VYPR

CVEs

31,787 total · page 305 of 636

  • CVE-2022-41495CriOct 13, 2022
    risk 0.64cvss 9.8epss 0.01

    ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manager/index.php.

  • CVE-2022-3457CriOct 13, 2022
    risk 0.57cvss 9.8epss 0.00

    Origin Validation Error in GitHub repository ikus060/rdiffweb prior to 2.5.0a5.

  • CVE-2022-3456CriOct 13, 2022
    risk 0.57cvss 9.8epss 0.00

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0.

  • CVE-2022-42889CriOct 13, 2022
    risk 0.68cvss 9.8epss 1.00

    Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs…

  • CVE-2022-24697CriOct 13, 2022
    risk 0.07cvss 9.8epss 0.85

    Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any operating system…

  • CVE-2022-42897CriOct 13, 2022
    risk 0.64cvss 9.8epss 0.02

    Array Networks AG/vxAG with ArrayOS AG before 9.4.0.469 allows unauthenticated command injection that leads to privilege escalation and control of the system. NOTE: ArrayOS AG 10.x is unaffected.

  • CVE-2018-18447CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.01

    dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 2 of 2).

  • CVE-2018-18446CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.01

    dotPDN Paint.NET before 4.1.2 allows Deserialization of Untrusted Data (issue 1 of 2).

  • CVE-2022-37601CriOct 12, 2022
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.

  • CVE-2022-41403CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.01

    OpenCart 3.x Newsletter Custom Popup was discovered to contain a SQL injection vulnerability via the email parameter at index.php?route=extension/module/so_newletter_custom_popup/newsletter.

  • CVE-2022-33106CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.01

    WiJungle NGFW Version U250 was discovered to be vulnerable to No Rate Limit attack, allowing the attacker to brute force the admin password leading to Account Take Over.

  • CVE-2022-40871CriOct 12, 2022
    risk 0.66cvss 9.8epss 0.33

    Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.

  • CVE-2022-37614CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in function enable in mockery.js in mfncooper mockery commit 822f0566fd6d72af8c943ae5ca2aa92e516aa2cf via the key variable in mockery.js.

  • CVE-2022-40664CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.02

    Apache Shiro before 1.10.0, Authentication Bypass Vulnerability in Shiro when forwarding or including via RequestDispatcher.

  • CVE-2022-42711CriOct 12, 2022
    risk 0.62cvss 9.6epss 0.01

    In Progress WhatsUp Gold before 22.1.0, an SNMP MIB Walker application endpoint failed to adequately sanitize malicious input. This could allow an unauthenticated attacker to execute arbitrary code in a victim's browser.

  • CVE-2022-37611CriOct 12, 2022
    risk 0.57cvss 9.8epss 0.01

    Prototype pollution vulnerability in tschaub gh-pages 3.1.0 via the partial variable in util.js.

  • CVE-2022-41408CriOct 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Pet Shop We App v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=orders/view_order.

  • CVE-2022-37617CriOct 11, 2022
    risk 0.57cvss 9.8epss 0.01

    Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js.

  • CVE-2022-42044CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-html package. The affected version is 0.1.0.

  • CVE-2022-42043CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-xml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-html package. The affected version is 0.1.0.

  • CVE-2022-42042CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-networking package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hashes package. The affected version is 0.1.0.

  • CVE-2022-42041CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-file-system package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hashes package. The affected version is 0.1.0.

  • CVE-2022-42040CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.05

    The d8s-algorithms package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-dicts package. The affected version is 0.1.0.

  • CVE-2022-42039CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-lists package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-dicts package. The affected version is 0.1.0.

  • CVE-2022-42038CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-ip-addresses package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.

  • CVE-2022-42037CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.

  • CVE-2022-42036CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-urls package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-csv package. The affected version is 0.1.0.

  • CVE-2022-41387CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-pdfs package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.

  • CVE-2022-41386CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.

  • CVE-2022-41385CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-html package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.

  • CVE-2022-41384CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-domains package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.

  • CVE-2022-41383CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

  • CVE-2022-41382CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

  • CVE-2022-41381CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

  • CVE-2022-41380CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-yaml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

  • CVE-2022-35299CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    SAP SQL Anywhere - version 17.0, and SAP IQ - version 16.1, allows an attacker to leverage logical errors in memory management to cause a memory corruption, such as Stack-based buffer overflow.

  • CVE-2020-14131CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The Xiaomi Security Center expresses heartfelt thanks to ADLab of VenusTech ! At the same time, we also welcome more outstanding and professional security experts and security teams to join the Mi Security Center (MiSRC) to jointly ensure the safe access of millions of Xiaomi…

  • CVE-2020-14129CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    A logic vulnerability exists in a Xiaomi product. The vulnerability is caused by an identity verification failure, which can be exploited by an attacker who can obtain a brief elevation of privilege.

  • CVE-2022-37968CriOct 11, 2022
    risk 0.65cvss 10.0epss 0.03

    Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kubernetes cluster.…

  • CVE-2022-37609CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in beautify-web js-beautify 1.13.7 via the name variable in options.js.

  • CVE-2022-32174CriOct 11, 2022
    risk 0.63cvss 9.0epss 0.58

    In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.

  • CVE-2022-41665CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA00-2AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA10-0AA0) (All versions < V3.10), SICAM P850 (7KG8500-0AA10-2AA0) (All versions < V3.10), SICAM P850…

  • CVE-2022-38465CriOct 11, 2022
    risk 0.60cvss 9.3epss 0.00

    A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9),…

  • CVE-2022-36361CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA1) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA1) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA1)…

  • CVE-2022-37616CriOct 11, 2022
    risk 0.57cvss 9.8epss 0.02

    A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package before 0.8.3 for Node.js via the p variable. NOTE: the vendor states "we are in the process of marking this report as invalid"; however, some third…

  • CVE-2022-40138CriOct 11, 2022
    risk 0.00cvss 9.8epss 0.01

    An integer conversion error in Hermes bytecode generation, prior to commit 6aa825e480d48127b480b08d13adf70033237097, could have been used to perform Out-Of-Bounds operations and subsequently execute arbitrary code. Note that this is only exploitable in cases where Hermes is used…

  • CVE-2022-35289CriOct 11, 2022
    risk 0.00cvss 9.8epss 0.01

    A write-what-where condition in hermes caused by an integer overflow, prior to commit 5b6255ae049fa4641791e47fad994e8e8c4da374 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes…

  • CVE-2022-32234CriOct 11, 2022
    risk 0.00cvss 9.8epss 0.01

    An out of bounds write in hermes, while handling large arrays, prior to commit 06eaec767e376bfdb883d912cb15e987ddf2bda1 allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits…

  • CVE-2022-41746CriOct 10, 2022
    risk 0.59cvss 9.1epss 0.01

    A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on affected installations to escalate privileges and modify certain agent groupings. Please note: an attacker must first obtain the ability to log onto the Apex…

  • CVE-2021-44171CriOct 10, 2022
    risk 0.59cvss 9.0epss 0.02

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7.0.3 allows attacker to…