VYPR

CVEs

31,787 total · page 320 of 636

  • CVE-2020-28434CriAug 2, 2022
    risk 0.61cvss 9.4epss 0.01

    This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.

  • CVE-2020-28423CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    This affects all versions of package monorepo-build.

  • CVE-2022-35422CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the qid parameter at update.php.

  • CVE-2022-34956CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_groups.php.

  • CVE-2022-34955CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Pligg CMS v2.0.2 was discovered to contain a time-based SQL injection vulnerability via the page_size parameter at load_data_for_topusers.php.

  • CVE-2022-34954CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoiceprint.php.

  • CVE-2022-34953CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getOrderReport.php.

  • CVE-2022-34952CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser.php.

  • CVE-2022-34951CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getsalereport.php.

  • CVE-2022-34950CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editproduct.php.

  • CVE-2022-34949CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or password parameter at login.php.

  • CVE-2022-34948CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editbrand.php.

  • CVE-2022-34947CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcategory.php.

  • CVE-2022-34946CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getexpproduct.php.

  • CVE-2022-34945CriAug 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getproductreport.php.

  • CVE-2022-31321CriAug 1, 2022
    risk 0.59cvss 9.1epss 0.01

    The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) via a crafted input.

  • CVE-2022-31183CriAug 1, 2022
    risk 0.52cvss 9.1epss 0.01

    fs2 is a compositional, streaming I/O library for Scala. When establishing a server-mode `TLSSocket` using `fs2-io` on Node.js, the parameter `requestCert = true` is ignored, peer certificate verification is skipped, and the connection proceeds. The vulnerability is limited to:…

  • CVE-2022-31181CriAug 1, 2022
    risk 0.57cvss 9.8epss 0.05

    PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call PHP's Eval function on attacker input. The problem is fixed in version 1.7.8.7. Users are advised…

  • CVE-2022-31180CriAug 1, 2022
    risk 0.57cvss 9.8epss 0.02

    Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of white space when interpolating output. This issue only impacts users that use the `escape` or `escapeAll` functions with the `interpolation` option set to…

  • CVE-2022-2595CriAug 1, 2022
    risk 0.00cvss 10.0epss 0.01

    Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.

  • CVE-2022-36301CriAug 1, 2022
    risk 0.64cvss 9.8epss 0.01

    BF-OS version 3.x up to and including 3.83 do not enforce strong passwords which may allow a remote attacker to brute-force the device password.

  • CVE-2022-26437CriAug 1, 2022
    risk 0.64cvss 9.8epss 0.01

    In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WSAP00103831; Issue ID: WSAP00103831.

  • CVE-2022-2317CriAug 1, 2022
    risk 0.64cvss 9.8epss 0.01

    The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the registration stage due to insufficient checking of a user supplied parameter.

  • CVE-2022-1950CriAug 1, 2022
    risk 0.64cvss 9.8epss 0.04

    The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

  • CVE-2022-27255CriAug 1, 2022
    risk 0.67cvss 9.8epss 0.37

    In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker to remotely execute code without authentication via a crafted SIP packet that contains malicious SDP data.

  • CVE-2022-31775CriAug 1, 2022
    risk 0.59cvss 9.1epss 0.01

    IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose…

  • CVE-2022-30083CriJul 30, 2022
    risk 0.64cvss 9.8epss 0.01

    EllieGrid Android Application version 3.4.1 is vulnerable to Code Injection. The application appears to evaluate user input as code (remote).

  • CVE-2022-34531CriJul 29, 2022
    risk 0.66cvss 9.8epss 0.23

    DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.

  • CVE-2022-34496CriJul 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Hiby R3 PRO firmware v1.5 to v1.7 was discovered to contain a file upload vulnerability via the file upload feature.

  • CVE-2022-22280CriJul 29, 2022
    risk 0.64cvss 9.8epss 0.09

    Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.3.1-SP2-Hotfix1, Analytics On-Prem 2.5.0.3-2520 and earlier versions.

  • CVE-2022-35643CriJul 29, 2022
    risk 0.59cvss 9.1epss 0.01

    IBM PowerVM VIOS 3.1 could allow a remote attacker to tamper with system configuration or cause a denial of service. IBM X-Force ID: 230956.

  • CVE-2022-1277CriJul 29, 2022
    risk 0.61cvss 9.4epss 0.01

    Inavitas Solar Log product has an unauthenticated SQL Injection vulnerability.

  • CVE-2022-34558CriJul 28, 2022
    risk 0.64cvss 9.8epss 0.01

    WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows attackers to execute arbitrary code via a crafted dbs-client package.

  • CVE-2022-34555CriJul 28, 2022
    risk 0.65cvss 9.8epss 0.20

    TP-LINK TL-R473G 2.0.1 Build 220529 Rel.65574n was discovered to contain a remote code execution vulnerability which is exploited via a crafted packet.

  • CVE-2021-41556CriJul 28, 2022
    risk 0.58cvss 10.0epss 0.02

    sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script…

  • CVE-2022-2564CriJul 28, 2022
    risk 0.59cvss 9.8epss 0.33

    Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.

  • CVE-2016-4991CriJul 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This…

  • CVE-2022-30315CriJul 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient Verification of Data Authenticity. According to FSCT-2022-0053, there is a Honeywell Experion PKS Safety Manager insufficient logic security controls issue. The affected components are…

  • CVE-2022-22683CriJul 28, 2022
    risk 0.65cvss 10.0epss 0.01

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2022-36992CriJul 28, 2022
    risk 0.64cvss 9.9epss 0.01

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely execute arbitrary commands on…

  • CVE-2022-36990CriJul 28, 2022
    risk 0.62cvss 9.6epss 0.01

    An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with authenticated access to a NetBackup Client could remotely write arbitrary files to…

  • CVE-2022-2010CriJul 28, 2022
    risk 0.61cvss 9.3epss 0.01

    Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2022-1853CriJul 27, 2022
    risk 0.62cvss 9.6epss 0.01

    Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2022-36956CriJul 27, 2022
    risk 0.59cvss 9.0epss 0.00

    In Veritas NetBackup, the NetBackup Client allows arbitrary command execution from any remote host that has access to a valid host-id NetBackup certificate/private key from the same domain. The affects 9.0.x through 9.0.0.1 and 9.1.x through 9.1.0.1.

  • CVE-2022-36954CriJul 27, 2022
    risk 0.64cvss 9.9epss 0.01

    In Veritas NetBackup OpsCenter, under specific conditions, an authenticated remote attacker may be able to create or modify OpsCenter user accounts. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.

  • CVE-2022-36951CriJul 27, 2022
    risk 0.64cvss 9.8epss 0.01

    In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may compromise the host by exploiting an incorrectly patched vulnerability. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.

  • CVE-2022-36950CriJul 27, 2022
    risk 0.64cvss 9.8epss 0.01

    In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may be able to perform remote command execution through a Java classloader manipulation. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.

  • CVE-2022-36949CriJul 27, 2022
    risk 0.60cvss 9.3epss 0.00

    In Veritas NetBackup OpsCenter, an attacker with local access to a NetBackup OpsCenter server could potentially escalate their privileges. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.

  • CVE-2022-24405CriJul 27, 2022
    risk 0.64cvss 9.8epss 0.03

    OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.

  • CVE-2022-23100CriJul 27, 2022
    risk 0.64cvss 9.8epss 0.03

    OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).