VYPR

CVEs

31,787 total · page 298 of 636

  • CVE-2022-38165CriNov 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbitrary locations on the F-Secure Policy Manager Server.

  • CVE-2022-36787CriNov 17, 2022
    risk 0.64cvss 9.8epss 0.01

    webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/showfiles.aspx?jobnumber=nullDoc Number=HERE.

  • CVE-2022-36786CriNov 17, 2022
    risk 0.64cvss 9.9epss 0.01

    DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.

  • CVE-2022-36784CriNov 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Elsight – Elsight Halo  Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. through the POST request : /api/v1/nics/wifi/wlan0/ping we can abuse DESTINATION parameter and leverage it to remote code execution.

  • CVE-2022-44001CriNov 17, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services can be bypassed.

  • CVE-2022-43138CriNov 17, 2022
    risk 0.57cvss 9.8epss 0.01

    Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.

  • CVE-2022-42245CriNov 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Dreamer CMS 4.0.01 is vulnerable to SQL Injection.

  • CVE-2022-40881CriNov 17, 2022
    risk 0.66cvss 9.8epss 0.29

    SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php

  • CVE-2022-43782CriNov 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Affected versions of Atlassian Crowd allow an attacker to authenticate as the crowd application via security misconfiguration and subsequent ability to call privileged endpoints in Crowd's REST API under the {{usermanagement}} path. This vulnerability can only be exploited by…

  • CVE-2022-43781CriNov 17, 2022
    risk 0.75cvss 9.8epss 0.98

    There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the…

  • CVE-2022-44006CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is…

  • CVE-2022-44004CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password.

  • CVE-2022-44003CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.

  • CVE-2022-44000CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbitrary system commands on the server.

  • CVE-2022-40752CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.02

    IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID:  236687.

  • CVE-2022-43999CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executed on the server.

  • CVE-2022-43135CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php.

  • CVE-2022-43262CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /hrm/controller/login.php.

  • CVE-2022-43256CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    SeaCms before v12.6 was discovered to contain a SQL injection vulnerability via the component /js/player/dmplayer/dmku/index.php.

  • CVE-2022-43234CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the /attachments component of Hoosk v1.8 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-3980CriNov 16, 2022
    risk 0.64cvss 9.8epss 0.08

    An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.

  • CVE-2022-45047CriNov 16, 2022
    risk 0.57cvss 9.8epss 0.04

    Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for…

  • CVE-2022-2166CriNov 16, 2022
    risk 0.00cvss 9.8epss 0.01

    Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0.

  • CVE-2022-43265CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-42785CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple W&T products of the ComServer Series are prone to an authentication bypass. An unathenticated remote attacker, can log in without knowledge of the password by crafting a modified HTTP GET Request.

  • CVE-2022-24942CriNov 15, 2022
    risk 0.59cvss 9.1epss 0.02

    Heap based buffer overflow in HTTP Server functionality in Micrium uC-HTTP 3.01.01 allows remote code execution via HTTP request.

  • CVE-2022-45400CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-45397CriNov 15, 2022
    risk 0.57cvss 9.8epss 0.01

    Jenkins OSF Builder Suite : : XML Linter Plugin 1.0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-45396CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Jenkins SourceMonitor Plugin 0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-45395CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-41558CriNov 15, 2022
    risk 0.59cvss 9.0epss 0.01

    The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, TIBCO Spotfire Desktop, TIBCO Spotfire Desktop, TIBCO Spotfire Server,…

  • CVE-2022-25727CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.00

    Memory Corruption in modem due to improper length check while copying into memory in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

  • CVE-2022-42058CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

  • CVE-2022-42122CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in the Friendly Url module in Liferay Portal 7.3.7, and Liferay DXP 7.3 fix pack 2 through update 4 allows attackers to execute arbitrary SQL commands via a crafted payload injected into the `title` field of a friendly URL.

  • CVE-2022-42120CriNov 15, 2022
    risk 0.57cvss 9.8epss 0.01

    A SQL injection vulnerability in the Fragment module in Liferay Portal 7.3.3 through 7.4.3.16, and Liferay DXP 7.3 before update 4, and 7.4 before update 17 allows attackers to execute arbitrary SQL commands via a PortletPreferences' `namespace` attribute.

  • CVE-2022-42984CriNov 15, 2022
    risk 0.64cvss 9.8epss 0.01

    WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=search&s=recipients.

  • CVE-2022-43294CriNov 14, 2022
    risk 0.00cvss 9.8epss 0.01

    Tasmota before commit 066878da4d4762a9b6cb169fdf353e804d735cfd was discovered to contain a stack overflow via the ClientPortPtr parameter at lib/libesp32/rtsp/CRtspSession.cpp.

  • CVE-2022-3362CriNov 14, 2022
    risk 0.57cvss 9.8epss 0.01

    Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.

  • CVE-2022-37109CriNov 14, 2022
    risk 0.64cvss 9.8epss 0.49

    patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access Control. Access to the password.txt file is not properly restricted as it is in the root directory served by StaticFileHandler and the Tornado rule to throw a…

  • CVE-2022-3993CriNov 14, 2022
    risk 0.00cvss 9.4epss 0.01

    Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.

  • CVE-2022-45136CriNov 14, 2022
    risk 0.64cvss 9.8epss 0.02

    Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the underlying database server to return malicious data. The mySQL JDBC driver in particular is known to be vulnerable to this class of…

  • CVE-2022-3574CriNov 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.

  • CVE-2022-3477CriNov 14, 2022
    risk 0.64cvss 9.8epss 0.04

    The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their…

  • CVE-2022-45378CriNov 14, 2022
    risk 0.64cvss 9.8epss 0.02

    In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even…

  • CVE-2022-38652CriNov 12, 2022
    risk 0.64cvss 9.9epss 0.01

    A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host operating system with the privileges of…

  • CVE-2022-38651CriNov 12, 2022
    risk 0.64cvss 9.8epss 0.01

    A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects products that are no…

  • CVE-2022-38650CriNov 12, 2022
    risk 0.65cvss 10.0epss 0.01

    A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to run arbitrary code or malware within Hyperic Server and the host operating system with the privileges of the…

  • CVE-2022-43672CriNov 12, 2022
    risk 0.69cvss 9.8epss 0.67

    Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.

  • CVE-2022-43671CriNov 12, 2022
    risk 0.70cvss 9.8epss 0.75

    Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.

  • CVE-2022-45182CriNov 11, 2022
    risk 0.00cvss 9.8epss 0.01

    Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.