VYPR

CVEs

31,787 total · page 313 of 636

  • CVE-2022-36045CriAug 31, 2022
    risk 0.52cvss 9.0epss 0.01

    NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interactions and real-time notifications. `utils.generateUUID`, a helper function available in essentially all versions of NodeBB (as far…

  • CVE-2022-37021CriAug 31, 2022
    risk 0.64cvss 9.8epss 0.02

    Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wishes to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode…

  • CVE-2022-36749CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.02

    RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file.

  • CVE-2022-36735CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /admin/delete.php.

  • CVE-2022-36734CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /admin/delstu.php.

  • CVE-2022-36733CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /admin/del.php.

  • CVE-2022-36732CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /librarian/dele.php.

  • CVE-2022-36731CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /librarian/delstu.php.

  • CVE-2022-36730CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /librarian/delete.php.

  • CVE-2022-37176CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi-Fi password and force the device into open security mode via a crafted packet sent to goform/setWizard.

  • CVE-2022-37149CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.03

    WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the file adm.cgi. This vulnerability allows attackers to execute arbitrary commands via the username parameter.

  • CVE-2022-38116CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Le-yan Personnel and Salary Management System has hard-coded database account and password within the website source code. An unauthenticated remote attacker can access, modify system data or disrupt service.

  • CVE-2022-36714CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /staff/lab.php.

  • CVE-2022-36713CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Section parameter at /librarian/lab.php.

  • CVE-2022-36712CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/studentdetails.php.

  • CVE-2022-36711CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/bookdetails.php.

  • CVE-2022-36709CriAug 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /staff/edit_book_details.php.

  • CVE-2022-36560CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root. Attackers are able to access the passcodes at /etc/srapi/config/system.conf and /usr/sbin/ssol-sshd.sh.

  • CVE-2022-36559CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.02

    Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_exec.cgi.

  • CVE-2022-36558CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg.

  • CVE-2022-36557CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file.

  • CVE-2022-36556CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01.

  • CVE-2022-36555CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked via a brute-force attack.

  • CVE-2022-36554CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows attackers to execute arbitrary commands with root privileges.

  • CVE-2022-36553CriAug 29, 2022
    risk 0.71cvss 9.8epss 0.91

    Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen.cgi.

  • CVE-2022-32993CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.

  • CVE-2022-32548CriAug 29, 2022
    risk 0.68cvss 10.0epss 0.34

    An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.

  • CVE-2022-22897CriAug 29, 2022
    risk 0.65cvss 9.8epss 0.11

    A SQL injection vulnerability in the product_all_one_img and image_product parameters of the ApolloTheme AP PageBuilder component through 2.4.4 for PrestaShop allows unauthenticated attackers to exfiltrate database data.

  • CVE-2022-25644CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.01

    All versions of package @pendo324/get-process-by-name are vulnerable to Arbitrary Code Execution due to improper sanitization of getProcessByName function.

  • CVE-2022-21165CriAug 29, 2022
    risk 0.64cvss 9.8epss 0.03

    All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of input that potentially flows into the child_process.exec() function.

  • CVE-2022-34668CriAug 29, 2022
    risk 0.60cvss 9.8epss 0.09

    NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.

  • CVE-2022-36572CriAug 29, 2022
    risk 0.65cvss 9.8epss 0.21

    Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /upload/admin.php?/deal/.

  • CVE-2022-36708CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /student/bookdetails.php.

  • CVE-2022-36706CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_stockout.php.

  • CVE-2022-36705CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_waste.php.

  • CVE-2022-38555CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.09

    Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.

  • CVE-2022-37056CriAug 28, 2022
    risk 0.65cvss 9.8epss 0.10

    D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main,

  • CVE-2022-37055CriKEVAug 28, 2022
    risk 0.80cvss 9.8epss 0.57

    D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,

  • CVE-2022-38557CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.

  • CVE-2022-38556CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d/S80telnetd.sh.

  • CVE-2022-37057CriAug 28, 2022
    risk 0.66cvss 9.8epss 0.25

    D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Command Injection via cgibin, ssdpcgi_main.

  • CVE-2022-37053CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.02

    TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.

  • CVE-2022-36756CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.03

    DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.

  • CVE-2022-36755CriAug 28, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as demonstrated by a request for getcfg.php.

  • CVE-2022-38792CriAug 27, 2022
    risk 0.57cvss 9.8epss 0.01

    The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party.

  • CVE-2019-15167CriAug 27, 2022
    risk 0.00cvss 9.1epss 0.01

    The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463.

  • CVE-2022-36545CriAug 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php.

  • CVE-2022-36544CriAug 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php.

  • CVE-2022-36543CriAug 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php.

  • CVE-2022-37152CriAug 26, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Online Diagnostic Lab Management System 1.0, There is a SQL injection vulnerability via "dob" parameter in "/classes/Users.php?f=save_client"