VYPR

CVEs

31,788 total · page 283 of 636

  • CVE-2022-47697CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Account takeover. Anyone can reset the password of the admin accounts.

  • CVE-2022-45172CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/registration/validateEmail endpoint, the /api/v1/vdeskintegration/user/adduser endpoint, and the /api/v1/registration/changePasswordUser endpoint. The web…

  • CVE-2023-22610CriJan 31, 2023
    risk 0.59cvss 9.1epss 0.01

    A CWE-863: Incorrect Authorization vulnerability exists that could cause Denial of Service against the Geo SCADA server when specific messages are sent to the server over the database server TCP port.

  • CVE-2023-24163CriJan 31, 2023
    risk 0.57cvss 9.8epss 0.01

    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.

  • CVE-2023-24162CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.

  • CVE-2022-47780CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Bangresto 1.0 via the itemID parameter.

  • CVE-2022-47035CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method to the /CPE endpoint.

  • CVE-2022-28331CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.02

    On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow.

  • CVE-2022-24963CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0.

  • CVE-2023-22900CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database.

  • CVE-2022-39060CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote attacker can exploit this vulnerability to access and modify HKEY_CURRENT_USER subkey (ex: AutoRUN) in Registry where malicious scripts can be executed to take…

  • CVE-2022-48175CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.02

    Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.

  • CVE-2022-32529CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted log data request messages. Affected Products: IGSS Data Server -…

  • CVE-2022-32527CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm cache data messages. Affected Products: IGSS Data Server -…

  • CVE-2022-32526CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted setting value messages. Affected Products: IGSS Data Server -…

  • CVE-2022-32525CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm data messages. Affected Products: IGSS Data Server -…

  • CVE-2022-32524CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted time reduced data messages. Affected Products: IGSS Data Server -…

  • CVE-2022-32523CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted online data request messages. Affected Products: IGSS Data Server -…

  • CVE-2022-32522CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted mathematically reduced data request messages. Affected Products: IGSS…

  • CVE-2022-32514CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when logging into a web page. Affected Products: C-Bus Network Automation Controller - LSS5500NAC (Versions prior to V1.10.0), Wiser for C-Bus Automation Controller…

  • CVE-2022-32513CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker brute forces the password. Affected Products: C-Bus Network Automation Controller - LSS5500NAC (Versions prior to V1.10.0), Wiser for C-Bus…

  • CVE-2022-48006CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploited via manipulation of the upext variable at /include/Model/Upload.php.

  • CVE-2022-4395CriJan 30, 2023
    risk 0.68cvss 9.8epss 0.18

    The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.

  • CVE-2022-23334CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.00

    The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have write access and escalate privileges via replacing NEWTESTREMOTEMANAGER.EXE.

  • CVE-2022-42484CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.06

    An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2023-24612CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.01

    The PdfBook extension through 2.0.5 before b07b6a64 for MediaWiki allows command injection via an option.

  • CVE-2022-27596CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QuTS hero, QTS: QuTS hero h5.0.1.2248 build…

  • CVE-2023-0556CriJan 27, 2023
    risk 0.64cvss 9.8epss 0.01

    The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several functions in versions up to, and including, 1.2.5. This makes it possible for unauthenticated attackers to obtain the blog metadata (via the function…

  • CVE-2022-39811CriJan 27, 2023
    risk 0.59cvss 9.1epss 0.01

    Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGui/SaveFileUploader. By not verifying permissions for access to resources, it allows an attacker to view pages that are not allowed, and modify the system…

  • CVE-2022-48108CriJan 27, 2023
    risk 0.64cvss 9.8epss 0.03

    D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask. This vulnerability allows attackers to escalate privileges to root via a crafted payload.

  • CVE-2022-48107CriJan 27, 2023
    risk 0.64cvss 9.8epss 0.03

    D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This vulnerability allows attackers to escalate privileges to root via a crafted payload.

  • CVE-2022-48011CriJan 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerrors function.

  • CVE-2022-48008CriJan 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-48066CriJan 27, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue in the component global.so of Totolink A830R V4.1.2cu.5182 allows attackers to bypass authentication via a crafted cookie.

  • CVE-2022-44298CriJan 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SiteServer CMS 7.1.3 is vulnerable to SQL Injection.

  • CVE-2022-46967CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.01

    An access control issue in Revenue Collection System v1.0 allows unauthenticated attackers to view the contents of /admin/DBbackup/ directory.

  • CVE-2022-46966CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Revenue Collection System v1.0 was discovered to contain a SQL injection vulnerability at step1.php.

  • CVE-2022-42493CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.04

    Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command…

  • CVE-2022-42492CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.03

    Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command…

  • CVE-2022-42491CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.03

    Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command…

  • CVE-2022-42490CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.03

    Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command…

  • CVE-2022-41991CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger this vulnerability.

  • CVE-2022-41030CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.03

    Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to…

  • CVE-2022-41019CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.02

    Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to…

  • CVE-2022-41018CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.02

    Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to…

  • CVE-2022-41017CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.02

    Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to…

  • CVE-2022-41016CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.02

    Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to…

  • CVE-2022-41015CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.02

    Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to…

  • CVE-2022-41014CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.02

    Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to…

  • CVE-2022-41013CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.02

    Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to…