VYPR

CVEs

101,972 total · page 1251 of 2,040

  • CVE-2021-36185HigNov 2, 2021
    risk 0.57cvss 8.8epss 0.02

    A improper neutralization of special elements used in an OS command ('OS Command Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.

  • CVE-2021-36184HigNov 2, 2021
    risk 0.57cvss 8.8epss 0.01

    A improper neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclosure device, users and database information via crafted HTTP requests.

  • CVE-2021-36183HigNov 2, 2021
    risk 0.48cvss 7.4epss 0.00

    An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates.

  • CVE-2021-41238HigNov 2, 2021
    risk 0.56cvss 8.6epss 0.01

    Hangfire is an open source system to perform background job processing in a .NET or .NET Core applications. No Windows Service or separate process required. Dashboard UI in Hangfire.Core uses authorization filters to protect it from showing sensitive data to unauthorized users.…

  • CVE-2021-41232HigNov 2, 2021
    risk 0.46cvss 8.1epss 0.01

    Thunderdome is an open source agile planning poker tool in the theme of Battling for points. In affected versions there is an LDAP injection vulnerability which affects instances with LDAP authentication enabled. The provided username is not properly escaped. This issue has been…

  • CVE-2020-23686HigNov 2, 2021
    risk 0.57cvss 8.8epss 0.01

    Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified impacts.

  • CVE-2020-21574HigNov 2, 2021
    risk 0.49cvss 7.5epss 0.01

    Buffer overflow vulnerability in YotsuyaNight c-http v0.1.0, allows attackers to cause a denial of service via a long url request which is passed to the delimitedread function.

  • CVE-2020-21572HigNov 2, 2021
    risk 0.00cvss 7.5epss 0.01

    Buffer overflow vulnerability in function src_parser_trans_stage_1_2_3 trgil gilcc before commit 803969389ca9c06237075a7f8eeb1a19e6651759, allows attackers to cause a denial of service.

  • CVE-2020-20658HigNov 2, 2021
    risk 0.49cvss 7.5epss 0.01

    Buffer overflow vulnerability in fcovatti libiec_iccp_mod v1.5, allows attackers to cause a denail of service when trying to calloc an unexpectiedly large space.

  • CVE-2020-20657HigNov 2, 2021
    risk 0.49cvss 7.5epss 0.01

    Buffer overflow vulnerability in fcovatti libiec_iccp_mod v1.5, allows attackers to cause a denial of service via an unexpected packet while trying to connect.

  • CVE-2020-18438HigNov 2, 2021
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in qinggan phpok 5.1, allows attackers to disclose sensitive information, via the title parameter to admin.php.

  • CVE-2021-29888HigNov 2, 2021
    risk 0.57cvss 8.8epss 0.00

    IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 207123.

  • CVE-2021-29875HigNov 2, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information due to a insecure third party domain access vulnerability. IBM X-Force ID: 206572.

  • CVE-2021-29737HigNov 2, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of the REST API server certificate. IBM X-Force ID: 201301.

  • CVE-2021-36925HigNov 2, 2021
    risk 0.51cvss 7.8epss 0.00

    RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve an arbitrary read or write operation from/to physical memory (leading to Escalation of Privileges, Denial of Service, Code Execution, and…

  • CVE-2021-36924HigNov 2, 2021
    risk 0.51cvss 7.8epss 0.00

    RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (leading to Escalation of Privileges, Denial of Service, and Code Execution) via a crafted Device IO Control packet to a device.

  • CVE-2021-36923HigNov 2, 2021
    risk 0.51cvss 7.8epss 0.00

    RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve unauthorized access to USB device privileged IN and OUT instructions (leading to Escalation of Privileges, Denial of Service, Code Execution, and…

  • CVE-2021-36922HigNov 2, 2021
    risk 0.51cvss 7.8epss 0.00

    RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve unauthorized access to USB devices (Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted Device IO…

  • CVE-2021-42763HigNov 2, 2021
    risk 0.49cvss 7.5epss 0.01

    Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the cluster manager forwards a HTTP request from the pluggable UI (query workbench etc) to the specific service. In the backtrace, the Basic Auth Header included…

  • CVE-2021-37842HigNov 2, 2021
    risk 0.49cvss 7.5epss 0.01

    metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials can get leaked in debug logs. Config key tombstone purging was added in Couchbase Server 7.0.0. This issue happens when a config key, which is being logged, has…

  • CVE-2021-3765HigNov 2, 2021
    risk 0.42cvss 7.5epss 0.02

    validator.js is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-41187HigNov 1, 2021
    risk 0.53cvss 8.1epss 0.01

    DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability has been found in specific versions of DHIS2. This vulnerability affects the API endpoints for /api/trackedEntityInstances and api/events…

  • CVE-2021-39341HigNov 1, 2021
    risk 0.55cvss 8.2epss 0.23

    The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to exploit inject malicious…

  • CVE-2021-39333HigNov 1, 2021
    risk 0.53cvss 8.1epss 0.01

    The Hashthemes Demo Importer Plugin <= 1.1.1 for WordPress contained several AJAX functions which relied on a nonce which was visible to all logged-in users for access control, allowing them to execute a function that truncated nearly all database tables and removed the contents…

  • CVE-2021-31849HigNov 1, 2021
    risk 0.55cvss 8.4epss 0.01

    SQL injection vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker logged into ePO as an administrator to inject arbitrary SQL into the ePO database through the user management section of the DLP ePO extension.

  • CVE-2021-31848HigNov 1, 2021
    risk 0.55cvss 8.4epss 0.01

    Cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker to highjack an active DLP ePO administrator session by convincing the logged in administrator to click on a carefully crafted link in the case…

  • CVE-2021-38847HigNov 1, 2021
    risk 0.57cvss 8.8epss 0.01

    S-Cart v6.4.1 and below was discovered to contain an arbitrary file upload vulnerability in the Editor module on the Admin panel. This vulnerability allows attackers to execute arbitrary code via a crafted IMG file.

  • CVE-2021-3704HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.01

    Potential security vulnerabilities have been discovered on a certain HP LaserJet Pro printer that may allow a Denial of Service on the device.

  • CVE-2021-3440HigNov 1, 2021
    risk 0.51cvss 7.8epss 0.00

    HP Print and Scan Doctor, an application within the HP Smart App for Windows, is potentially vulnerable to local elevation of privilege.

  • CVE-2021-27005HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.01

    Clustered Data ONTAP versions 9.6 and higher prior to 9.6P16, 9.7P16, 9.8P7 and 9.9.1P3 are susceptible to a vulnerability which could allow a remote attacker to cause a crash of the httpd server.

  • CVE-2020-28702HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.01

    A SQL injection vulnerability in TopicMapper.xml of PybbsCMS v5.2.1 allows attackers to access sensitive database information.

  • CVE-2021-42557HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.02

    In Jeedom through 4.1.19, a bug allows a remote attacker to bypass API access and retrieve users credentials.

  • CVE-2021-25877HigNov 1, 2021
    risk 0.47cvss 7.2epss 0.02

    AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php.

  • CVE-2021-25874HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.02

    AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.

  • CVE-2021-27644HigNov 1, 2021
    risk 0.57cvss 8.8epss 0.02

    In Apache DolphinScheduler before 1.3.6 versions, authorized users can use SQL injection in the data source center. (Only applicable to MySQL data source with internal login account password)

  • CVE-2021-24809HigNov 1, 2021
    risk 0.57cvss 8.8epss 0.01

    The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_better_messages_leave_chat, bp_better_messages_join_chat, bp_messages_leave_thread, bp_messages_mute_thread, bp_messages_unmute_thread,…

  • CVE-2021-24717HigNov 1, 2021
    risk 0.57cvss 8.8epss 0.01

    The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

  • CVE-2020-36503HigNov 1, 2021
    risk 0.52cvss 8.0epss 0.01

    The Connections Business Directory WordPress plugin before 9.7 does not validate or sanitise some connections' fields, which could lead to a CSV injection issue

  • CVE-2018-25019HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.02

    The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server

  • CVE-2015-20067HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.08

    The WP Attachment Export WordPress plugin before 0.2.4 does not have proper access controls, allowing unauthenticated users to download the XML data that holds all the details of attachments/posts on a Wordpress

  • CVE-2021-40348HigNov 1, 2021
    risk 0.00cvss 8.8epss 0.02

    Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize the configuration filename used to append Spacewalk-specific key-value pair. The script is intended to be run by the tomcat user account with Sudo, according to…

  • CVE-2021-42694HigNov 1, 2021
    risk 0.54cvss 8.3epss 0.04

    An issue was discovered in the character definitions of the Unicode Specification through 14.0. The specification allows an adversary to produce source code identifiers such as function names using homoglyphs that render visually identical to a target identifier. Adversaries can…

  • CVE-2021-42574HigNov 1, 2021
    risk 0.55cvss 8.3epss 0.12

    An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens…

  • CVE-2021-20838HigNov 1, 2021
    risk 0.49cvss 7.5epss 0.01

    Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition by processing a specially crafted XML document.

  • CVE-2021-1120HigOct 29, 2021
    risk 0.46cvss 7.0epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a string provided by the guest OS may not be properly null terminated. The guest OS or attacker has no ability to push content to the plugin through this vulnerability, which may lead…

  • CVE-2021-1119HigOct 29, 2021
    risk 0.46cvss 7.1epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can double-free a pointer, which may lead to denial of service. This flaw may result in a write-what-where condition, allowing an attacker to execute arbitrary code impacting…

  • CVE-2021-1118HigOct 29, 2021
    risk 0.51cvss 7.8epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to execute privileged operations by the guest OS, which may lead to information disclosure, data tampering, escalation of privileges, and denial of service

  • CVE-2021-41746HigOct 29, 2021
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability exists in all versions of Yonyou TurboCRM.via the orgcode parameter in changepswd.php. Attackers can use the vulnerabilities to obtain sensitive database information.

  • CVE-2021-41189HigOct 29, 2021
    risk 0.40cvss 7.2epss 0.02

    DSpace is an open source turnkey repository application. In version 7.0, any community or collection administrator can escalate their permission up to become system administrator. This vulnerability only exists in 7.0 and does not impact 6.x or below. This issue is patched in…

  • CVE-2021-41645HigOct 29, 2021
    risk 0.57cvss 8.8epss 0.03

    Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to inject arbitrary code via the image upload field. .