VYPR

CVEs

31,787 total · page 322 of 636

  • CVE-2022-20857CriJul 21, 2022
    risk 0.64cvss 9.8epss 0.02

    Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilities, see the…

  • CVE-2022-26138CriKEVJul 20, 2022
    risk 0.84cvss 9.8epss 0.98

    The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded…

  • CVE-2022-26136CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.05

    A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used by first and third party apps. The impact depends on which filters are used by each app, and how the filters are used. This vulnerability can result in…

  • CVE-2022-34045CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.03

    Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configuration files at /etc_ro/lighttpd/www/cgi-bin/ExportAllSettings.sh.

  • CVE-2022-33318CriJul 20, 2022
    risk 0.67cvss 9.8epss 0.45

    Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric Iconics…

  • CVE-2022-2141CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication.

  • CVE-2022-2107CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master password. This may allow an attacker to send SMS commands directly to the GPS tracker as if they were coming from the GPS owner’s mobile number.

  • CVE-2022-34610CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the URL /ihomers/app.

  • CVE-2022-34609CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the INTF parameter at /doping.asp.

  • CVE-2022-34608CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the ajaxmsg parameter at /AJAX/ajaxget.

  • CVE-2022-34607CriJul 20, 2022
    risk 0.65cvss 9.8epss 0.13

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /doping.asp.

  • CVE-2022-34606CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditvsList parameter at /dotrace.asp.

  • CVE-2022-34605CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the HOST parameter at /dotrace.asp.

  • CVE-2022-34604CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the INTF parameter at /dotrace.asp.

  • CVE-2022-34603CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the DelDNSHnList interface at /goform/aspForm.

  • CVE-2022-34602CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the ipqos_lanip_editlist interface at /goform/aspForm.

  • CVE-2022-34601CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the Delstlist interface at /goform/aspForm.

  • CVE-2022-34600CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditSTList interface at /goform/aspForm.

  • CVE-2022-34599CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EdittriggerList interface at /goform/aspForm.

  • CVE-2022-24657CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Goldshell ASIC Miners v2.1.x was discovered to contain hardcoded credentials which allow attackers to remotely connect via the SSH protocol (port 22).

  • CVE-2022-32456CriJul 20, 2022
    risk 0.64cvss 9.8epss 0.02

    Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt service.

  • CVE-2016-1000273criJul 20, 2022
    risk 0.52cvss epss 0.02

    JavaMelody is a monitoring tool for JavaEE applications. Versions prior to 1.61.0 are vulnerable to a cross-site scripting (XSS) attack. This issue was patched in version 1.61.0, and users are recommended to upgrade to the latest version. There are no known workarounds.

  • CVE-2022-21543CriJul 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mgmt). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2022-34023CriJul 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /officials/officials.php.

  • CVE-2022-35912CriJul 19, 2022
    risk 0.64cvss 9.8epss 0.02

    In grails-databinding in Grails before 3.3.15, 4.x before 4.1.1, 5.x before 5.1.9, and 5.2.x before 5.2.1 (at least when certain Java 8 configurations are used), data binding allows a remote attacker to execute code by gaining access to the class loader.

  • CVE-2022-35405CriKEVJul 19, 2022
    risk 0.87cvss 9.8epss 1.00

    Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)

  • CVE-2022-24082CriJul 19, 2022
    risk 0.67cvss 9.8epss 0.12

    If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect…

  • CVE-2022-34635CriJul 18, 2022
    risk 0.64cvss 9.8epss 0.01

    The mstatus.sd field in CVA6 commit d315ddd0f1be27c1b3f27eb0b8daf471a952299a does not update when the mstatus.fs field is set to Dirty.

  • CVE-2022-34632CriJul 18, 2022
    risk 0.00cvss 9.1epss 0.01

    Rocket-Chip commit 4f8114374d8824dfdec03f576a8cd68bebce4e56 was discovered to contain insufficient cryptography via the component /rocket/RocketCore.scala.

  • CVE-2022-34029CriJul 18, 2022
    risk 0.59cvss 9.1epss 0.01

    Nginx NJS v0.7.4 was discovered to contain an out-of-bounds read via njs_scope_value at njs_scope.h.

  • CVE-2015-8031CriJul 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Hudson (aka org.jvnet.hudson.main:hudson-core) before 3.3.2 allows XXE attacks.

  • CVE-2022-2437CriJul 18, 2022
    risk 0.57cvss 9.8epss 0.02

    The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possible for unauthenticated attackers to call files using a…

  • CVE-2022-35741CriJul 18, 2022
    risk 0.64cvss 9.8epss 0.08

    Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin is not enabled by default and the attacker would require that this plugin be enabled to exploit the…

  • CVE-2022-27434CriJul 18, 2022
    risk 0.64cvss 9.8epss 0.01

    UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the errorReporting page.

  • CVE-2021-41419CriJul 18, 2022
    risk 0.64cvss 9.8epss 0.09

    QVIS NVR DVR before 2021-12-13 is vulnerable to Remote Code Execution via Java deserialization.

  • CVE-2021-40874CriJul 18, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (for another LemonLDAP::NG instance, for example) and using the Kerberos authentication method combined with another method with…

  • CVE-2022-32985CriJul 17, 2022
    risk 0.64cvss 9.8epss 0.01

    libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on port 50200 or 50201.

  • CVE-2022-31211CriJul 17, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Infiray IRAY-A8Z3 1.0.957. There is a blank root password for TELNET by default.

  • CVE-2022-31210CriJul 17, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The binary file /usr/local/sbin/webproject/set_param.cgi contains hardcoded credentials to the web application. Because these accounts cannot be deactivated or have their passwords changed, they are considered to be backdoor…

  • CVE-2022-31209CriJul 17, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The firmware contains a potential buffer overflow by calling strcpy() without checking the string length beforehand.

  • CVE-2022-26479CriJul 17, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authentication.

  • CVE-2022-26352CriKEVJul 17, 2022
    risk 0.92cvss 9.8epss 0.92

    An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage…

  • CVE-2021-36711CriJul 16, 2022
    risk 0.61cvss 9.8epss 0.15

    WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.

  • CVE-2022-35890CriJul 15, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client Session IDs are mishandled. An attacker can determine which session IDs were generated in the past and then hijack sessions assigned to these IDs via Randy.

  • CVE-2022-31161CriJul 15, 2022
    risk 0.63cvss 10.0epss 0.27

    Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Version 6.1.1.0…

  • CVE-2022-35409CriJul 15, 2022
    risk 0.52cvss 9.1epss 0.02

    An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This can cause a server crash or…

  • CVE-2022-32417CriJul 14, 2022
    risk 0.66cvss 9.8epss 0.33

    PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.

  • CVE-2022-32409CriJul 14, 2022
    risk 0.64cvss 9.8epss 0.13

    A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.

  • CVE-2022-30113CriJul 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Electronic mall system 1.0_build20200203 is affected vulnerable to SQL Injection.

  • CVE-2022-28375CriJul 14, 2022
    risk 0.64cvss 9.8epss 0.02

    Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the crtcswitchsimprofile function of the crtcrpc JSON listener. A remote attacker on the local network can inject shell metacharacters into…