VYPR

CVEs

31,787 total · page 294 of 636

  • CVE-2021-3821CriDec 12, 2022
    risk 0.64cvss 9.8epss 0.01

    A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Denial of Service when running HP Workpath solutions on potentially affected products.

  • CVE-2021-3437CriDec 12, 2022
    risk 0.65cvss 9.8epss 0.16

    Potential security vulnerabilities have been identified in an OMEN Gaming Hub SDK package which may allow escalation of privilege and/or denial of service. HP is releasing software updates to mitigate the potential vulnerabilities.

  • CVE-2022-3485CriDec 12, 2022
    risk 0.64cvss 9.8epss 0.01

    In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password by only supplying the serial number and thus gain full control of the device.

  • CVE-2022-46682CriDec 12, 2022
    risk 0.57cvss 9.8epss 0.01

    Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-45145CriDec 10, 2022
    risk 0.64cvss 9.8epss 0.01

    egg-compile.scm in CHICKEN 5.x before 5.3.1 allows arbitrary OS command execution during package installation via escape characters in a .egg file.

  • CVE-2022-23510CriDec 9, 2022
    risk 0.55cvss 9.6epss 0.01

    cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint. This issue has been resolved in version 0.31.24. Users are advised…

  • CVE-2022-4390CriDec 9, 2022
    risk 0.65cvss 10.0epss 0.01

    A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400 series of routers. IPv6 is enabled for the WAN interface by default on these devices. While there are firewall restrictions in place that define access restrictions for IPv4 traffic,…

  • CVE-2022-45290CriDec 9, 2022
    risk 0.59cvss 9.1epss 0.01

    Kbase Doc v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /web/IndexController.java.

  • CVE-2022-4170CriDec 9, 2022
    risk 0.64cvss 9.8epss 0.02

    The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.

  • CVE-2022-23493CriDec 9, 2022
    risk 0.59cvss 9.1epss 0.01

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Read in xrdp_mm_trans_process_drdynvc_channel_close() function. There are no known workarounds for this issue.…

  • CVE-2022-23480CriDec 9, 2022
    risk 0.59cvss 9.1epss 0.01

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in devredir_proc_client_devlist_announce_req() function. There are no known workarounds for this issue.…

  • CVE-2022-23479CriDec 9, 2022
    risk 0.59cvss 9.1epss 0.01

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in xrdp_mm_chan_data_in() function. There are no known workarounds for this issue. Users are advised to…

  • CVE-2022-23478CriDec 9, 2022
    risk 0.59cvss 9.1epss 0.01

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open() function. There are no known workarounds for this issue.…

  • CVE-2022-23477CriDec 9, 2022
    risk 0.59cvss 9.1epss 0.01

    xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a buffer over flow in audin_send_open() function. There are no known workarounds for this issue. Users are advised to upgrade.

  • CVE-2022-33186CriDec 8, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in Brocade Fabric OS software v9.1.1, v9.0.1e, v8.2.3c, v7.4.2j, and earlier versions could allow a remote unauthenticated attacker to execute on a Brocade Fabric OS switch commands capable of modifying zoning, disabling the switch, disabling ports, and modifying…

  • CVE-2022-44938CriDec 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.

  • CVE-2022-45506CriDec 8, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.

  • CVE-2022-45497CriDec 8, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the tpi_get_ping_output function at /goform/exeCommand.

  • CVE-2022-45550CriDec 7, 2022
    risk 0.64cvss 9.8epss 0.01

    AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE).

  • CVE-2022-44351CriDec 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Skycaiji v2.5.1 was discovered to contain a deserialization vulnerability via /SkycaijiApp/admin/controller/Mystore.php.

  • CVE-2022-44371CriDec 7, 2022
    risk 0.64cvss 9.8epss 0.01

    hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).

  • CVE-2022-42458CriDec 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Authentication bypass using an alternate path or channel vulnerability in bingo!CMS version1.7.4.1 and earlier allows a remote unauthenticated attacker to upload an arbitrary file. As a result, an arbitrary script may be executed and/or a file may be altered.

  • CVE-2022-46742CriDec 7, 2022
    risk 0.58cvss 10.0epss 0.01

    Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.

  • CVE-2022-45026CriDec 7, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue in Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom allows attackers to execute arbitrary commands during the GFM export process.

  • CVE-2022-45025CriDec 7, 2022
    risk 0.66cvss 9.8epss 0.35

    Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerability via the PDF file import function.

  • CVE-2022-45010CriDec 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Simple Phone Book/Directory Web App v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at /PhoneBook/edit.php.

  • CVE-2022-42699CriDec 6, 2022
    risk 0.59cvss 9.1epss 0.01

    Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.

  • CVE-2022-45359CriDec 6, 2022
    risk 0.65cvss 9.8epss 0.14

    Unauth. Arbitrary File Upload vulnerability in YITH WooCommerce Gift Cards premium plugin <= 3.19.0 on WordPress.

  • CVE-2022-42888CriDec 6, 2022
    risk 0.64cvss 9.8epss 0.01

    Unauth. Privilege Escalation vulnerability in ARMember premium plugin <= 5.5.1 on WordPress.

  • CVE-2022-46332CriDec 6, 2022
    risk 0.62cvss 9.6epss 0.01

    The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin privileges within the user interface. This affects all versions 8.19.0 and below.

  • CVE-2022-44900CriDec 6, 2022
    risk 0.52cvss 9.1epss 0.02

    A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.

  • CVE-2022-46161CriDec 6, 2022
    risk 0.65cvss 10.0epss 0.02

    pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfmake contains an unsafe evaluation of user controlled input. Users of pdfmake are thus subject to arbitrary code execution in the context of the process running…

  • CVE-2022-41559CriDec 6, 2022
    risk 0.61cvss 9.3epss 0.01

    The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to exploit an open redirect on the affected system. A successful attack using this vulnerability requires human…

  • CVE-2022-46383CriDec 6, 2022
    risk 0.64cvss 9.8epss 0.01

    RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 through 4.8.5, 4.9 through 4.9.12, and 4.10 through 4.10.8 has exposed a privileged token via a public API endpoint (Incorrect Access Control). The token can be used to escalate privileges within the Digital Rebar…

  • CVE-2020-6627CriDec 6, 2022
    risk 0.04cvss 9.8epss 0.12

    The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.

  • CVE-2022-40918CriDec 6, 2022
    risk 0.64cvss 9.8epss 0.02

    Buffer overflow in firmware lewei_cam binary version 2.0.10 in Force 1 Discovery Wifi U818A HD+ FPV Drone allows attacker to gain remote code execution as root user via a specially crafted UDP packet. Please update the Reference section to these links > http://thiscomputer.com/…

  • CVE-2022-38337CriDec 6, 2022
    risk 0.59cvss 9.1epss 0.01

    When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this as an invalid login attempt which can result in a Denial of Service (DoS) for the user if services like fail2ban are used.

  • CVE-2022-43549CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.01

    Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechanisms.

  • CVE-2022-35255CriDec 5, 2022
    risk 0.59cvss 9.1epss 0.02

    A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource()…

  • CVE-2022-32224CriDec 5, 2022
    risk 0.57cvss 9.8epss 0.02

    A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an…

  • CVE-2022-32221CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.04

    When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This…

  • CVE-2022-30123CriDec 5, 2022
    risk 0.58cvss 10.0epss 0.02

    A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.

  • CVE-2022-27773CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.03

    A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated privileges.

  • CVE-2022-46169CriKEVDec 5, 2022
    risk 0.23cvss 9.8epss 1.00

    Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if…

  • CVE-2022-46164CriDec 5, 2022
    risk 0.58cvss 9.4epss 0.49

    NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1.…

  • CVE-2022-45481CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.02

    The default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute arbitrary code with no prior authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • CVE-2022-45479CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.02

    PC Keyboard allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • CVE-2022-44039CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.01

    Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker can overwrite system files like [system.conf] and [passwd], this occurs because the insecure usage of "fopen" system function with…

  • CVE-2022-45477CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.02

    Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • CVE-2022-45822CriDec 5, 2022
    risk 0.65cvss 10.0epss 0.01

    Unauth. SQL Injection (SQLi) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress.