VYPR

CVEs

31,787 total · page 319 of 636

  • CVE-2022-24020CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability…

  • CVE-2022-24019CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability…

  • CVE-2022-24018CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability…

  • CVE-2022-24017CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability…

  • CVE-2022-24016CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability…

  • CVE-2022-24015CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability…

  • CVE-2022-24014CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability…

  • CVE-2022-24013CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability…

  • CVE-2022-24012CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability…

  • CVE-2022-24011CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability…

  • CVE-2022-24010CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability…

  • CVE-2022-24009CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability…

  • CVE-2022-24008CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability…

  • CVE-2022-24007CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability…

  • CVE-2022-24006CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability…

  • CVE-2022-24005CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability…

  • CVE-2022-23919CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the confsrv set_mf_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this…

  • CVE-2022-23918CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the confsrv set_mf_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this…

  • CVE-2022-23399CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the confsrv set_port_fwd_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this…

  • CVE-2022-23103CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the confsrv confctl_set_app_language functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger…

  • CVE-2022-22144CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    A hard-coded password vulnerability exists in the libcommonprod.so prod_change_root_passwd functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. During system startup this functionality is always called, leading to a known root password. An attacker does not have to do…

  • CVE-2022-22140CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.04

    An os command injection vulnerability exists in the confsrv ucloud_add_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2022-21178CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.04

    An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this…

  • CVE-2022-31657CriAug 5, 2022
    risk 0.64cvss 9.8epss 0.01

    VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain.

  • CVE-2022-31656CriAug 5, 2022
    risk 0.65cvss 9.8epss 0.19

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

  • CVE-2022-37434CriAug 5, 2022
    risk 0.65cvss 9.8epss 0.16

    zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable…

  • CVE-2022-21186CriAug 5, 2022
    risk 0.59cvss 9.8epss 0.25

    The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.

  • CVE-2022-35143CriAug 4, 2022
    risk 0.57cvss 9.8epss 0.01

    Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force attacks.

  • CVE-2022-34993CriAug 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample.

  • CVE-2022-34970CriAug 4, 2022
    risk 0.00cvss 9.8epss 0.03

    Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitation this vulnerability allows attackers to remotely execute arbitrary code in the context of the vulnerable service.

  • CVE-2022-25168CriAug 4, 2022
    risk 0.57cvss 9.8epss 0.03

    Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands. This is only used in Hadoop 3.3 InMemoryAliasMap.completeBootstrapTransfer, which is only ever run by a local user. It…

  • CVE-2022-32965CriAug 4, 2022
    risk 0.64cvss 9.8epss 0.01

    OMICARD EDM has a hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code, manipulate system data and disrupt service.

  • CVE-2022-32964CriAug 4, 2022
    risk 0.64cvss 9.8epss 0.01

    OMICARD EDM’s API function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to access, modify, delete database or disrupt service.

  • CVE-2022-2651CriAug 4, 2022
    risk 0.04cvss 9.8epss 0.12

    Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5.

  • CVE-2022-35161CriAug 3, 2022
    risk 0.64cvss 9.8epss 0.01

    GVRET Stable Release as of Aug 15, 2015 was discovered to contain a buffer overflow via the handleConfigCmd function at SerialConsole.cpp.

  • CVE-2022-35866CriAug 3, 2022
    risk 0.64cvss 9.8epss 0.03

    This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the MySQL server. The…

  • CVE-2022-35865CriAug 3, 2022
    risk 0.64cvss 9.8epss 0.01

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authorization of HTTP requests. The issue results from…

  • CVE-2022-2272CriAug 3, 2022
    risk 0.64cvss 9.8epss 0.02

    This vulnerability allows remote attackers to bypass authentication on affected installations of Sante PACS Server 3.0.4. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of calls to the login endpoint. When parsing the…

  • CVE-2022-35620CriAug 3, 2022
    risk 0.66cvss 9.8epss 0.31

    D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function binary.soapcgi_main.

  • CVE-2022-35619CriAug 3, 2022
    risk 0.64cvss 9.8epss 0.02

    D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the function ssdpcgi_main.

  • CVE-2022-34974CriAug 3, 2022
    risk 0.66cvss 9.8epss 0.23

    D-Link DIR810LA1_FW102B22 was discovered to contain a command injection vulnerability via the Ping_addr function.

  • CVE-2022-32292CriAug 3, 2022
    risk 0.64cvss 9.8epss 0.02

    In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in received_data to execute code.

  • CVE-2022-30285CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.00

    In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with invalid credentials.

  • CVE-2022-29807CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code execution via download_agent_installer.php.

  • CVE-2022-35924CriAug 2, 2022
    risk 0.52cvss 9.1epss 0.01

    NextAuth.js is a complete open source authentication solution for Next.js applications. `next-auth` users who are using the `EmailProvider` either in versions before `4.10.3` or `3.29.10` are affected. If an attacker could forge a request that sent a comma-separated list of…

  • CVE-2022-35223CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation vulnerability. Deserializing a cookie containing malicious payload will trigger this insecure deserialization vulnerability, allowing an unauthenticated remote attacker to execute…

  • CVE-2022-34613CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file.

  • CVE-2020-28453CriAug 2, 2022
    risk 0.61cvss 9.4epss 0.01

    This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.

  • CVE-2020-28451CriAug 2, 2022
    risk 0.57cvss 9.8epss 0.01

    This affects the package image-tiler before 2.0.2.

  • CVE-2020-28437CriAug 2, 2022
    risk 0.61cvss 9.4epss 0.01

    This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.