VYPR

CVEs

31,787 total · page 310 of 636

  • CVE-2022-39009CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WLAN functions.

  • CVE-2022-39008CriSep 16, 2022
    risk 0.59cvss 9.1epss 0.01

    The NFC module has bundle serialization/deserialization vulnerabilities. Successful exploitation of this vulnerability may cause third-party apps to read and write files that are accessible only to system apps.

  • CVE-2022-39007CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    The location module has a vulnerability of bypassing permission verification.Successful exploitation of this vulnerability may cause privilege escalation.

  • CVE-2022-39003CriSep 16, 2022
    risk 0.59cvss 9.1epss 0.00

    Buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerability will affect the confidentiality and integrity of trusted components.

  • CVE-2022-39002CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Double free vulnerability in the storage module. Successful exploitation of this vulnerability will cause the memory to be freed twice.

  • CVE-2022-39000CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    The iAware module has a vulnerability in managing malicious apps.Successful exploitation of this vulnerability will cause malicious apps to automatically start upon system startup.

  • CVE-2022-38999CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    The AOD module has the improper update of reference count vulnerability. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability.

  • CVE-2021-40019CriSep 16, 2022
    risk 0.59cvss 9.1epss 0.01

    Out-of-bounds heap read vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may cause out-of-bounds access.

  • CVE-2021-40017CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may result in out-of-bounds memory access.

  • CVE-2022-38831CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/SetNetControlList

  • CVE-2022-38830CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setIPv6Status.

  • CVE-2022-38829CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda RX9_Pro V22.03.02.10 is vulnerable to Buffer Overflow via httpd/setMacFilterCfg.

  • CVE-2022-38828CriSep 16, 2022
    risk 0.65cvss 9.8epss 0.19

    TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to command injection via cstecgi.cgi

  • CVE-2022-38827CriSep 16, 2022
    risk 0.65cvss 9.8epss 0.12

    TOTOLINK T6 V4.1.5cu.709_B20210518 is vulnerable to Buffer Overflow via cstecgi.cgi

  • CVE-2022-38826CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    In TOTOLINK T6 V4.1.5cu.709_B20210518, there is an execute arbitrary command in cstecgi.cgi.

  • CVE-2022-38823CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.01

    In TOTOLINK T6 V4.1.5cu.709_B20210518, there is a hard coded password for root in /etc/shadow.sample.

  • CVE-2021-42949CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.06

    The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session token, allowing attackers to bypass authentication via bruteforce attacks.

  • CVE-2022-25708CriSep 16, 2022
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in WLAN due to buffer copy without checking size of input while parsing keys in Snapdragon Connectivity, Snapdragon Mobile

  • CVE-2022-25652CriSep 16, 2022
    risk 0.59cvss 9.0epss 0.00

    Cryptographic issues in BSP due to improper hash verification in Snapdragon Wired Infrastructure and Networking

  • CVE-2022-22105CriSep 16, 2022
    risk 0.61cvss 9.4epss 0.00

    Memory corruption in bluetooth due to integer overflow while processing HFP-UNIT profile in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music

  • CVE-2022-36536CriSep 16, 2022
    risk 0.67cvss 9.8epss 0.04

    An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens.

  • CVE-2022-26959CriSep 16, 2022
    risk 0.65cvss 10.0epss 0.01

    There are two full (read/write) Blind/Time-based SQL injection vulnerabilities in the Northstar Club Management version 6.3 application. The vulnerabilities exist in the userName parameter of the processlogin.jsp page in the /northstar/Portal/ directory and the userID parameter…

  • CVE-2022-38326CriSep 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the page parameter at /goform/NatStaticSetting.

  • CVE-2022-38325CriSep 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 WiFi Router V15.03.05.19_multi and AC18 WiFi Router V15.03.05.19_multi were discovered to contain a buffer overflow via the filePath parameter at /goform/expandDlnaFile.

  • CVE-2022-37861CriSep 15, 2022
    risk 0.64cvss 9.8epss 0.02

    There is a remote code execution (RCE) vulnerability in Tenhot TWS-100 V4.0-201809201424 router device. It is necessary to know that the device account password is allowed to escape the execution system command through the network tools in the network diagnostic component.

  • CVE-2022-37264CriSep 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in stealjs steal 2.2.4 via the optionName variable in main.js.

  • CVE-2022-2471CriSep 15, 2022
    risk 0.64cvss 9.9epss 0.01

    Stack-based Buffer Overflow vulnerability in the EZVIZ Motion Detection component as used in camera models CS-CV248, CS-C6N-A0-1C2WFR, CS-DB1C-A0-1E2W2FR, CS-C6N-B0-1G2WF, CS-C3W-A0-3H4WFRL allows a remote attacker to execute remote code on the device. This issue affects: EZVIZ…

  • CVE-2022-37266CriSep 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js.

  • CVE-2022-37257CriSep 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVersion variable in npm-convert.js.

  • CVE-2022-38789CriSep 15, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Airties Smart Wi-Fi before 2020-08-04. It allows attackers to change the main/guest SSID and the PSK to arbitrary values, and map the LAN, because of Insecure Direct Object Reference.

  • CVE-2022-38352CriSep 15, 2022
    risk 0.65cvss 9.8epss 0.20

    ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Storage\Psr6Cache. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

  • CVE-2022-38308CriSep 14, 2022
    risk 0.65cvss 9.8epss 0.20

    TOTOLink A700RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the lang parameter in the function cstesystem. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.

  • CVE-2022-35947CriSep 14, 2022
    risk 0.00cvss 10.0epss 0.01

    GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. Affected versions have been found to be vulnerable to a SQL injection attack which…

  • CVE-2022-37661CriSep 14, 2022
    risk 0.70cvss 9.8epss 0.36

    SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.

  • CVE-2022-37138CriSep 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Loan Management System 1.0 is vulnerable to SQL Injection at the login page, which allows unauthorized users to login as Administrator after injecting username form.

  • CVE-2022-36669CriSep 14, 2022
    risk 0.64cvss 9.8epss 0.02

    Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

  • CVE-2022-36436CriSep 14, 2022
    risk 0.57cvss 9.8epss 0.02

    OSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentication-bypass vulnerability that could allow a malicious actor to gain unauthorized access to a VNC session or to disconnect a legitimate user from a VNC…

  • CVE-2022-2900CriSep 14, 2022
    risk 0.52cvss 9.1epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 8.1.0.

  • CVE-2022-34831CriSep 14, 2022
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order and the corresponding CSR submitted during finalization. During the ACME enrollment process, an order is submitted containing an…

  • CVE-2020-19586CriSep 14, 2022
    risk 0.59cvss 9.0epss 0.01

    Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI.

  • CVE-2022-38771CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to send SCRIPT tags as injected input to the API request.

  • CVE-2022-38768CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to bypass authorization.

  • CVE-2022-35413CriSep 13, 2022
    risk 0.65cvss 9.8epss 0.14

    WAPPLES through 6.0 has a hardcoded systemi account. A threat actor could use this account to access the system configuration and confidential information (such as SSL keys) via an HTTPS request to the /webapi/ URI on port 443 or 5001.

  • CVE-2022-39815CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.02

    In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system.

  • CVE-2022-38637CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.05

    Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page.

  • CVE-2022-20391CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.00

    Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257000

  • CVE-2022-20390CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.00

    Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257002

  • CVE-2022-20389CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.00

    Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257004

  • CVE-2022-20388CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.00

    Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227323

  • CVE-2022-20387CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.00

    Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227324