VYPR

CVEs

31,787 total · page 296 of 636

  • CVE-2022-45152CriNov 25, 2022
    risk 0.00cvss 9.1epss 0.01

    A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An…

  • CVE-2022-45476CriNov 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the application is vulnerable to insecure file upload.

  • CVE-2022-41705CriNov 25, 2022
    risk 0.64cvss 9.8epss 0.02

    Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.

  • CVE-2022-45207CriNov 25, 2022
    risk 0.57cvss 9.8epss 0.01

    Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.

  • CVE-2022-45206CriNov 25, 2022
    risk 0.57cvss 9.8epss 0.01

    Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.

  • CVE-2022-37721CriNov 25, 2022
    risk 0.59cvss 9.0epss 0.01

    PyroCMS 3.9 is vulnerable to a stored Cross Site Scripting (XSS_ when a low privileged user such as an author, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation.

  • CVE-2022-37720CriNov 25, 2022
    risk 0.59cvss 9.0epss 0.01

    Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation when the…

  • CVE-2022-36133CriNov 25, 2022
    risk 0.59cvss 9.1epss 0.01

    The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass.

  • CVE-2022-4135CriKEVNov 25, 2022
    risk 0.70cvss 9.6epss 0.32

    Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-29830CriNov 25, 2022
    risk 0.59cvss 9.1epss 0.01

    Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.065T allows a remote unauthenticated attacker to disclose or tamper with sensitive…

  • CVE-2022-2650CriNov 24, 2022
    risk 0.57cvss 9.8epss 0.01

    Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2.

  • CVE-2022-4136CriNov 24, 2022
    risk 0.00cvss 9.8epss 0.01

    Dangerous method exposed which can lead to RCE in qmpass/leadshop v1.4.15 allows an attacker to control the target host by calling any function in leadshop.php via the GET method.

  • CVE-2022-45872CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.01

    iTerm2 before 3.4.18 mishandles a DECRQSS response.

  • CVE-2022-45276CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated attackers to obtain the Administrator account password.

  • CVE-2022-44120CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.01

    dedecmdv6 6.1.9 is vulnerable to SQL Injection. via sys_sql_query.php.

  • CVE-2022-44118CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.02

    dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.

  • CVE-2022-44117CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not ship with any support for SQL.

  • CVE-2022-43196CriNov 23, 2022
    risk 0.59cvss 9.1epss 0.01

    dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.

  • CVE-2022-41934CriNov 23, 2022
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on commonly accessible documents including the menu macro can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to…

  • CVE-2022-41931CriNov 23, 2022
    risk 0.57cvss 9.9epss 0.01

    xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'). Any user with view rights on commonly accessible documents including the icon picker macro can execute arbitrary Groovy, Python or Velocity code in…

  • CVE-2022-41928CriNov 23, 2022
    risk 0.64cvss 9.9epss 0.01

    XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml. The issue can also be reproduced by inserting the dangerous payload in the `height` or `alt` macro properties. This has been patched in…

  • CVE-2022-41924CriNov 23, 2022
    risk 0.56cvss 9.6epss 0.02

    A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemon `tailscaled`, which can then be used to remotely execute code. In the Tailscale Windows client, the local API was bound to a local TCP socket, and…

  • CVE-2022-41923CriNov 23, 2022
    risk 0.59cvss 9.1epss 0.02

    Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to one endpoint (i.e. the targeted endpoint) using the authorization requirements of a different endpoint (i.e. the donor endpoint). In some Grails framework…

  • CVE-2022-41875CriNov 23, 2022
    risk 0.65cvss 10.0epss 0.02

    A remote code execution (RCE) vulnerability in Optica allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Specially crafted JSON payloads may lead to RCE (remote code execution) on the attacked system running Optica. The vulnerability…

  • CVE-2021-35284CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in function get_user in login_manager.php in rizalafani cms-php v1.

  • CVE-2022-44255CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data.

  • CVE-2022-44252CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.

  • CVE-2022-44251CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.

  • CVE-2022-44250CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.

  • CVE-2022-44249CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.

  • CVE-2022-44139CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.

  • CVE-2022-45462CriNov 23, 2022
    risk 0.57cvss 9.8epss 0.03

    Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher

  • CVE-2022-43213CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php.

  • CVE-2020-23591CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an attacker to upload arbitrary files through " /mgm_dev_upgrade.asp " which can "delete every file for Denial of Service (using 'rm -rf *.*' in the code), reverse…

  • CVE-2020-23584CriNov 23, 2022
    risk 0.67cvss 9.8epss 0.41

    Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that leads to command execution.

  • CVE-2020-23583CriNov 23, 2022
    risk 0.64cvss 9.8epss 0.02

    OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise…

  • CVE-2022-4116CriNov 22, 2022
    risk 0.66cvss 9.8epss 0.33

    A vulnerability was found in quarkus. This security flaw happens in Dev UI Config Editor which is vulnerable to drive-by localhost attacks leading to remote code execution.

  • CVE-2022-41943CriNov 22, 2022
    risk 0.59cvss 9.0epss 0.01

    sourcegraph is a code intelligence platform. As a site admin it was possible to execute arbitrary commands on Gitserver when the experimental `customGitFetch` feature was enabled. This experimental feature has now been disabled by default. This issue has been patched in version…

  • CVE-2022-43212CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php.

  • CVE-2022-39070CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    There is an access control vulnerability in some ZTE PON OLT products. Due to improper access control settings, remote attackers could use the vulnerability to log in to the device and execute any operation.

  • CVE-2022-44808CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.04

    A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the…

  • CVE-2022-44807CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString.

  • CVE-2022-44806CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow.

  • CVE-2022-44804CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function.

  • CVE-2022-44801CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.

  • CVE-2022-44202CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.

  • CVE-2022-44201CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.

  • CVE-2022-44184CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_sec.

  • CVE-2022-44200CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.0.8, V1.3.1.64 is vulnerable to Buffer Overflow via parameters: stamode_dns1_pri and stamode_dns1_sec.

  • CVE-2022-44199CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.