VYPR

CVEs

101,972 total · page 1252 of 2,040

  • CVE-2021-41675HigOct 29, 2021
    risk 0.47cvss 7.2epss 0.03

    A Remote Code Execution (RCE) vulnerabilty exists in Sourcecodester E-Negosyo System 1.0 in /admin/produts/controller.php via the doInsert function, which validates images with getImageSizei. .

  • CVE-2021-39179HigOct 29, 2021
    risk 0.00cvss 8.8epss 0.02

    DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL Injection vulnerability in the Tracker component in DHIS2 Server allows authenticated remote attackers to execute arbitrary SQL commands via unspecified vectors. This…

  • CVE-2021-22038HigOct 29, 2021
    risk 0.57cvss 8.8epss 0.01

    On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so it does not block the installation directory). This temporary location is not randomized and does not restrict access to…

  • CVE-2021-22037HigOct 29, 2021
    risk 0.51cvss 7.8epss 0.00

    Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The full path to the command is not enforced, which results in a search in the search path until a binary can be identified. This makes the installer/uninstaller…

  • CVE-2021-31627HigOct 29, 2021
    risk 0.57cvss 8.8epss 0.01

    Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the index parameter.

  • CVE-2021-31624HigOct 29, 2021
    risk 0.57cvss 8.8epss 0.01

    Buffer Overflow vulnerability in Tenda AC9 V1.0 through V15.03.05.19(6318), and AC9 V3.0 V15.03.06.42_multi, allows attackers to execute arbitrary code via the urls parameter.

  • CVE-2021-25742HigOct 29, 2021
    risk 0.50cvss 7.6epss 0.02

    A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.

  • CVE-2020-23549HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted .cr2 file, related to a "Data from Faulting Address controls Branch Selection starting at FORMATS!GetPlugInInfo+0x00000000000047f6".

  • CVE-2020-23546HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    IrfanView 4.54 allows attackers to cause a denial of service or possibly other unspecified impacts via a crafted XBM file, related to a "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FORMATS!ReadMosaic+0x0000000000000981.

  • CVE-2021-30840HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    This issue was addressed with improved checks. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted dfont file may lead to arbitrary code execution.

  • CVE-2021-30834HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, watchOS 8, Security Update 2021-007 Catalina. Processing a malicious audio file may result in unexpected application termination or…

  • CVE-2021-30824HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to execute arbitrary code with kernel privileges.

  • CVE-2021-30821HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may be able to execute arbitrary code with kernel privileges.

  • CVE-2021-30818HigOct 28, 2021
    risk 0.57cvss 8.8epss 0.02

    A type confusion issue was addressed with improved state handling. This issue is fixed in iOS 14.8 and iPadOS 14.8, tvOS 15, iOS 15 and iPadOS 15, Safari 15, watchOS 8. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2021-30814HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    A memory corruption issue was addressed with improved input validation. This issue is fixed in tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing a maliciously crafted image may lead to arbitrary code execution.

  • CVE-2021-30809HigOct 28, 2021
    risk 0.57cvss 8.8epss 0.01

    A use after free issue was addressed with improved memory management. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2020-9897HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1. Processing a maliciously crafted PDF may lead to arbitrary code execution.

  • CVE-2021-22044HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapping`annotations over Feign client interfaces, can be involuntarily exposing endpoints corresponding to `@RequestMapping`-annotated…

  • CVE-2020-7875HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.

  • CVE-2021-3823HigOct 28, 2021
    risk 0.46cvss 7.1epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects: Bitdefender GravityZone versions prior…

  • CVE-2021-3579HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    Incorrect Default Permissions vulnerability in the bdservicehost.exe and Vulnerability.Scan.exe components as used in Bitdefender Endpoint Security Tools for Windows, Total Security allows a local attacker to elevate privileges to NT AUTHORITY\SYSTEM This issue affects:…

  • CVE-2021-3576HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    Execution with Unnecessary Privileges vulnerability in Bitdefender Endpoint Security Tools, Total Security allows a local attacker to elevate to 'NT AUTHORITY\System. Impersonation enables the server thread to perform actions on behalf of the client but within the limits of the…

  • CVE-2021-37254HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.

  • CVE-2021-37001HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Register tampering vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow the register value to be modified.

  • CVE-2021-36999HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.01

    There is a Buffer overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by sending malicious images and inducing users to open the images may cause remote code execution.

  • CVE-2021-36995HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Unauthorized file access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by modifying soft links may tamper with the files restored from backups.

  • CVE-2021-36993HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Memory leaks vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

  • CVE-2021-36992HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Public key verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-36991HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Unauthorized file access vulnerability in Huawei Smartphone due to unstandardized path input.Successful exploitation of this vulnerability by creating malicious file paths can cause unauthorized file access.

  • CVE-2021-36988HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Parameter verification issue in Huawei Smartphone.Successful exploitation of this vulnerability can affect service integrity.

  • CVE-2021-36985HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Code injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may exhaust system resources and cause the system to restart.

  • CVE-2021-22491HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

  • CVE-2021-22488HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Unauthorized file access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability by modifying soft links may tamper with the files restored from backups.

  • CVE-2021-22487HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Out-of-bounds read vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service availability.

  • CVE-2021-22486HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a issue of Unstandardized field names in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-22485HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a SSID vulnerability with Wi-Fi network connections in Huawei devices.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-22483HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a issue of IP address spoofing in Huawei Smartphone. Successful exploitation of this vulnerability may cause DoS.

  • CVE-2021-22481HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Verification errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-22473HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Authentication vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-22472HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-22470HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Privileges Controls vulnerability. Local attackers may exploit this vulnerability to expand the Recording Trusted Domain.

  • CVE-2021-22469HigOct 28, 2021
    risk 0.46cvss 7.1epss 0.00

    A component of the HarmonyOS has a Out-of-bounds Read vulnerability. Local attackers may exploit this vulnerability to cause kernel out-of-bounds read.

  • CVE-2021-22458HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. Local attackers may exploit this vulnerability to cause arbitrary code execution.

  • CVE-2021-22451HigOct 28, 2021
    risk 0.51cvss 7.8epss 0.00

    A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulnerability to cause memory overwriting.

  • CVE-2021-22406HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an Uncaught Exception vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the app to exit unexpectedly.

  • CVE-2021-22405HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Configuration defects in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

  • CVE-2021-22402HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause DoS attacks.

  • CVE-2021-22401HigOct 28, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Remote DoS vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability can affect service integrity.

  • CVE-2021-37915HigOct 28, 2021
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered on the Grandstream HT801 Analog Telephone Adaptor before 1.0.29.8. From the limited configuration shell, it is possible to set the malicious gdb_debug_server variable. As a result, after a reboot, the device downloads and executes malicious scripts from…

  • CVE-2021-37748HigOct 28, 2021
    risk 0.58cvss 8.8epss 0.07

    Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated users to execute arbitrary code as root via a crafted manage_if setting, thus bypassing the intended restrictions of this shell…