VYPR

CVEs

31,787 total · page 295 of 636

  • CVE-2022-42496CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.02

    OS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain appkey of the product and execute an arbitrary OS command on the product.

  • CVE-2022-41642CriDec 5, 2022
    risk 0.57cvss 9.8epss 0.02

    OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.61 and earlier allows a remote attacker to execute an arbitrary OS command when processing compression and decompression on the product.

  • CVE-2022-35508CriDec 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on…

  • CVE-2022-46414CriDec 4, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal.

  • CVE-2022-44945CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.

  • CVE-2022-44291CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.04

    webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.

  • CVE-2022-44290CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.04

    webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.

  • CVE-2022-2641CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow an attacker to perform unauthorized changes to the device, remotely execute arbitrary code, or cause a denial-of-service condition.

  • CVE-2022-3520CriDec 2, 2022
    risk 0.00cvss 9.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.

  • CVE-2022-44367CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setUplinkInfo.

  • CVE-2022-44366CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.10

    Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setDiagnoseInfo.

  • CVE-2022-44365CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda i21 V1.0.0.14(4656) has a stack overflow vulnerability via /goform/setSysPwd.

  • CVE-2022-44363CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setSnmpInfo.

  • CVE-2022-44362CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/AddSysLogRule.

  • CVE-2022-45482CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • CVE-2022-46366CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.04

    Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version…

  • CVE-2022-2807CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Algan Software Prens Student Information System allows SQL Injection. This issue affects Prens Student Information System: before 2.1.11.

  • CVE-2022-44930CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.03

    D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.

  • CVE-2022-44929CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.

  • CVE-2022-44928CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.03

    D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.

  • CVE-2022-43325CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.03

    An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input.

  • CVE-2022-43333CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.02

    Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_control.php.

  • CVE-2022-37016CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an…

  • CVE-2022-30528CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to execute arbitrary commands via the username parameter to /system/user/modules/mod_users/controller.php.

  • CVE-2022-3270CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.01

    In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.

  • CVE-2022-4221CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.05

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7.

  • CVE-2022-36431CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.

  • CVE-2022-44262CriDec 1, 2022
    risk 0.57cvss 9.8epss 0.01

    ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).

  • CVE-2022-44151CriNov 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.

  • CVE-2022-44136CriNov 30, 2022
    risk 0.57cvss 9.8epss 0.01

    Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).

  • CVE-2022-44097CriNov 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

  • CVE-2022-44096CriNov 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

  • CVE-2022-3751CriNov 29, 2022
    risk 0.57cvss 9.8epss 0.01

    SQL Injection in GitHub repository owncast/owncast prior to 0.0.13.

  • CVE-2022-44354CriNov 29, 2022
    risk 0.64cvss 9.8epss 0.02

    SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.

  • CVE-2022-44038CriNov 29, 2022
    risk 0.64cvss 9.8epss 0.02

    Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunner.cgi component.

  • CVE-2022-42109CriNov 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.

  • CVE-2022-44399CriNov 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/category.php.

  • CVE-2022-44401CriNov 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.

  • CVE-2022-44400CriNov 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.

  • CVE-2022-44283CriNov 28, 2022
    risk 0.64cvss 9.8epss 0.01

    AVS Audio Converter 10.3 is vulnerable to Buffer Overflow.

  • CVE-2022-41912CriNov 28, 2022
    risk 0.52cvss 9.1epss 0.02

    The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.

  • CVE-2022-3603CriNov 28, 2022
    risk 0.64cvss 9.8epss 0.01

    The Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list WordPress plugin before 2.0.69 does not validate data when outputting it back in a CSV file, which could lead to CSV injection.

  • CVE-2022-36193CriNov 28, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL injection in School Management System 1.0 allows remote attackers to modify or delete data, causing persistent changes to the application's content or behavior by using malicious SQL queries.

  • CVE-2022-43705CriNov 27, 2022
    risk 0.59cvss 9.1epss 0.00

    In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (November 2016).

  • CVE-2022-45933CriNov 27, 2022
    risk 0.68cvss 9.8epss 0.52

    KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was…

  • CVE-2022-45909CriNov 26, 2022
    risk 0.00cvss 9.1epss 0.01

    drachtio-server before 0.8.19 has a heap-based buffer over-read via a long Request-URI in an INVITE request.

  • CVE-2022-45908CriNov 26, 2022
    risk 0.57cvss 9.8epss 0.01

    In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution.

  • CVE-2022-45907CriNov 26, 2022
    risk 0.57cvss 9.8epss 0.01

    In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.

  • CVE-2022-44844CriNov 25, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCfg function.

  • CVE-2022-44843CriNov 25, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnClientCfg function.