VYPR

CVEs

101,972 total · page 1255 of 2,040

  • CVE-2021-38473HigOct 22, 2021
    risk 0.52cvss 8.0epss 0.01

    The affected product’s code base doesn’t properly control arguments for specific functions, which could lead to a stack overflow.

  • CVE-2021-38467HigOct 22, 2021
    risk 0.48cvss 7.3epss 0.01

    A specific function code receives a raw pointer supplied by the user and deallocates this pointer. The user can then control what memory regions will be freed and cause use-after-free condition.

  • CVE-2021-38465HigOct 22, 2021
    risk 0.52cvss 8.0epss 0.01

    The webinstaller is a Golang web server executable that enables the generation of an Auvesy image agent. Resource consumption can be achieved by generating large amounts of installations, which are then saved without limitation in the temp folder of the webinstaller executable.

  • CVE-2021-38463HigOct 22, 2021
    risk 0.48cvss 7.3epss 0.01

    The affected product does not properly control the allocation of resources. A user may be able to allocate unlimited memory buffers using API functions.

  • CVE-2021-38461HigOct 22, 2021
    risk 0.53cvss 8.2epss 0.01

    The affected product uses a hard-coded blowfish key for encryption/decryption processes. The key can be easily extracted from binaries.

  • CVE-2021-38459HigOct 22, 2021
    risk 0.53cvss 8.1epss 0.01

    The data of a network capture of the initial handshake phase can be used to authenticate at a SYSDBA level. If a specific .exe is not restarted often, it is possible to access the needed handshake packets between admin/client connections. Using the SYSDBA permission, an attacker…

  • CVE-2021-38455HigOct 22, 2021
    risk 0.48cvss 7.3epss 0.01

    The affected product’s OS Service does not verify any given parameter. A user can supply any type of parameter that will be passed to inner calls without checking the type of the parameter or the value.

  • CVE-2021-34362HigOct 22, 2021
    risk 0.57cvss 8.7epss 0.01

    A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of Media Streaming…

  • CVE-2021-41127HigOct 21, 2021
    risk 0.41cvss 7.3epss 0.01

    Rasa is an open source machine learning framework to automate text-and voice-based conversations. In affected versions a vulnerability exists in the functionality that loads a trained model `tar.gz` file which allows a malicious actor to craft a `model.tar.gz` file which can…

  • CVE-2021-39352HigOct 21, 2021
    risk 0.54cvss 7.2epss 0.56

    The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes it possible for an…

  • CVE-2021-39321HigOct 21, 2021
    risk 0.57cvss 8.8epss 0.02

    Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unvalidated user supplied inputs via the import_config function found in the…

  • CVE-2021-22034HigOct 21, 2021
    risk 0.49cvss 7.5epss 0.01

    Releases prior to VMware vRealize Operations Tenant App 8.6 contain an Information Disclosure Vulnerability.

  • CVE-2021-42716HigOct 21, 2021
    risk 0.00cvss 7.1epss 0.01

    An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially have crashed a service…

  • CVE-2021-41146HigOct 21, 2021
    risk 0.50cvss 8.8epss 0.01

    qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` URL handler. With certain applications, opening a specially crafted `qutebrowserurl:...` URL can lead…

  • CVE-2021-29873HigOct 21, 2021
    risk 0.53cvss 8.1epss 0.01

    IBM Flash System 900 could allow an authenticated attacker to obtain sensitive information and cause a denial of service due to a restricted shell escape vulnerability. IBM X-Force ID: 206229.

  • CVE-2021-20120HigOct 21, 2021
    risk 0.57cvss 8.8epss 0.01

    The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user.

  • CVE-2021-41790HigOct 21, 2021
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded outside of the Data Dictionary. This could allow a logged-in attacker to execute arbitrary code inside a sandboxed environment.

  • CVE-2021-42108HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    Unnecessary privilege vulnerabilities in the Web Console of Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability…

  • CVE-2021-42107HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must…

  • CVE-2021-42106HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must…

  • CVE-2021-42105HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must…

  • CVE-2021-42104HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must…

  • CVE-2021-42103HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in…

  • CVE-2021-42102HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2021-42101HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in…

  • CVE-2021-42012HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.01

    A stack-based buffer overflow vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute…

  • CVE-2021-42011HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with escalated privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged…

  • CVE-2021-23139HigOct 21, 2021
    risk 0.49cvss 7.5epss 0.01

    A null pointer vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an attacker to crash the CGI program on affected installations.

  • CVE-2021-1529HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the system CLI. An attacker could exploit this vulnerability…

  • CVE-2021-42097HigOct 21, 2021
    risk 0.52cvss 8.0epss 0.01

    GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A csrf_token value is not specific to a single user account. An attacker can obtain a value within the context of an unprivileged user account, and then use that value in a CSRF attack against an admin (e.g., for…

  • CVE-2021-42771HigOct 20, 2021
    risk 0.44cvss 7.8epss 0.01

    Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.

  • CVE-2021-42765HigOct 20, 2021
    risk 0.49cvss 7.5epss 0.01

    The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to leverage network delay to cause a denial of service (indefinite stalling of consensus decisions).

  • CVE-2021-41167HigOct 20, 2021
    risk 0.42cvss 7.5epss 0.02

    modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises. In affected versions a bug affecting two of the functions in this library: forEachSeries and forEachLimit. They should limit the concurrency of some actions but,…

  • CVE-2021-21744HigOct 20, 2021
    risk 0.49cvss 7.5epss 0.01

    ZTE MF971R product has a configuration file control vulnerability. An attacker could use this vulnerability to modify the configuration parameters of the device, causing some security functions of the device to be disabled.

  • CVE-2021-23452HigOct 20, 2021
    risk 0.56cvss 8.6epss 0.01

    This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.

  • CVE-2021-25970HigOct 20, 2021
    risk 0.50cvss 8.8epss 0.01

    Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have access to the application even after the password was changed.

  • CVE-2021-35662HigOct 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2021-35661HigOct 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2021-35660HigOct 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2021-35659HigOct 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2021-35658HigOct 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2021-35657HigOct 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2021-35656HigOct 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2021-35654HigOct 20, 2021
    risk 0.49cvss 7.5epss 0.02

    Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

  • CVE-2021-35653HigOct 20, 2021
    risk 0.50cvss 7.7epss 0.01

    Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2021-35651HigOct 20, 2021
    risk 0.55cvss 8.5epss 0.01

    Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2021-35620HigOct 20, 2021
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2021-35619HigOct 20, 2021
    risk 0.46cvss 7.1epss 0.01

    Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 19c and 21c. Difficult to exploit vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to…

  • CVE-2021-35610HigOct 20, 2021
    risk 0.46cvss 7.1epss 0.02

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL…

  • CVE-2021-35599HigOct 20, 2021
    risk 0.53cvss 8.2epss 0.00

    Vulnerability in the Zero Downtime DB Migration to Cloud component of Oracle Database Server. The supported version that is affected is 21c. Easily exploitable vulnerability allows high privileged attacker having Local Logon privilege with logon to the infrastructure where Zero…