VYPR

CVEs

31,787 total · page 325 of 636

  • CVE-2022-31510CriJul 11, 2022
    risk 0.00cvss 9.3epss 0.01

    The sergeKashkin/Simple-RAT repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31509CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The iedadata/usap-dc-website repository through 1.0.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31508CriJul 11, 2022
    risk 0.00cvss 9.3epss 0.01

    The idayrus/evoting repository before 2022-05-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31507CriJul 11, 2022
    risk 0.54cvss 9.3epss 0.02

    The ganga-devs/ganga repository before 8.5.10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31506CriJul 11, 2022
    risk 0.54cvss 9.3epss 0.01

    The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31505CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The cheo0/MercadoEnLineaBack repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31504CriJul 11, 2022
    risk 0.00cvss 9.3epss 0.01

    The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31503CriJul 11, 2022
    risk 0.00cvss 9.3epss 0.02

    The orchest/orchest repository before 2022.05.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31502CriJul 11, 2022
    risk 0.00cvss 9.3epss 0.01

    The operatorequals/wormnest repository through 0.4.7 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31501CriJul 11, 2022
    risk 0.00cvss 9.3epss 0.01

    The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31137CriJul 8, 2022
    risk 0.10cvss 10.0epss 0.90

    Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocess_execute function without processing the inputs received…

  • CVE-2022-35411CriJul 8, 2022
    risk 0.63cvss 9.8epss 0.46

    rpc.py through 0.6.0 allows Remote Code Execution because an unpickle occurs when the "serializer: pickle" HTTP header is sent. In other words, although JSON (not Pickle) is the default data format, an unauthenticated client can cause the data to be processed with unpickle.

  • CVE-2022-34914CriJul 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is associated with a variable in the configuration page. The {clientIp} variable can be used as an application startup argument. The X-Forwarded-For header can be manipulated by a client to…

  • CVE-2022-28623CriJul 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL…

  • CVE-2021-41037CriJul 8, 2022
    risk 0.65cvss 10.0epss 0.01

    In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation. Those touchpoints can, for example, alter the command-line used to start the application, injecting things like agent or other settings…

  • CVE-2022-1245CriJul 8, 2022
    risk 0.57cvss 9.8epss 0.01

    A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain…

  • CVE-2021-35283CriJul 7, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via the Name, Fname, and ID parameters to search.php.

  • CVE-2021-29281CriJul 7, 2022
    risk 0.64cvss 9.8epss 0.02

    File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317.

  • CVE-2022-34592CriJul 7, 2022
    risk 0.64cvss 9.8epss 0.03

    Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obtw. This vulnerability allows attackers to execute arbitrary commands via a crafted POST request.

  • CVE-2022-32449CriJul 7, 2022
    risk 0.65cvss 9.8epss 0.18

    TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function. This vulnerability is exploitable via a crafted MQTT data packet.

  • CVE-2022-32056CriJul 7, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Accreditation Management v1.0 was discovered to contain a SQL injection vulnerability via the USERNAME parameter at process.php.

  • CVE-2022-32054CriJul 7, 2022
    risk 0.66cvss 9.8epss 0.32

    Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter.

  • CVE-2021-46825CriJul 7, 2022
    risk 0.59cvss 9.1epss 0.02

    Symantec Advanced Secure Gateway (ASG) and ProxySG are susceptible to an HTTP desync vulnerability. When a remote unauthenticated attacker and other web clients communicate through the proxy with the same web server, the attacker can send crafted HTTP requests and cause the…

  • CVE-2022-32207CriJul 7, 2022
    risk 0.64cvss 9.8epss 0.07

    When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the…

  • CVE-2022-25046CriJul 7, 2022
    risk 0.67cvss 9.8epss 0.54

    A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2022-20813CriJul 6, 2022
    risk 0.59cvss 9.0epss 0.01

    Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected…

  • CVE-2022-20812CriJul 6, 2022
    risk 0.59cvss 9.0epss 0.02

    Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files or conduct null byte poisoning attacks on an affected…

  • CVE-2014-8164CriJul 6, 2022
    risk 0.59cvss 9.1epss 0.01

    A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x.

  • CVE-2022-33047CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.01

    OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.

  • CVE-2022-31126CriJul 6, 2022
    risk 0.64cvss 10.0epss 0.50

    Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi…

  • CVE-2022-31125CriJul 6, 2022
    risk 0.62cvss 10.0epss 0.20

    Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially crafted HTTP request. This…

  • CVE-2022-34598CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.07

    The udpserver in H3C Magic R100 V200R004 and V100R005 has the 9034 port opened, allowing attackers to execute arbitrary commands.

  • CVE-2022-34597CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting.

  • CVE-2022-34596CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSetting.

  • CVE-2022-34595CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function setipv6status.

  • CVE-2022-21744CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.03

    In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Packet Neighbour Cell Data (PNCD) improper neighbouring cell size with no additional execution privileges needed. User interaction…

  • CVE-2022-20083CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.03

    In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding combined FACILITY with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2022-33980CriJul 6, 2022
    risk 0.66cvss 9.8epss 0.43

    Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configuration2.interpol.Lookup…

  • CVE-2022-32386CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.10

    Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.

  • CVE-2022-32385CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote).

  • CVE-2022-32383CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the AdvSetMacMtuWan function.

  • CVE-2022-32533CriJul 6, 2022
    risk 0.64cvss 9.8epss 0.04

    Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dormant project of…

  • CVE-2022-34972CriJul 5, 2022
    risk 0.64cvss 9.8epss 0.01

    So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_value_id , opt_value_id , and subcate_value_id parameters at /index.php?route=extension/module/so_filter_shop_by/filter_data.

  • CVE-2022-32413CriJul 5, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2022-32311CriJul 5, 2022
    risk 0.64cvss 9.8epss 0.01

    Ingredient Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /isms/admin/stocks/view_stock.php.

  • CVE-2022-32310CriJul 5, 2022
    risk 0.64cvss 9.8epss 0.02

    An access control issue in Ingredient Stock Management System v1.0 allows attackers to take over user accounts via a crafted POST request to /isms/classes/Users.php.

  • CVE-2022-31856CriJul 5, 2022
    risk 0.64cvss 9.8epss 0.01

    Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php.

  • CVE-2022-2321CriJul 5, 2022
    risk 0.57cvss 9.8epss 0.01

    Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0. This results in login brute-force attacks.

  • CVE-2022-31836CriJul 5, 2022
    risk 0.57cvss 9.8epss 0.02

    The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk.

  • CVE-2021-43702CriJul 5, 2022
    risk 0.59cvss 9.0epss 0.01

    ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.