VYPR

CVEs

101,972 total · page 1253 of 2,040

  • CVE-2021-43057HigOct 28, 2021
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in the Linux kernel before 5.14.8. A use-after-free in selinux_ptrace_traceme (aka the SELinux handler for PTRACE_TRACEME) could be used by local attackers to cause memory corruption and escalate privileges, aka CID-a3727a8bac0a. This occurs because of an…

  • CVE-2021-41191HigOct 27, 2021
    risk 0.00cvss 7.5epss 0.01

    Roblox-Purchasing-Hub is an open source Roblox product purchasing hub. A security risk in versions 1.0.1 and prior allowed people who have someone's API URL to get product files without an API key. This issue is fixed in version 1.0.2. As a workaround, add `@require_apikey` in…

  • CVE-2021-3903HigOct 27, 2021
    risk 0.00cvss 7.8epss 0.01

    vim is vulnerable to Heap-based Buffer Overflow

  • CVE-2021-3901HigOct 27, 2021
    risk 0.50cvss 8.8epss 0.01

    firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)

  • CVE-2021-40118HigOct 27, 2021
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to…

  • CVE-2021-40117HigOct 27, 2021
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in SSL/TLS message handler for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This…

  • CVE-2021-40116HigOct 27, 2021
    risk 0.56cvss 8.6epss 0.01

    Multiple Cisco products are affected by a vulnerability in Snort rules that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.The vulnerability is due to improper handling of the Block with Reset or Interactive…

  • CVE-2021-34793HigOct 27, 2021
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software operating in transparent mode could allow an unauthenticated, remote attacker to poison MAC address tables, resulting in a denial of service…

  • CVE-2021-34792HigOct 27, 2021
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the memory management of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due…

  • CVE-2021-34783HigOct 27, 2021
    risk 0.56cvss 8.6epss 0.02

    A vulnerability in the software-based SSL/TLS message handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service…

  • CVE-2021-34781HigOct 27, 2021
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the processing of SSH connections for multi-instance deployments of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to…

  • CVE-2021-34762HigOct 27, 2021
    risk 0.53cvss 8.1epss 0.02

    A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to perform a directory traversal attack on an affected device. The attacker would require valid device credentials. The…

  • CVE-2021-37807HigOct 27, 2021
    risk 0.49cvss 7.5epss 0.01

    An SQL Injection vulneraility exists in https://phpgurukul.com Online Shopping Portal 3.1 via the email parameter on the /check_availability.php endpoint that serves as a checker whether a new user's email is already exist within the database.

  • CVE-2021-37803HigOct 27, 2021
    risk 0.53cvss 8.1epss 0.02

    An SQL Injection vulnerability exists in Sourcecodester Online Covid Vaccination Scheduler System 1.0 via the username in lognin.php .

  • CVE-2021-29844HigOct 27, 2021
    risk 0.57cvss 8.8epss 0.01

    IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.

  • CVE-2021-29774HigOct 27, 2021
    risk 0.49cvss 7.5epss 0.01

    IBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.

  • CVE-2021-37221HigOct 27, 2021
    risk 0.57cvss 8.8epss 0.01

    A file upload vulnerability exists in Sourcecodester Customer Relationship Management System 1.0 via the account update option & customer create option, which could let a remote malicious user upload an arbitrary php file. .

  • CVE-2021-22101HigOct 27, 2021
    risk 0.49cvss 7.5epss 0.01

    Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers to cause denial of service by using REST HTTP requests with label_selectors on multiple V3 endpoints by generating an enormous SQL…

  • CVE-2021-41619HigOct 27, 2021
    risk 0.47cvss 7.2epss 0.03

    An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the application startup configuration. The installation configuration user interface (available to administrators) allows specifying arbitrary Java Virtual Machine startup…

  • CVE-2021-41872HigOct 27, 2021
    risk 0.49cvss 7.5epss 0.01

    Skyworth Digital Technology Penguin Aurora Box 41502 has a denial of service vulnerability, which can be exploited by attackers to cause a denial of service.

  • CVE-2021-34580HigOct 27, 2021
    risk 0.49cvss 7.5epss 0.01

    In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind of response the server sends for crafted invalid login attempts.

  • CVE-2021-37130HigOct 27, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a path traversal vulnerability in Huawei FusionCube 6.0.2.The vulnerability is due to that the software uses external input to construct a pathname that is intended to identify a directory that is located underneath a restricted parent directory, but the software does…

  • CVE-2021-37129HigOct 27, 2021
    risk 0.49cvss 7.5epss 0.01

    There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a module that does not properly verify input parameter. Successful exploit could cause out of bounds write leading to a denial of service condition.Affected…

  • CVE-2021-37127HigOct 27, 2021
    risk 0.47cvss 7.2epss 0.01

    There is a signature management vulnerability in some huawei products. An attacker can forge signature and bypass the signature check. During firmware update process, successful exploit this vulnerability can cause the forged system file overwrite the correct system file.…

  • CVE-2021-26610HigOct 27, 2021
    risk 0.47cvss 7.2epss 0.00

    The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.

  • CVE-2020-7867HigOct 27, 2021
    risk 0.52cvss 8.0epss 0.01

    An improper input validation vulnerability in Helpu solution could allow a local attacker to arbitrary file creation and execution without click file transfer menu. It is possible to file in arbitrary directory for user because the viewer program receive the file from agent with…

  • CVE-2011-4126HigOct 27, 2021
    risk 0.53cvss 8.1epss 0.01

    Race condition issues were found in Calibre at devices/linux_mount_helper.c allowing unprivileged users the ability to mount any device to anywhere.

  • CVE-2019-3556HigOct 26, 2021
    risk 0.00cvss 8.1epss 0.02

    HHVM supports the use of an "admin" server which accepts administrative requests over HTTP. One of those request handlers, dump-pcre-cache, can be used to output cached regular expressions from the current execution context into a file. The handler takes a parameter which…

  • CVE-2021-35499HigOct 26, 2021
    risk 0.52cvss 8.0epss 0.01

    The Web Reporting component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Stored Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected…

  • CVE-2021-41185HigOct 26, 2021
    risk 0.00cvss 8.8epss 0.01

    Mycodo is an environmental monitoring and regulation system. An exploit in versions prior to 8.12.7 allows anyone with access to endpoints to download files outside the intended directory. A patch has been applied and a release made. Users should upgrade to version 8.12.7. As a…

  • CVE-2021-41175HigOct 26, 2021
    risk 0.00cvss 7.3epss 0.01

    Pi-hole's Web interface (based on AdminLTE) provides a central location to manage one's Pi-hole and review the statistics generated by FTLDNS. Prior to version 5.8, cross-site scripting is possible when adding a client via the groups-clients management page. This issue was…

  • CVE-2021-37364HigOct 26, 2021
    risk 0.51cvss 7.8epss 0.01

    OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify permission to openclinic folders/files. A low privilege account is able to rename mysqld.exe or tomcat8.exe files located in bin folders and replace with a…

  • CVE-2021-37363HigOct 26, 2021
    risk 0.51cvss 7.8epss 0.02

    An Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.exe file located in bin folder and replace with a malicious file that would connect back to an attacking computer giving system level privileges (nt…

  • CVE-2021-41078HigOct 26, 2021
    risk 0.51cvss 7.8epss 0.01

    Nameko through 2.13.0 can be tricked into performing arbitrary code execution when deserializing the config file.

  • CVE-2021-37372HigOct 26, 2021
    risk 0.57cvss 8.8epss 0.03

    Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can upload malicious PHP files by updating their profile image to gain remote code execution.

  • CVE-2021-26609HigOct 26, 2021
    risk 0.49cvss 7.5epss 0.02

    A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type parameter. The order_type parameter makes a SQL query using unfiltered data. This vulnerability allows a remote attacker to steal user information.

  • CVE-2021-26607HigOct 26, 2021
    risk 0.53cvss 8.1epss 0.02

    An Improper input validation in execDefaultBrowser method of NEXACRO17 allows a remote attacker to execute arbitrary command on affected systems.

  • CVE-2021-40345HigOct 26, 2021
    risk 0.49cvss 7.2epss 0.23

    An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injection (within the name of the first file in the archive) allows an attacker to execute system commands.

  • CVE-2021-40344HigOct 26, 2021
    risk 0.52cvss 7.2epss 0.66

    An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary extensions as long as the MIME type corresponds to an image. Therefore it is possible to upload a crafted PHP script to achieve remote…

  • CVE-2021-40343HigOct 26, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios user to elevate their privileges to the root user.

  • CVE-2021-34595HigOct 26, 2021
    risk 0.53cvss 8.1epss 0.01

    A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.

  • CVE-2021-34593HigOct 26, 2021
    risk 0.49cvss 7.5epss 0.03

    In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be…

  • CVE-2021-34586HigOct 26, 2021
    risk 0.50cvss 7.5epss 0.13

    In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the CODESYS web server and may result in a denial-of-service condition.

  • CVE-2021-34585HigOct 26, 2021
    risk 0.49cvss 7.5epss 0.01

    In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser result is not checked under all conditions, a pointer dereference with an invalid address can occur. This leads to a denial of service situation.

  • CVE-2021-34583HigOct 26, 2021
    risk 0.49cvss 7.5epss 0.08

    Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.

  • CVE-2021-41307HigOct 26, 2021
    risk 0.49cvss 7.5epss 0.02

    Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of private projects and private filters via an Insecure Direct Object References (IDOR) vulnerability in the Workload Pie Chart Gadget. The affected versions are…

  • CVE-2021-41306HigOct 26, 2021
    risk 0.49cvss 7.5epss 0.02

    Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an Insecure Direct Object References (IDOR) vulnerability in the Average Time in Status Gadget. The affected versions are before version…

  • CVE-2021-41305HigOct 26, 2021
    risk 0.49cvss 7.5epss 0.01

    Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private projects and filters via an Insecure Direct Object References (IDOR) vulnerability in the Average Number of Times in Status Gadget. The affected versions are…

  • CVE-2021-41178HigOct 25, 2021
    risk 0.00cvss 8.8epss 0.02

    Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes an attacker able to download arbitrary SVG images from the host system, including user provided files. This could also be leveraged…

  • CVE-2021-41177HigOct 25, 2021
    risk 0.00cvss 8.1epss 0.01

    Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, Nextcloud Server did not implement a database backend for rate-limiting purposes. Any component of Nextcloud using rate-limits (as as `AnonRateThrottle` or…