VYPR

CVEs

31,787 total · page 321 of 636

  • CVE-2022-2310CriJul 27, 2022
    risk 0.65cvss 10.0epss 0.01

    An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is…

  • CVE-2022-36129CriJul 26, 2022
    risk 0.59cvss 9.1epss 0.01

    HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the voter status of a node within a Vault HA cluster, introducing potential for future data loss or…

  • CVE-2022-30274CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded client. Credentials for accessing this gateway are stored after being encrypted with the Tiny Encryption Algorithm (TEA) in ECB…

  • CVE-2022-30271CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.

  • CVE-2022-30270CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote maintenance and for SFTP file-transfer operations that are part of engineering software functionality. Access to this interface is…

  • CVE-2022-31207CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication. They utilize the Omron FINS (9600/TCP) protocol for engineering purposes, including downloading projects and control logic to the PLC. This…

  • CVE-2022-31206CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authentication. These PLCs are programmed using the SYMAC Studio engineering software (which compiles IEC 61131-3 conformant POU code to native…

  • CVE-2022-30273CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.00

    The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption mode, traffic is encrypted via the Tiny Encryption Algorithm (TEA) block-cipher in ECB mode. This mode…

  • CVE-2022-29958CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.00

    JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protocol for engineering purposes, including downloading projects and control logic to the PLC. Control logic is downloaded to the PLC on a block-by-block basis with…

  • CVE-2022-29953CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality.

  • CVE-2022-29952CriJul 26, 2022
    risk 0.59cvss 9.1epss 0.01

    Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP, 60007/TCP) for communications between the monitoring controller and System 1 and/or Bently Nevada Monitor Configuration (BNMC)…

  • CVE-2022-29951CriJul 26, 2022
    risk 0.59cvss 9.1epss 0.01

    JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP or UDP) for a wide variety of engineering purposes such as starting and stopping the PLC, downloading and uploading projects, and…

  • CVE-2022-36412CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.06

    In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)

  • CVE-2022-36161CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

  • CVE-2022-34989CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Fruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_password_recover.php.

  • CVE-2022-34577CriJul 25, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2022-35131CriJul 25, 2022
    risk 0.52cvss 9.0epss 0.02

    Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.

  • CVE-2022-34907CriJul 25, 2022
    risk 0.65cvss 9.8epss 0.16

    An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform.

  • CVE-2022-35869CriJul 25, 2022
    risk 0.69cvss 9.8epss 0.60

    This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within…

  • CVE-2022-24083CriJul 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.

  • CVE-2022-35649CriJul 25, 2022
    risk 0.01cvss 9.8epss 0.08

    The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this…

  • CVE-2022-33965CriJul 25, 2022
    risk 0.61cvss 9.3epss 0.04

    Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.

  • CVE-2022-1312CriJul 25, 2022
    risk 0.62cvss 9.6epss 0.01

    Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

  • CVE-2022-1309CriJul 25, 2022
    risk 0.62cvss 9.6epss 0.01

    Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2022-0670CriJul 25, 2022
    risk 0.59cvss 9.1epss 0.01

    A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file system. The vulnerability is due to a bug in the "volumes" plugin in Ceph Manager. This allows an attacker to compromise…

  • CVE-2020-28447CriJul 25, 2022
    risk 0.64cvss 9.8epss 0.01

    This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)

  • CVE-2020-28446CriJul 25, 2022
    risk 0.57cvss 9.8epss 0.03

    The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.

  • CVE-2020-28445CriJul 25, 2022
    risk 0.64cvss 9.8epss 0.01

    This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function.

  • CVE-2020-28443CriJul 25, 2022
    risk 0.64cvss 9.8epss 0.01

    This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.

  • CVE-2020-28438CriJul 25, 2022
    risk 0.64cvss 9.8epss 0.01

    This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js

  • CVE-2020-28435CriJul 25, 2022
    risk 0.61cvss 9.4epss 0.01

    This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.

  • CVE-2022-36446CriJul 25, 2022
    risk 0.11cvss 9.8epss 0.96

    software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.

  • CVE-2022-34115CriJul 22, 2022
    risk 0.57cvss 9.8epss 0.01

    DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.

  • CVE-2022-34113CriJul 22, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.

  • CVE-2022-25759CriJul 22, 2022
    risk 0.58cvss 9.9epss 0.11

    The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.

  • CVE-2022-30998CriJul 22, 2022
    risk 0.59cvss 9.1epss 0.01

    Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in WooPlugins.co's Homepage Product Organizer for WooCommerce plugin <= 1.1 at WordPress.

  • CVE-2022-34983CriJul 22, 2022
    risk 0.64cvss 9.8epss 0.02

    The scu-captcha package in PyPI v0.0.1 to v0.0.4 included a code execution backdoor inserted by a third party.

  • CVE-2022-34982CriJul 22, 2022
    risk 0.64cvss 9.8epss 0.01

    The eziod package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.

  • CVE-2022-34981CriJul 22, 2022
    risk 0.64cvss 9.8epss 0.02

    The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.

  • CVE-2022-34509CriJul 22, 2022
    risk 0.64cvss 9.8epss 0.01

    The wikifaces package in PyPI v1.0 included a code execution backdoor inserted by a third party.

  • CVE-2022-34501CriJul 22, 2022
    risk 0.57cvss 9.8epss 0.01

    The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

  • CVE-2022-34500CriJul 22, 2022
    risk 0.57cvss 9.8epss 0.01

    The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

  • CVE-2022-2143CriJul 22, 2022
    risk 0.71cvss 9.8epss 0.59

    The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2022-0977CriJul 21, 2022
    risk 0.62cvss 9.6epss 0.01

    Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0973CriJul 21, 2022
    risk 0.62cvss 9.6epss 0.01

    Use after free in Safe Browsing in Google Chrome prior to 99.0.4844.74 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-34487CriJul 21, 2022
    risk 0.64cvss 9.8epss 0.03

    Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.

  • CVE-2022-33198CriJul 21, 2022
    risk 0.64cvss 9.8epss 0.03

    Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.

  • CVE-2022-28700CriJul 21, 2022
    risk 0.59cvss 9.1epss 0.02

    Authenticated Arbitrary File Creation via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.

  • CVE-2022-20861CriJul 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the…

  • CVE-2022-20858CriJul 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the…