VYPR

CVEs

31,787 total · page 317 of 636

  • CVE-2022-2661CriAug 16, 2022
    risk 0.64cvss 9.9epss 0.01

    Sequi PortBloque S has an improper authorization vulnerability, which may allow a low-privileged user to perform administrative functions using specifically crafted requests.

  • CVE-2021-39085CriAug 16, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete…

  • CVE-2022-36242CriAug 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Clinic's Patient Management System v1.0 is vulnerable to SQL Injection via /pms/update_medicine.php?id=.

  • CVE-2022-36599CriAug 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.

  • CVE-2022-36273CriAug 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 V15.03.2.21_cn is vulnerable to command injection via goform/SetSysTimeCfg.

  • CVE-2022-36272CriAug 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.

  • CVE-2022-30264CriAug 16, 2022
    risk 0.64cvss 9.8epss 0.00

    The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer…

  • CVE-2022-36344CriAug 16, 2022
    risk 0.64cvss 9.8epss 0.01

    An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others. Since the affected product starts another program with an unquoted file path, a malicious…

  • CVE-2022-36308CriAug 16, 2022
    risk 0.59cvss 9.1epss 0.01

    Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 credentials unhashed on the filesystem, enabling anyone with web access to use these credentials to manipulate the eNodeB over SNMP.…

  • CVE-2020-21642CriAug 15, 2022
    risk 0.64cvss 9.8epss 0.08

    Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.

  • CVE-2022-36010CriAug 15, 2022
    risk 0.58cvss 10.0epss 0.01

    This library allows strings to be parsed as functions and stored as a specialized component, [`JsonFunctionValue`](https://github.com/oxyno-zeta/react-editable-json-tree/blob/09a0ca97835b0834ad054563e2fddc6f22bc5d8c/src/components/JsonFunctionValue.js). To do this, Javascript's…

  • CVE-2022-36525CriAug 15, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Buffer Overflow via authenticationcgi_main.

  • CVE-2022-36523CriAug 15, 2022
    risk 0.64cvss 9.8epss 0.02

    D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/upnpinc/gena.php.

  • CVE-2022-36262CriAug 15, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.

  • CVE-2022-34294CriAug 15, 2022
    risk 0.64cvss 9.8epss 0.01

    totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning because there is not enough entropy to prevent traffic injection attacks.

  • CVE-2022-38221CriAug 15, 2022
    risk 0.64cvss 9.8epss 0.02

    A buffer overflow in the FTcpListener thread in The Isle Evrima (the dedicated server on Windows and Linux) 0.9.88.07 before 2022-08-12 allows a remote attacker to crash any server with an accessible RCON port, or possibly execute arbitrary code.

  • CVE-2022-2818CriAug 15, 2022
    risk 0.57cvss 9.8epss 0.01

    Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.

  • CVE-2022-2314CriAug 15, 2022
    risk 0.65cvss 9.8epss 0.13

    The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.

  • CVE-2022-2180CriAug 15, 2022
    risk 0.64cvss 9.8epss 0.02

    The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, leading to possible remote code execution…

  • CVE-2022-35942CriAug 12, 2022
    risk 0.53cvss 9.3epss 0.01

    Improper input validation on the `contains` LoopBack filter may allow for arbitrary SQL injection. When the extended filter property `contains` is permitted to be interpreted by the Postgres connector, it is possible to inject arbitrary SQL which may affect the confidentiality…

  • CVE-2022-2587CriAug 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote attacker to potentially exploit heap corruption via crafted audio metadata.

  • CVE-2022-37042CriKEVAug 12, 2022
    risk 0.92cvss 9.8epss 0.89

    Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal…

  • CVE-2022-35559CriAug 12, 2022
    risk 0.65cvss 9.8epss 0.11

    A stack overflow vulnerability exists in /goform/setAutoPing in Tenda W6 V1.0.0.9(4122), which allows an attacker to construct ping1 parameters and ping2 parameters for a stack overflow attack. An attacker can use this vulnerability to execute arbitrary code execution.

  • CVE-2022-35555CriAug 12, 2022
    risk 0.66cvss 9.8epss 0.25

    A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to construct cmdinput parameters for arbitrary command execution.

  • CVE-2022-28755CriAug 11, 2022
    risk 0.62cvss 9.6epss 0.01

    The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading…

  • CVE-2022-20405CriAug 11, 2022
    risk 0.64cvss 9.8epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-216363416References: N/A

  • CVE-2022-20403CriAug 11, 2022
    risk 0.64cvss 9.8epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-207975764References: N/A

  • CVE-2022-20402CriAug 11, 2022
    risk 0.64cvss 9.8epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-218701042References: N/A

  • CVE-2022-20400CriAug 11, 2022
    risk 0.64cvss 9.8epss 0.01

    In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2022-20384CriAug 11, 2022
    risk 0.64cvss 9.8epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-211727306References: N/A

  • CVE-2022-20381CriAug 11, 2022
    risk 0.64cvss 9.8epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-188935887References: N/A

  • CVE-2022-20378CriAug 11, 2022
    risk 0.64cvss 9.8epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-234657153References: N/A

  • CVE-2022-20365CriAug 11, 2022
    risk 0.64cvss 9.8epss 0.00

    Product: AndroidVersions: Android kernelAndroid ID: A-229632566References: N/A

  • CVE-2022-20237CriAug 11, 2022
    risk 0.64cvss 9.8epss 0.01

    In BuildDevIDResponse of miscdatabuilder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-38130CriAug 10, 2022
    risk 0.68cvss 9.8epss 0.53

    The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takes the path of the zipped database file as the single parameter. An unauthenticated, remote attacker can specify an UNC path for the database…

  • CVE-2022-38129CriAug 10, 2022
    risk 0.65cvss 9.8epss 0.18

    A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to the SMS host.

  • CVE-2022-37003CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.00

    The AOD module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may cause permission escalation and unauthorized access to files.

  • CVE-2022-37002CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.00

    The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this vulnerability can cause malicious applications to pop up windows or run in the background.

  • CVE-2022-36750CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Clinic's Patient Management System v1.0 is vulnerable to SQL injection via /pms/update_user.php?id=.

  • CVE-2022-36270CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php.

  • CVE-2022-35538CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.02

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: delete_list, delete_al_mac, b_delete_list and b_delete_al_mac, which leads to command injection in page /wifi_mesh.shtml.

  • CVE-2022-35537CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.02

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameters: mac_5g and Newname, which leads to command injection in page /wifi_mesh.shtml.

  • CVE-2022-35536CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.02

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 qos.cgi has no filtering on parameters: qos_bandwith and qos_dat, which leads to command injection in page /qos.shtml.

  • CVE-2022-35535CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.02

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter macAddr, which leads to command injection in page /wifi_mesh.shtml.

  • CVE-2022-35534CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.02

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 wireless.cgi has no filtering on parameter hiddenSSID32g and SSID2G2, which leads to command injection in page /wifi_multi_ssid.shtml.

  • CVE-2022-35533CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.02

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 qos.cgi has no filtering on parameters: cli_list and cli_num, which leads to command injection in page /qos.shtml.

  • CVE-2022-35526CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.02

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 login.cgi has no filtering on parameter key, which leads to command injection in page /login.shtml.

  • CVE-2022-35525CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.02

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameter led_switch, which leads to command injection in page /ledonoff.shtml.

  • CVE-2022-35524CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.02

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 adm.cgi has no filtering on parameters: wlan_signal, web_pskValue, sel_EncrypTyp, sel_Automode, wlan_bssid, wlan_ssid and wlan_channel, which leads to command injection in page /wizard_rep.shtml.

  • CVE-2022-35523CriAug 10, 2022
    risk 0.64cvss 9.8epss 0.02

    WAVLINK WN572HP3, WN533A8, WN530H4, WN535G3, WN531P3 firewall.cgi has no filtering on parameter del_mac and parameter flag, which leads to command injection in page /cli_black_list.shtml.