0.00cvss 8.2epss 0.01

    An issue was discovered in Barrier before 2.4.0. An attacker can enter an active session state with the barriers component (aka the server-side implementation of Barrier) simply by supplying a client label that identifies a valid client configuration. This label is "Unnamed" by…

  • CVE-2021-42072HigNov 8, 2021
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Barrier before 2.4.0. The barriers component (aka the server-side implementation of Barrier) does not sufficiently verify the identify of connecting clients. Clients can thus exploit weaknesses in the provided protocol to cause denial-of-service or…

  • CVE-2021-31601HigNov 8, 2021
    risk 0.46cvss 7.1epss 0.01

    An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of…

  • CVE-2021-31599HigNov 8, 2021
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. A reports (.prpt) file allows the inclusion of BeanShell scripts to ease the production of complex reports. An authenticated user can run arbitrary code.

  • CVE-2021-43414HigNov 7, 2021
    risk 0.46cvss 7.0epss 0.00

    An issue was discovered in GNU Hurd before 0.9 20210404-9. The use of an authentication protocol in the proc server is vulnerable to man-in-the-middle attacks, which can be exploited for local privilege escalation to get full root access.