VYPR

CVEs

31,787 total · page 307 of 636

  • CVE-2021-45790CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.

  • CVE-2020-35674CriSep 29, 2022
    risk 0.57cvss 9.8epss 0.01

    BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoint that is responsible for issuing self-service password resets). An unauthenticated attacker is able to send a request containing a crafted…

  • CVE-2020-27602CriSep 29, 2022
    risk 0.00cvss 9.8epss 0.01

    BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.

  • CVE-2020-15347CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.

  • CVE-2020-15332CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.

  • CVE-2020-15331CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.

  • CVE-2016-2338CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.05

    An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Specially constructed object passed as element of tags array can…

  • CVE-2022-40929CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).

  • CVE-2022-40942CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.08

    Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time.

  • CVE-2022-40083CriSep 28, 2022
    risk 0.56cvss 9.6epss 0.02

    Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged by attackers to cause a Server-Side Request Forgery (SSRF).

  • CVE-2022-28814CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arbitrary files and gain full control of the device.

  • CVE-2022-28812CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device.

  • CVE-2022-28811CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands.

  • CVE-2022-22526CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows for full access via API.

  • CVE-2022-22524CriSep 28, 2022
    risk 0.61cvss 9.4epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker could utilize a SQL-Injection vulnerability to gain full database access, modify users and stop services .

  • CVE-2022-22522CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device.

  • CVE-2022-30935CriSep 28, 2022
    risk 0.59cvss 9.1epss 0.01

    An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users, and optionally reset their password.…

  • CVE-2022-39033CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.02

    Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication, access restricted paths to…

  • CVE-2022-41571CriSep 27, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur.

  • CVE-2022-41570CriSep 27, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur.

  • CVE-2022-40877CriSep 27, 2022
    risk 0.64cvss 9.8epss 0.01

    Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.

  • CVE-2022-37346CriSep 27, 2022
    risk 0.64cvss 9.8epss 0.01

    EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an…

  • CVE-2021-41433CriSep 27, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability exists in version 1.0 of the Resumes Management and Job Application Website application login form by EGavilan Media that allows authentication bypass through login.php.

  • CVE-2022-39256CriSep 27, 2022
    risk 0.52cvss 9.0epss 0.01

    Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated…

  • CVE-2022-40050CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.01

    ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.

  • CVE-2022-30004CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..

  • CVE-2022-3075CriKEVSep 26, 2022
    risk 0.75cvss 9.6epss 0.06

    Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2022-28722CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Certain HP Print Products are potentially vulnerable to Buffer Overflow.

  • CVE-2022-28721CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.02

    Certain HP Print Products are potentially vulnerable to Remote Code Execution.

  • CVE-2022-40485CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php.

  • CVE-2022-40484CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_edit.php.

  • CVE-2022-40483CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /wedding_details.php.

  • CVE-2022-41352CriKEVSep 26, 2022
    risk 0.86cvss 9.8epss 0.95

    An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends…

  • CVE-2022-23463CriSep 24, 2022
    risk 0.61cvss 9.4epss 0.02

    Nepxion Discovery is a solution for Spring Cloud. Discover is vulnerable to SpEL Injection in discovery-commons. DiscoveryExpressionResolver’s eval method is evaluating expression with a StandardEvaluationContext, allowing the expression to reach and interact with Java classes…

  • CVE-2022-36025CriSep 24, 2022
    risk 0.59cvss 9.1epss 0.01

    Besu is a Java-based Ethereum client. In versions newer than 22.1.3 and prior to 22.7.1, Besu is subject to an Incorrect Conversion between Numeric Types. An error in 32 bit signed and unsigned types in the calculation of available gas in the CALL operations (including…

  • CVE-2022-40122CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer_action.php.

  • CVE-2022-40121CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/manage_customers.php.

  • CVE-2022-40120CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/customer_transactions.php.

  • CVE-2022-40119CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/transactions.php.

  • CVE-2022-40118CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds_action.php.

  • CVE-2022-40117CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_customer.php.

  • CVE-2022-40116CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/beneficiary.php.

  • CVE-2022-40115CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_beneficiary.php.

  • CVE-2022-40114CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer.php.

  • CVE-2022-40113CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds.php.

  • CVE-2022-40100CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda i9 v1.0.0.8(3828) was discovered to contain a command injection vulnerability via the FormexeCommand function.

  • CVE-2022-32847CriSep 23, 2022
    risk 0.59cvss 9.1epss 0.03

    This issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Big Sur 11.6.8, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Security Update 2022-005 Catalina. A remote user may be able to cause unexpected system termination or corrupt…

  • CVE-2022-32845CriSep 23, 2022
    risk 0.65cvss 10.0epss 0.04

    This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to break out of its sandbox.

  • CVE-2022-36944CriSep 23, 2022
    risk 0.57cvss 9.8epss 0.08

    Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary…

  • CVE-2022-40628CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.02

    This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper control of code generation in the Tacitine Firewall web-based management interface. An unauthenticated remote…