VYPR

CVEs

31,787 total · page 323 of 636

  • CVE-2022-28373CriJul 14, 2022
    risk 0.64cvss 9.8epss 0.02

    Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crtcreadpartition function of the crtcrpc JSON listener in /usr/lib/lua/luci/crtc.lua. A remote attacker on the local network can inject shell metacharacters to…

  • CVE-2022-28369CriJul 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function's enable_ssh sub-operation of the crtcrpc JSON listener (found at /lib/functions/wnc_jsonsh/crtcmode.sh) A remote attacker on the local network can provide a…

  • CVE-2022-25801CriJul 14, 2022
    risk 0.59cvss 9.1epss 0.01

    Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.

  • CVE-2022-25800CriJul 14, 2022
    risk 0.59cvss 9.1epss 0.01

    Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.

  • CVE-2022-35857CriJul 13, 2022
    risk 0.64cvss 9.8epss 0.02

    kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. The rememberMe parameter is encrypted with a hardcoded key from the com.kalvin.kvf.common.shiro.ShiroConfig file.

  • CVE-2022-20238CriJul 13, 2022
    risk 0.64cvss 9.8epss 0.01

    'remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm_page_prot' can also be controlled by userspace, so userspace may map the kernel area to be writable, which is easy to be exploitedProduct: AndroidVersions:…

  • CVE-2022-20229CriJul 13, 2022
    risk 0.64cvss 9.8epss 0.03

    In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-20222CriJul 13, 2022
    risk 0.64cvss 9.8epss 0.01

    In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12…

  • CVE-2022-20216CriJul 13, 2022
    risk 0.64cvss 9.8epss 0.01

    android exported is used to set third-party app access permissions, and the default value of intent-filter is true. com.sprd.firewall has set exported as true.Product: AndroidVersions: Android SoCAndroid ID: A-231911916

  • CVE-2022-28888CriJul 13, 2022
    risk 0.64cvss 9.8epss 0.04

    Spryker Commerce OS 1.4.2 allows Remote Command Execution.

  • CVE-2022-32073CriJul 13, 2022
    risk 0.00cvss 9.8epss 0.02

    WolfSSH v1.4.7 was discovered to contain an integer overflow via the function wolfSSH_SFTP_RecvRMDIR.

  • CVE-2022-35628CriJul 12, 2022
    risk 0.66cvss 9.8epss 0.26

    A SQL injection issue was discovered in the lux extension before 17.6.1, and 18.x through 24.x before 24.0.2, for TYPO3.

  • CVE-2022-29601CriJul 12, 2022
    risk 0.64cvss 9.8epss 0.01

    The seminars (aka Seminar Manager) extension through 4.1.3 for TYPO3 allows SQL Injection.

  • CVE-2022-29600CriJul 12, 2022
    risk 0.64cvss 9.8epss 0.01

    The oelib (aka One is Enough Library) extension through 4.1.5 for TYPO3 allows SQL Injection.

  • CVE-2022-1737CriJul 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Pyramid Solutions' affected products, the Developer and DLL kits for EtherNet/IP Adapter and EtherNet/IP Scanner, are vulnerable to an out-of-bounds write, which may allow an unauthorized attacker to send a specially crafted packet that may result in a denial-of-service…

  • CVE-2022-34737CriJul 12, 2022
    risk 0.59cvss 9.1epss 0.01

    The application security module has a vulnerability in permission assignment. Successful exploitation of this vulnerability may affect data integrity and confidentiality.

  • CVE-2022-34819CriJul 12, 2022
    risk 0.65cvss 10.0epss 0.02

    A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 LTE EU (All versions < V3.3.46), SIMATIC CP 1243-7 LTE US (All versions < V3.3.46), SIMATIC CP 1243-8 IRC (All versions < V3.3.46),…

  • CVE-2022-26649CriJul 12, 2022
    risk 0.62cvss 9.6epss 0.01

    A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT (All versions < V5.5.2), SCALANCE X201-3P IRT PRO (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE X202-2IRT (All versions < V5.5.2), SCALANCE…

  • CVE-2021-44222CriJul 12, 2022
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service of affected systems does not perform authentication in the default configuration. This could allow an unauthenticated remote attacker to send arbitrary messages…

  • CVE-2020-35169CriJul 11, 2022
    risk 0.59cvss 9.1epss 0.01

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Improper Input Validation Vulnerability.

  • CVE-2020-4150CriJul 11, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174142.

  • CVE-2022-1952CriJul 11, 2022
    risk 0.65cvss 9.8epss 0.23

    The Free Booking Plugin for Hotels, Restaurant and Car Rental WordPress plugin before 1.1.16 suffers from insufficient input validation which leads to arbitrary file upload and subsequently to remote code execution. An AJAX action accessible to unauthenticated users is affected…

  • CVE-2022-1057CriJul 11, 2022
    risk 0.64cvss 9.8epss 0.08

    The Pricing Deals for WooCommerce WordPress plugin through 2.0.2.02 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection

  • CVE-2022-2302CriJul 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Multiple Lenze products of the cabinet series skip the password verification upon second login. After a user has been logged on to the device once, a remote attacker can get full access without knowledge of the password.

  • CVE-2022-32294CriJul 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Zimbra Collaboration Open Source 8.8.15 does not encrypt the initial-login randomly created password (from the "zmprove ca" command). It is visible in cleartext on port UDP 514 (aka the syslog port). NOTE: a third party reports that this cannot be reproduced.

  • CVE-2022-31588CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31587CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The yuriyouzhou/KG-fashion-chatbot repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31586CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The unizar-30226-2019-06/ChangePop-Back repository through 2019-06-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31585CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The umeshpatil-dev/Home__internet repository through 2020-08-28 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31584CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The stonethree/s3label repository through 2019-08-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31583CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The sravaniboinepelli/AutomatedQuizEval repository through 2020-04-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31582CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The shaolo1/VideoServer repository through 2019-09-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31581CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The scorelab/OpenMF repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31580CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31579CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31577CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The longmaoteamtf/audio_aligner_app repository through 2020-01-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31576CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The heidi-luong1109/shackerpanel repository through 2021-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31575CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The duducosmos/livro_python repository through 2018-06-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31574CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31573CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The chainer/chainerrl-visualizer repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31572CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The ceee-vip/cockybook repository through 2015-04-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31571CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31570CriJul 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The adriankoczuruek/ceneo-web-scrapper repository through 2021-03-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31568CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The Rexians/rex-web repository through 2022-06-05 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31567CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31565CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The yogson/syrabond repository through 2020-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31564CriJul 11, 2022
    risk 0.00cvss 9.3epss 0.01

    The woduq1414/munhak-moa repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31563CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The whmacmac/vprj repository through 2022-04-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31562CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31561CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The varijkapil13/Sphere_ImageBackend repository through 2019-10-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.