VYPR

CVEs

31,787 total · page 311 of 636

  • CVE-2022-20386CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.00

    Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227328

  • CVE-2022-20385CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.00

    a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspace) with 'maxtype' (in this case, it is GSCAN_MAX), then it access polciy array 'policy[type]', which OOB access happens.Product: AndroidVersions: Android…

  • CVE-2021-0942CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.00

    The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the ui32PageIndex offset in the expression:sPA.uiAddr = page_to_phys(psOSPageArrayData->pagearray[ui32PageIndex]);With the current PoC this crashes as an OOB read.…

  • CVE-2022-39206CriSep 13, 2022
    risk 0.00cvss 9.9epss 0.02

    Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. When using Docker-based job executors, the Docker socket (e.g. /var/run/docker.sock on Linux) is mounted into each Docker step. Users that can define and trigger CI/CD jobs on a project could use this to…

  • CVE-2022-39205CriSep 13, 2022
    risk 0.00cvss 9.0epss 0.02

    Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. In versions of Onedev prior to 7.3.0 unauthenticated users can take over a OneDev instance if there is no properly configured reverse proxy. The /git-prereceive-callback endpoint is used by the pre-receive…

  • CVE-2022-34722CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.02

    Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability

  • CVE-2022-34721CriSep 13, 2022
    risk 0.70cvss 9.8epss 0.76

    Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability

  • CVE-2022-34718CriSep 13, 2022
    risk 0.68cvss 9.8epss 0.46

    Windows TCP/IP Remote Code Execution Vulnerability

  • CVE-2022-38542CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill_session interface. The project has released an update, please upgrade to v1.9.0 and above.

  • CVE-2022-38541CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_time parameters in the my2sql interface.

  • CVE-2022-38540CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the create_kill_session interface.

  • CVE-2022-38539CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/apply.

  • CVE-2022-38538CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the report module.

  • CVE-2022-38537CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file, start_time, and stop_time parameters in the binlog2sql interface.

  • CVE-2022-37011CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 8 compatible) (All versions < V2.3.0), Mendix SAML (Mendix 9 compatible, New Track) (All versions < V3.3.1), Mendix SAML (Mendix 9 compatible, Upgrade Track)…

  • CVE-2022-38297CriSep 12, 2022
    risk 0.64cvss 9.8epss 0.01

    UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.

  • CVE-2022-38296CriSep 12, 2022
    risk 0.64cvss 9.8epss 0.04

    Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.

  • CVE-2022-38292CriSep 12, 2022
    risk 0.64cvss 9.8epss 0.01

    SLiMS Senayan Library Management System v9.4.2 was discovered to contain multiple Server-Side Request Forgeries via the components /bibliography/marcsru.php and /bibliography/z3950sru.php.

  • CVE-2022-37860CriSep 12, 2022
    risk 0.70cvss 9.8epss 0.80

    The web configuration interface of the TP-Link M7350 V3 with firmware version 190531 is affected by a pre-authentication command injection vulnerability.

  • CVE-2022-37300CriSep 12, 2022
    risk 0.64cvss 9.8epss 0.01

    A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions…

  • CVE-2022-37767CriSep 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Pebble Templates 3.1.5 allows attackers to bypass a protection mechanism and implement arbitrary code execution with springbok. NOTE: the vendor disputes this because input to the Pebble templating engine is intended to include arbitrary Java code, and thus either the input…

  • CVE-2022-37794CriSep 12, 2022
    risk 0.64cvss 9.8epss 0.01

    In Library Management System 1.0 the /card/in-card.php file id_no parameters are vulnerable to SQL injection.

  • CVE-2022-39135CriSep 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (XXE) attack. Therefore any client…

  • CVE-2022-38638CriSep 9, 2022
    risk 0.52cvss 9.1epss 0.01

    Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.

  • CVE-2021-44835CriSep 9, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Active Intelligent Visualization 5. The Vdc header is used in a SQL query without being sanitized. This causes SQL injection.

  • CVE-2022-2526CriSep 9, 2022
    risk 0.00cvss 9.8epss 0.01

    A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks…

  • CVE-2022-40305CriSep 9, 2022
    risk 0.64cvss 9.8epss 0.01

    A Server-Side Request Forgery issue in Canto Cumulus through 11.1.3 allows attackers to enumerate the internal network, overload network resources, and possibly have unspecified other impact via the server parameter to the /cwc/login login form.

  • CVE-2022-36084CriSep 8, 2022
    risk 0.57cvss 9.9epss 0.01

    cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl starting with version 1.1.0 and prior to versions 2.7.0 and 3.0.2 is used to generate a schema that uses `@flexSearchFulltext`, users of that schema may be able to…

  • CVE-2022-36100CriSep 8, 2022
    risk 0.63cvss 9.9epss 0.74

    XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki Platform Applications Tag and prior to 13.10.6 and 14.4 in XWiki Platform Tag UI, the tags document `Main.Tags` in XWiki didn't…

  • CVE-2022-36099CriSep 8, 2022
    risk 0.63cvss 9.9epss 0.76

    XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting with version 5.3-milestone-2 and prior to versions 13.10.6 and 14.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script…

  • CVE-2022-37164CriSep 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Inoda OnTrack v3.4 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much easier for tools like hashcat to crack the…

  • CVE-2022-37163CriSep 8, 2022
    risk 0.64cvss 9.8epss 0.00

    Bminusl IHateToBudget v1.5.7 employs a weak password policy which allows attackers to potentially gain unauthorized access to the application via brute-force attacks. Additionally, user passwords are hashed without a salt or pepper making it much easier for tools like hashcat to…

  • CVE-2022-27593CriKEVSep 8, 2022
    risk 0.90cvss 10.0epss 0.88

    An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo…

  • CVE-2022-38394CriSep 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote unauthenticated attacker to execute an arbitrary OS command.

  • CVE-2022-33941CriSep 8, 2022
    risk 0.64cvss 9.8epss 0.02

    PowerCMS XMLRPC API provided by Alfasado Inc. contains a command injection vulnerability. Sending a specially crafted message by POST method to PowerCMS XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it. Affected…

  • CVE-2022-36588CriSep 8, 2022
    risk 0.64cvss 9.8epss 0.02

    In D-Link DAP1650 v1.04 firmware, the fileaccess.cgi program in the firmware has a buffer overflow vulnerability caused by strncpy.

  • CVE-2022-36586CriSep 8, 2022
    risk 0.64cvss 9.8epss 0.01

    In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0x869f4 in the httpd binary.

  • CVE-2021-34236CriSep 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cause a denial-of-service by sending a crafted POST to '/bd_genie_create_account.cgi' with a sufficiently long parameter 'register_country'.

  • CVE-2022-36585CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf.

  • CVE-2022-38250CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.03

    Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.

  • CVE-2022-38314CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo.

  • CVE-2022-38313CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/saveParentControlInfo.

  • CVE-2022-38312CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind.

  • CVE-2022-38311CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/PowerSaveSet.

  • CVE-2022-38310CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.

  • CVE-2022-38309CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.

  • CVE-2022-36660CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    xhyve commit dfbe09b was discovered to contain a stack buffer overflow via the component pci_vtrnd_notify().

  • CVE-2022-36587CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.01

    In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by sprintf in function in the httpd binary.

  • CVE-2022-31247CriSep 7, 2022
    risk 0.59cvss 9.1epss 0.01

    An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role template bindings or project role template bindings (such as cluster-owner, manage cluster members, project-owner and manage project members) to gain owner…

  • CVE-2021-36783CriSep 7, 2022
    risk 0.64cvss 9.9epss 0.01

    A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed via API endpoints. This…