VYPR

CVEs

31,787 total · page 308 of 636

  • CVE-2022-2972CriSep 23, 2022
    risk 0.65cvss 10.0epss 0.01

    MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) is vulnerable to a stack-based buffer overflow, which could allow an attacker to crash the device or remotely execute arbitrary code.

  • CVE-2022-2970CriSep 23, 2022
    risk 0.65cvss 10.0epss 0.01

    MZ Automation's libIEC61850 (versions 1.4 and prior; version 1.5 prior to commit a3b04b7bc4872a5a39e5de3fdc5fbde52c09e10e) does not sanitize input before memcpy is used, which could allow an attacker to crash the device or remotely execute arbitrary code.

  • CVE-2022-2070CriSep 23, 2022
    risk 0.67cvss 9.8epss 0.04

    In Grandstream GSD3710 in its 1.0.11.13 version, it's possible to overflow the stack since it doesn't check the param length before using the sscanf instruction. Because of that, an attacker could create a socket and connect with a remote IP:port by opening a shell and getting…

  • CVE-2022-2025CriSep 23, 2022
    risk 0.67cvss 9.8epss 0.04

    an attacker with knowledge of user/pass of Grandstream GSD3710 in its 1.0.11.13 version, could overflow the stack since it doesn't check the param length before use the strcopy instruction. The explotation of this vulnerability may lead an attacker to execute a shell with full…

  • CVE-2022-40868CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formDelDhcpRule with the request /goform/delDhcpRules/

  • CVE-2022-40867CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formIPMacBindDel with the request /goform/delIpMacBind/

  • CVE-2022-40866CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda W20E router V15.11.0.6 (US_W20EV4.0br_V15.11.0.6(1068_1546_841)_CN_TDC) contains a stack overflow vulnerability in the function formSetDebugCfg with request /goform/setDebugCfg/

  • CVE-2022-40855CriSep 23, 2022
    risk 0.65cvss 9.8epss 0.14

    Tenda W20E router V15.11.0.6 contains a stack overflow in the function formSetPortMapping with post request 'goform/setPortMapping/'. This vulnerability allows attackers to cause a Denial of Service (DoS) or Remote Code Execution (RCE) via the portMappingServer,…

  • CVE-2022-40854CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router contained a stack overflow vulnerability in /goform/fast_setting_wifi_set

  • CVE-2022-40851CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.09

    Tenda AC15 V15.03.05.19 contained a stack overflow via the function fromAddressNat.

  • CVE-2022-23144CriSep 23, 2022
    risk 0.59cvss 9.1epss 0.01

    There is a broken access control vulnerability in ZTE ZXvSTB product. Due to improper permission control, attackers could use this vulnerability to delete the default application type, which affects normal use of system.

  • CVE-2022-40869CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function fromDhcpListClient with a combined parameter "list*" ("%s%d","list").

  • CVE-2022-40865CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 and AC18 routers V15.03.05.19 contain heap overflow vulnerabilities in the function setSchedWifi with the request /goform/openSchedWifi/

  • CVE-2022-40864CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 and AC18 routers V15.03.05.19 contain stack overflow vulnerabilities in the function setSmartPowerManagement with the request /goform/PowerSaveSet

  • CVE-2022-40862CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 and AC18 router V15.03.05.19 contains stack overflow vulnerability in the function fromNatStaticSetting with the request /goform/NatStaticSetting

  • CVE-2022-40860CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 router V15.03.05.19 contains a stack overflow vulnerability in the function formSetQosBand->FUN_0007dd20 with request /goform/SetNetControlList

  • CVE-2022-40853CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 router V15.03.05.19 contains a stack overflow via the list parameter at /goform/fast_setting_wifi_set

  • CVE-2022-3236CriKEVSep 23, 2022
    risk 0.84cvss 9.8epss 0.99

    A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

  • CVE-2022-2566CriSep 23, 2022
    risk 0.00cvss 9.0epss 0.01

    A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc->ctts_data[i].count` to `sc->sample_offsets_count`. This can lead to an integer overflow resulting in a…

  • CVE-2022-3269CriSep 23, 2022
    risk 0.57cvss 9.8epss 0.01

    Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.

  • CVE-2022-26112CriSep 23, 2022
    risk 0.57cvss 9.8epss 0.01

    In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default from Pinot release 0.11.0.…

  • CVE-2022-39227CriSep 23, 2022
    risk 0.52cvss 9.1epss 0.04

    python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its…

  • CVE-2022-37235CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncat

  • CVE-2022-37232CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear N300 wireless router wnr2000v4-V1.0.0.70 is vulnerable to Buffer Overflow via uhttpd. There is a stack overflow vulnerability caused by strcpy.

  • CVE-2022-38573CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.

  • CVE-2022-40089CriSep 22, 2022
    risk 0.64cvss 9.8epss 0.02

    A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.

  • CVE-2022-40087CriSep 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-36934CriSep 22, 2022
    risk 0.64cvss 9.8epss 0.02

    An integer overflow in WhatsApp could result in remote code execution in an established video call.

  • CVE-2022-31937CriSep 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Netgear N300 wireless router wnr2000v4-V1.0.0.70 was discovered to contain a stack overflow via strcpy in uhttpd.

  • CVE-2022-3268CriSep 22, 2022
    risk 0.00cvss 9.8epss 0.01

    Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.

  • CVE-2022-40186CriSep 22, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in HashiCorp Vault and Vault Enterprise before 1.11.3. A vulnerability in the Identity Engine was found where, in a deployment where an entity has multiple mount accessors with shared alias names, Vault may overwrite metadata to the wrong alias due to an…

  • CVE-2022-36386CriSep 21, 2022
    risk 0.59cvss 9.1epss 0.01

    Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.

  • CVE-2022-28802CriSep 21, 2022
    risk 0.64cvss 9.9epss 0.01

    Code by Zapier before 2022-08-17 allowed intra-account privilege escalation that included execution of Python or JavaScript code. In other words, Code by Zapier was providing a customer-controlled general-purpose virtual machine that unintentionally granted full access to all…

  • CVE-2021-43310CriSep 21, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were being re-added to a verifier. This could lead to a remote code execution.

  • CVE-2022-40030CriSep 21, 2022
    risk 0.64cvss 9.8epss 0.01

    SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php.

  • CVE-2022-41241CriSep 21, 2022
    risk 0.59cvss 9.1epss 0.01

    Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-41238CriSep 21, 2022
    risk 0.64cvss 9.8epss 0.01

    A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.

  • CVE-2022-41237CriSep 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

  • CVE-2022-41226CriSep 21, 2022
    risk 0.57cvss 9.8epss 0.01

    Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-37026CriSep 21, 2022
    risk 0.64cvss 9.8epss 0.01

    In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.

  • CVE-2022-0495CriSep 21, 2022
    risk 0.61cvss 9.4epss 0.01

    The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticated SQL Injection vulnerability. This has been fixed in the version 19.05.03.01.

  • CVE-2022-2315CriSep 21, 2022
    risk 0.61cvss 9.4epss 0.01

    Database Software Accreditation Tracking/Presentation Module product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2.

  • CVE-2022-41220CriSep 21, 2022
    risk 0.64cvss 9.8epss 0.01

    md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: the vendor's position is that the product is not intended for untrusted input

  • CVE-2022-38619CriSep 21, 2022
    risk 0.64cvss 9.8epss 0.01

    SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.

  • CVE-2022-40357CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_crawler.php file allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into…

  • CVE-2022-32882CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. An app may be able to bypass Privacy preferences.

  • CVE-2022-32863CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2022-32788CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.02

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. A remote user may be able to cause kernel code execution.

  • CVE-2022-40009CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    SWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function grow_unicode at /lib/ttf.c.

  • CVE-2022-40008CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    SWFTools commit 772e55a was discovered to contain a heap-buffer overflow via the function readU8 at /lib/ttf.c.