VYPR

CVEs

31,787 total · page 306 of 636

  • CVE-2022-39289CriOct 7, 2022
    risk 0.00cvss 9.1epss 0.01

    ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, modification, deletion of logs without System Privileges. Users are advised yo…

  • CVE-2022-31680CriOct 7, 2022
    risk 0.62cvss 9.1epss 0.33

    The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.

  • CVE-2022-42075CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Wedding Planner v1.0 is vulnerable to arbitrary code execution.

  • CVE-2022-37891CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web management interface. Successful exploitation results in the execution of arbitrary commands on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and…

  • CVE-2022-37890CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web management interface. Successful exploitation results in the execution of arbitrary commands on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and…

  • CVE-2022-37889CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2022-37887CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2022-37886CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2022-37885CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2022-40872CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    An SQL injection vulnerability issue was discovered in Sourcecodester Simple E-Learning System 1.0., in /vcs/classRoom.php?classCode=, classCode.

  • CVE-2022-40835CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php. Note: Multiple third parties have disputed this as not a valid vulnerability

  • CVE-2022-40834CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_not_like() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40833CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40832CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php having() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40831CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php like() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40830CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40829CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_like() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40828CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where_not_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40827CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40826CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_having() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40825CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php where_in() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40824CriOct 7, 2022
    risk 0.64cvss 9.8epss 0.01

    B.C. Institute of Technology CodeIgniter <=3.1.13 is vulnerable to SQL Injection via system\database\DB_query_builder.php or_where() function. Note: Multiple third parties have disputed this as not a valid vulnerability.

  • CVE-2022-40494CriOct 6, 2022
    risk 0.64cvss 9.8epss 0.02

    NPS before v0.26.10 was discovered to contain an authentication bypass vulnerability via constantly generating and sending the Auth key and Timestamp parameters.

  • CVE-2022-41525CriOct 6, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the OpModeCfg function at /cgi-bin/cstecgi.cgi.

  • CVE-2022-41522CriOct 6, 2022
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain an unauthenticated stack overflow via the "main" function.

  • CVE-2022-42457CriOct 6, 2022
    risk 0.59cvss 9.1epss 0.02

    Generex CS141 through 2.10 allows remote command execution by administrators via a web interface that reaches run_update in /usr/bin/gxserve-update.sh (e.g., command execution can occur via a reverse shell installed by install.sh).

  • CVE-2022-41518CriOct 6, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a command injection vulnerability via the UploadFirmwareFile function at /cgi-bin/cstecgi.cgi.

  • CVE-2022-40895CriOct 6, 2022
    risk 0.59cvss 9.1epss 0.02

    In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to affect the integrity of a device via a User Enumeration vulnerability. The vulnerability is due to insecure design, where a difference in…

  • CVE-2022-3273CriOct 6, 2022
    risk 0.57cvss 9.8epss 0.00

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a4.

  • CVE-2022-39269CriOct 6, 2022
    risk 0.59cvss 9.1epss 0.01

    PJSIP is a free and open source multimedia communication library written in C. When processing certain packets, PJSIP may incorrectly switch from using SRTP media transport to using basic RTP upon SRTP restart, causing the media to be sent insecurely. The vulnerability impacts…

  • CVE-2022-39222CriOct 6, 2022
    risk 0.54cvss 9.3epss 0.01

    Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex instances with public clients (and by extension, clients accepting tokens issued by those Dex instances) are affected by this vulnerability if they are running a version prior to…

  • CVE-2022-37888CriOct 6, 2022
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2022-41443CriOct 3, 2022
    risk 0.64cvss 9.8epss 0.01

    phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.

  • CVE-2022-33882CriOct 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Under certain conditions, an attacker could create an unintended sphere of control through a vulnerability present in file delete operation in Autodesk desktop app (ADA). An attacker could leverage this vulnerability to escalate privileges and execute arbitrary code.

  • CVE-2022-42308CriOct 3, 2022
    risk 0.59cvss 9.0epss 0.00

    An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can delete arbitrary files by leveraging a path traversal in the pbx_exchange registration code.

  • CVE-2022-42302CriOct 3, 2022
    risk 0.59cvss 9.0epss 0.01

    An issue was discovered in Veritas NetBackup through 10.0 and related Veritas products. The NetBackup Primary server is vulnerable to a SQL Injection attack affecting the NBFSMCLIENT service.

  • CVE-2022-40721CriOct 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Arbitrary file upload vulnerability in php uploader

  • CVE-2022-42002CriOct 1, 2022
    risk 0.59cvss 9.1epss 0.01

    SonicJS through 0.6.0 allows file overwrite. It has the following mutations that are used for updating files: fileCreate and fileUpdate. Both of these mutations can be called without any authentication to overwrite any files on a SonicJS application, leading to Arbitrary File…

  • CVE-2022-40943CriSep 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.

  • CVE-2022-35156CriSep 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..

  • CVE-2022-40944CriSep 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file.

  • CVE-2022-40315CriSep 30, 2022
    risk 0.64cvss 9.8epss 0.01

    A limited SQL injection risk was identified in the "browse list of users" site administration page.

  • CVE-2022-40314CriSep 30, 2022
    risk 0.00cvss 9.8epss 0.02

    A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.

  • CVE-2022-2778CriSep 30, 2022
    risk 0.64cvss 9.8epss 0.01

    In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.

  • CVE-2022-36066CriSep 29, 2022
    risk 0.00cvss 9.1epss 0.02

    Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, admins can upload a maliciously crafted Zip or Gzip Tar archive to write files at arbitrary locations and…

  • CVE-2022-33880CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.01

    hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the type parameter.

  • CVE-2022-39266CriSep 29, 2022
    risk 0.55cvss 9.6epss 0.01

    isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, if the untrusted v8 cached data is passed to the API through CachedDataOptions, attackers can bypass the sandbox and run arbitrary code in the nodejs process.…

  • CVE-2022-40887CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.01

    SourceCodester Best Student Result Management System 1.0 is vulnerable to SQL Injection.

  • CVE-2022-29503CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.01

    A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability.

  • CVE-2022-40475CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi.