VYPR

CVEs

31,787 total · page 304 of 636

  • CVE-2020-8974CriOct 17, 2022
    risk 0.65cvss 10.0epss 0.01

    In ZGR TPS200 NG 2.00 firmware version and 1.01 hardware version, the firmware upload process does not perform any type of restriction. This allows an attacker to modify it and re-upload it via web with malicious modifications, rendering the device unusable.

  • CVE-2020-8973CriOct 17, 2022
    risk 0.60cvss 9.3epss 0.00

    ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, does not properly accept specially constructed requests. This allows an attacker with access to the network where the affected asset is located, to operate and change several parameters without having to be…

  • CVE-2022-42149CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.02

    kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.

  • CVE-2022-32176CriOct 17, 2022
    risk 0.59cvss 9.0epss 0.01

    In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will…

  • CVE-2022-40055CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.

  • CVE-2022-2992CriOct 17, 2022
    risk 0.74cvss 9.9epss 0.86

    A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

  • CVE-2022-2884CriOct 17, 2022
    risk 0.73cvss 9.9epss 0.76

    A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

  • CVE-2022-22128CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only supports product versions for 24 months after release. Older versions have reached their End of…

  • CVE-2022-0699CriOct 17, 2022
    risk 0.00cvss 9.8epss 0.01

    A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified impact via control over malloc.

  • CVE-2022-42237CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account.

  • CVE-2022-42171CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/saveParentControlInfo.

  • CVE-2022-42170CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formWifiWpsStart.

  • CVE-2022-42169CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/addWifiMacFilter.

  • CVE-2022-42168CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromSetIpMacBind.

  • CVE-2022-42167CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetFirewallCfg.

  • CVE-2022-42166CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetSpeedWan.

  • CVE-2022-42154CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-42165CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetDeviceName.

  • CVE-2022-42164CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetClientState.

  • CVE-2022-42163CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromNatStaticSetting.

  • CVE-2022-2052CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system.

  • CVE-2022-42980CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    go-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key.

  • CVE-2022-42968CriOct 16, 2022
    risk 0.57cvss 9.8epss 0.01

    Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.

  • CVE-2017-20149CriOct 15, 2022
    risk 0.64cvss 9.8epss 0.03

    The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute…

  • CVE-2022-41436CriOct 14, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue in OXHOO TP50 OXH1.50 allows unauthenticated attackers to access the administrative panel via browsing to the URL http://device_ip/index1.html.

  • CVE-2022-39311CriOct 14, 2022
    risk 0.00cvss 9.1epss 0.02

    GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 are vulnerable to remote code execution on the server from a malicious or compromised agent. The…

  • CVE-2022-38418CriOct 14, 2022
    risk 0.70cvss 9.8epss 0.80

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user.…

  • CVE-2022-35712CriOct 14, 2022
    risk 0.67cvss 9.8epss 0.37

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction,…

  • CVE-2022-35711CriOct 14, 2022
    risk 0.70cvss 9.8epss 0.73

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction,…

  • CVE-2022-35710CriOct 14, 2022
    risk 0.67cvss 9.8epss 0.43

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user…

  • CVE-2022-35698CriOct 14, 2022
    risk 0.66cvss 10.0epss 0.10

    Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.

  • CVE-2022-35690CriOct 14, 2022
    risk 0.69cvss 9.8epss 0.72

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user…

  • CVE-2022-41477CriOct 14, 2022
    risk 0.59cvss 9.1epss 0.01

    A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inject payloads via theme parameters to read files across directories.

  • CVE-2022-41581CriOct 14, 2022
    risk 0.59cvss 9.1epss 0.00

    The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.

  • CVE-2022-41580CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.

  • CVE-2022-41578CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root privilege escalation attacks implemented by modifying program information.

  • CVE-2022-38986CriOct 14, 2022
    risk 0.59cvss 9.1epss 0.01

    The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause out-of-bounds access to the HIPP module and page table tampering, affecting device confidentiality and availability.

  • CVE-2022-38983CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The BT Hfp Client module has a Use-After-Free (UAF) vulnerability.Successful exploitation of this vulnerability may result in arbitrary code execution.

  • CVE-2022-38982CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.

  • CVE-2022-38980CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions.

  • CVE-2021-46840CriOct 14, 2022
    risk 0.59cvss 9.1epss 0.00

    The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.

  • CVE-2021-46839CriOct 14, 2022
    risk 0.59cvss 9.1epss 0.00

    The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.

  • CVE-2022-42064CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.

  • CVE-2022-3439CriOct 14, 2022
    risk 0.57cvss 9.8epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.

  • CVE-2022-37602CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.02

    Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.

  • CVE-2022-32177CriOct 14, 2022
    risk 0.59cvss 9.0epss 0.01

    In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3beta are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the 'Normal Upload' functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will…

  • CVE-2022-41391CriOct 13, 2022
    risk 0.64cvss 9.8epss 0.01

    OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at showImg.php.

  • CVE-2022-41390CriOct 13, 2022
    risk 0.64cvss 9.8epss 0.01

    OcoMon v4.0 was discovered to contain a SQL injection vulnerability via the cod parameter at download.php.

  • CVE-2022-41497CriOct 13, 2022
    risk 0.64cvss 9.8epss 0.01

    ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/index.php.

  • CVE-2022-41496CriOct 13, 2022
    risk 0.64cvss 9.8epss 0.01

    iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.