VYPR

CVEs

31,787 total · page 312 of 636

  • CVE-2021-36782CriSep 7, 2022
    risk 0.68cvss 9.9epss 0.03

    A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners, Project Members and User Base to use the Kubernetes API to retrieve plaintext version of sensitive data. This issue affects: SUSE…

  • CVE-2022-1525CriSep 6, 2022
    risk 0.59cvss 9.1epss 0.01

    The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-602: Client-Side Enforcement of Server-Side Security, which could allow attackers to bypass web access controls by inspecting and modifying the source code of password…

  • CVE-2022-1368CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-306: Missing Authentication for Critical Function, which allows unauthorized users to change the operator account password via webserver commands by monitoring web socket…

  • CVE-2022-36067CriSep 6, 2022
    risk 0.62cvss 10.0epss 0.48

    vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in…

  • CVE-2022-36663CriSep 6, 2022
    risk 0.57cvss 9.8epss 0.02

    Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter.

  • CVE-2022-31789CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.02

    An integer overflow in WatchGuard Firebox and XTM appliances allows an unauthenticated remote attacker to trigger a buffer overflow and potentially execute arbitrary code by sending a malicious request to exposed management ports. This is fixed in Fireware OS 12.8.1, 12.5.10,…

  • CVE-2020-21516CriSep 6, 2022
    risk 0.57cvss 9.8epss 0.01

    There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code.

  • CVE-2022-31860CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule.

  • CVE-2022-26447CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06784478; Issue ID: ALPS06784478.

  • CVE-2022-40111CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware.

  • CVE-2022-40109CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa.

  • CVE-2022-37843CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In TOTOLINK A860R V4.1.2cu.5182_B20201027 in cstecgi.cgi, the acquired parameters are directly put into the system for execution without filtering, resulting in a command injection vulnerability.

  • CVE-2022-37842CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In TOTOLINK A860R V4.1.2cu.5182_B20201027, the parameters in infostat.cgi are not filtered, causing a buffer overflow vulnerability.

  • CVE-2022-37840CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In TOTOLINK A860R V4.1.2cu.5182_B20201027, the main function in downloadfile.cgi has a buffer overflow vulnerability.

  • CVE-2022-37839CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A860R V4.1.2cu.5182_B20201027 is vulnerable to Buffer Overflow via Cstecgi.cgi.

  • CVE-2022-36584CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf.

  • CVE-2022-2714CriSep 6, 2022
    risk 0.57cvss 9.8epss 0.01

    Improper Handling of Length Parameter Inconsistency in GitHub repository francoisjacquet/rosariosis prior to 10.0.

  • CVE-2022-34882CriSep 6, 2022
    risk 0.59cvss 9.0epss 0.01

    Information Exposure Through an Error Message vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users to gain sensitive information. This issue affects: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versions prior to…

  • CVE-2022-34747CriSep 6, 2022
    risk 0.64cvss 9.8epss 0.02

    A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to achieve unauthorized remote code execution via a crafted UDP packet.

  • CVE-2022-31814CriSep 5, 2022
    risk 0.10cvss 9.8epss 0.87

    pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.

  • CVE-2022-36642CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.10

    A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of…

  • CVE-2022-36640CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.02

    influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly…

  • CVE-2021-27693CriSep 2, 2022
    risk 0.00cvss 9.8epss 0.01

    Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.

  • CVE-2020-22669CriSep 2, 2022
    risk 0.00cvss 9.8epss 0.01

    Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web…

  • CVE-2022-22096CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in Bluetooth HOST due to stack-based buffer overflow when when extracting data using command length parameter in Snapdragon Connectivity, Snapdragon Mobile

  • CVE-2021-35122CriSep 2, 2022
    risk 0.60cvss 9.3epss 0.00

    Non-secure region can try modifying RG permissions of IO space xPUs due to improper input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

  • CVE-2022-38054CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.02

    In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.

  • CVE-2022-29063CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.04

    The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or on a server…

  • CVE-2022-25371CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.04

    Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution (RCE) attack in…

  • CVE-2022-36609CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pms/update_patient.php.

  • CVE-2022-36594CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds function.

  • CVE-2022-36759CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?res_id=.

  • CVE-2022-36601CriSep 1, 2022
    risk 0.64cvss 9.8epss 0.01

    The Eclipse TCF debug interface in JasMiner-X4-Server-20220621-090907 and below is open on port 1534. This issue allows unauthenticated attackers to gain root privileges on the affected device and access sensitive data or execute arbitrary commands.

  • CVE-2022-34380CriSep 1, 2022
    risk 0.60cvss 9.3epss 0.00

    Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulnerability. A high privileged local attacker may potentially exploit this vulnerability leading to authentication bypass and access the CloudLink system console.…

  • CVE-2022-34379CriSep 1, 2022
    risk 0.61cvss 9.4epss 0.01

    Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with the knowledge of the active directory usernames, could potentially exploit this vulnerability to gain unauthorized access to the system.

  • CVE-2022-34372CriSep 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially access and interact with the docker registry API leading to an authentication bypass. The attacker may potentially alter…

  • CVE-2020-35527CriSep 1, 2022
    risk 0.64cvss 9.8epss 0.01

    In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.

  • CVE-2022-36672CriSep 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.

  • CVE-2022-36130CriSep 1, 2022
    risk 0.64cvss 9.9epss 0.00

    HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated with the correct scopes, allowing potential privilege escalation for authorized users of another scope. Fixed in Boundary 0.10.2.

  • CVE-2022-37130CriAug 31, 2022
    risk 0.66cvss 9.8epss 0.26

    In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagnosis, after the condition is met, setnum will be spliced into v10 by snprintf, and the system will be executed, resulting in a command injection vulnerability

  • CVE-2022-37125CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.03

    D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost.

  • CVE-2022-36202CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.01

    Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter.

  • CVE-2022-36201CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.02

    Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php.

  • CVE-2022-37128CriAug 31, 2022
    risk 0.65cvss 9.8epss 0.21

    In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.

  • CVE-2022-36566CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.02

    Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.

  • CVE-2022-30318CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.01

    Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials issue. The affected components are characterized as: SSH. The potential impact is: Remote code execution, manipulate…

  • CVE-2022-30317CriAug 31, 2022
    risk 0.59cvss 9.1epss 0.01

    Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0055, there is a Honeywell Experion LX Control Data Access (CDA) EpicMo protocol with unauthenticated functionality issue. The affected components are…

  • CVE-2022-2485CriAug 31, 2022
    risk 0.62cvss 9.6epss 0.00

    Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device responding with its password in the communication packets.

  • CVE-2022-2466CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.01

    It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavior.

  • CVE-2022-21941CriAug 31, 2022
    risk 0.65cvss 10.0epss 0.02

    All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system.