VYPR

CVEs

31,787 total · page 297 of 636

  • CVE-2022-44198CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1.

  • CVE-2022-44197CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.

  • CVE-2022-44196CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1.

  • CVE-2022-44194CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec.

  • CVE-2022-44193CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameters: starthour, startminute , endhour, and endminute.

  • CVE-2022-44191CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2.

  • CVE-2022-44190CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering.

  • CVE-2022-44188CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter enable_band_steering.

  • CVE-2022-44187CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri.

  • CVE-2022-44186CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_pri.

  • CVE-2022-42989CriNov 22, 2022
    risk 0.59cvss 9.0epss 0.01

    ERP Sankhya before v4.11b81 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Caixa de Entrada.

  • CVE-2022-40189CriNov 22, 2022
    risk 0.57cvss 9.8epss 0.04

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG files. This issue…

  • CVE-2022-38649CriNov 22, 2022
    risk 0.57cvss 9.8epss 0.03

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG files. This issue…

  • CVE-2022-40602CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    A flaw in the Zyxel LTE3301-M209 firmware verisons prior to V1.00(ABLG.6)C0 could allow a remote attacker to access the device using an improper pre-configured password if the remote administration feature has been enabled by an authenticated administrator.

  • CVE-2022-36227CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.02

    In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties…

  • CVE-2022-43215CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.

  • CVE-2022-43214CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php.

  • CVE-2022-41937CriNov 22, 2022
    risk 0.55cvss 9.6epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view access to modify any page of the wiki by importing a crafted XAR package. The problem has been patched in XWiki 14.6RC1, 14.6 and…

  • CVE-2022-41326CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated attacker to upload arbitrary scripts due to improper authorization controls. A successful exploit could allow remote code execution within the context of the application.

  • CVE-2022-40842CriNov 22, 2022
    risk 0.59cvss 9.1epss 0.01

    ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.

  • CVE-2022-36180CriNov 22, 2022
    risk 0.62cvss 9.6epss 0.01

    Fusiondirectory 1.3 is vulnerable to Cross Site Scripting (XSS) via /fusiondirectory/index.php?message=[injection], /fusiondirectory/index.php?message=invalidparameter&plug={Injection], /fusiondirectory/index.php?signout=1&message=[injection]&plug=106.

  • CVE-2022-36179CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Fusiondirectory 1.3 suffers from Improper Session Handling.

  • CVE-2022-44785CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Appalti & Contratti 9.12.2. The target web applications are subject to multiple SQL Injection vulnerabilities, some of which executable even by unauthenticated users, as demonstrated by the GetListaEnti.do cfamm parameter.

  • CVE-2022-30258CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would…

  • CVE-2022-30257CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would…

  • CVE-2022-43143CriNov 21, 2022
    risk 0.62cvss 9.6epss 0.01

    A cross-site scripting (XSS) vulnerability in Beekeeper Studio v3.6.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error modal container.

  • CVE-2022-44183CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.

  • CVE-2022-44180CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function addWifiMacFilter.

  • CVE-2022-44178CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow. via function formWifiWpsOOB.

  • CVE-2022-44177CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formWifiWpsStart.

  • CVE-2022-44176CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function fromSetRouteStatic.

  • CVE-2022-44175CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetMacFilterCfg.

  • CVE-2022-44174CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.05 is vulnerable to Buffer Overflow via function formSetDeviceName.

  • CVE-2022-44172CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function R7WebsSecurityHandler.

  • CVE-2022-44171CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function form_fast_setting_wifi_set.

  • CVE-2022-3634CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.04

    The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection

  • CVE-2022-3600CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.

  • CVE-2021-24649CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and…

  • CVE-2022-4093CriNov 21, 2022
    risk 0.57cvss 9.8epss 0.04

    SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and…

  • CVE-2022-4070CriNov 20, 2022
    risk 0.57cvss 9.8epss 0.01

    Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.

  • CVE-2022-41938CriNov 19, 2022
    risk 0.52cvss 9.0epss 0.01

    Flarum is an open source discussion platform. Flarum's page title system allowed for page titles to be converted into HTML DOM nodes when pages were rendered. The change was made after `v1.5` and was not noticed. This allowed an attacker to inject malicious HTML markup using a…

  • CVE-2022-45132CriNov 18, 2022
    risk 0.64cvss 9.8epss 0.02

    In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be…

  • CVE-2022-44584CriNov 18, 2022
    risk 0.59cvss 9.1epss 0.01

    Unauth. Arbitrary File Deletion vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.

  • CVE-2022-42698CriNov 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Unauth. Arbitrary File Upload vulnerability in WordPress Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.

  • CVE-2022-42497CriNov 18, 2022
    risk 0.65cvss 10.0epss 0.01

    Arbitrary Code Execution vulnerability in Api2Cart Bridge Connector plugin <= 1.1.0 on WordPress.

  • CVE-2022-34827CriNov 18, 2022
    risk 0.64cvss 9.9epss 0.01

    Carel Boss Mini 1.5.0 has Improper Access Control.

  • CVE-2022-45474CriNov 18, 2022
    risk 0.00cvss 9.8epss 0.01

    drachtio-server 0.8.18 has a request-handler.cpp event_cb use-after-free for any request.

  • CVE-2022-44204CriNov 18, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR3060 DIR3060A1_FW111B04.bin is vulnerable to Buffer Overflow.

  • CVE-2022-40200CriNov 17, 2022
    risk 0.64cvss 9.9epss 0.01

    Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.

  • CVE-2022-39180CriNov 17, 2022
    risk 0.64cvss 9.8epss 0.01

    College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in the login.php page