VYPR

CVEs

31,785 total · page 328 of 636

  • CVE-2022-26147CriJun 21, 2022
    risk 0.64cvss 9.8epss 0.03

    The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.

  • CVE-2022-29775CriJun 21, 2022
    risk 0.68cvss 9.8epss 0.61

    iSpyConnect iSpy v7.2.2.0 allows attackers to bypass authentication via a crafted URL.

  • CVE-2022-29774CriJun 21, 2022
    risk 0.64cvss 9.8epss 0.06

    iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal.

  • CVE-2022-33139CriJun 21, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All versions in non-default configuration), SIMATIC WinCC OA…

  • CVE-2022-31374CriJun 21, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted php file.

  • CVE-2022-31801CriJun 21, 2022
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.

  • CVE-2022-31800CriJun 21, 2022
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.

  • CVE-2022-2128CriJun 20, 2022
    risk 0.00cvss 9.8epss 0.03

    Unrestricted Upload of File with Dangerous Type in GitHub repository polonel/trudesk prior to 1.2.4.

  • CVE-2022-22318CriJun 20, 2022
    risk 0.64cvss 9.8epss 0.00

    IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

  • CVE-2022-22317CriJun 20, 2022
    risk 0.64cvss 9.8epss 0.00

    IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.

  • CVE-2022-31795CriJun 20, 2022
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the grel_finfo function in grel.php. An attacker is able to influence the username (user), password (pw), and file-name (file) parameters and…

  • CVE-2022-31794CriJun 20, 2022
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered on Fujitsu ETERNUS CentricStor CS8000 (Control Center) devices before 8.1A SP02 P04. The vulnerability resides in the requestTempFile function in hw_view.php. An attacker is able to influence the unitName POST parameter and inject special characters such…

  • CVE-2022-25772CriJun 20, 2022
    risk 0.60cvss 9.6epss 0.61

    A cross-site scripting (XSS) vulnerability in the web tracking component of Mautic before 4.3.0 allows remote attackers to inject executable javascript

  • CVE-2022-1905CriJun 20, 2022
    risk 0.67cvss 9.8epss 0.37

    The Events Made Easy WordPress plugin before 2.2.81 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

  • CVE-2022-2023CriJun 20, 2022
    risk 0.00cvss 9.8epss 0.03

    Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.

  • CVE-2022-34005CriJun 19, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa account on the Microsoft SQL Express 2019 instance installed by default during TitanFTP NextGen installation, aka NX-I674 (sub-issue…

  • CVE-2022-31874CriJun 17, 2022
    risk 0.65cvss 9.8epss 0.19

    ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.

  • CVE-2022-31941CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via \rdms\admin?page=user\manage_user&id=.

  • CVE-2022-29496CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.02

    A stack-based buffer overflow vulnerability exists in the BlynkConsole.h runCommand functionality of Blynk -Library v1.0.1. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.

  • CVE-2022-21806CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.02

    A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to remote code execution. The device is exposed to attacks from the network.

  • CVE-2022-30422CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.04

    Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is vulnerable to Remote code execution via the Viewstate parameter.

  • CVE-2022-22485CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.01

    In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability…

  • CVE-2022-31357CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=.

  • CVE-2022-31356CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.

  • CVE-2022-31355CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=.

  • CVE-2021-40903CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.04

    A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.

  • CVE-2022-31784CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the management interface of MiVoice Business through 9.3 PR1 and MiVoice Business Express through 8.0 SP3 PR3 could allow an unauthenticated attacker (that has network access to the management interface) to conduct a buffer overflow attack due to insufficient…

  • CVE-2022-31296CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.02

    Online Discussion Forum Site 1 was discovered to contain a blind SQL injection vulnerability via the component /odfs/posts/view_post.php.

  • CVE-2021-45024CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.01

    ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).

  • CVE-2021-41408CriJun 17, 2022
    risk 0.64cvss 9.8epss 0.01

    VoIPmonitor WEB GUI up to version 24.61 is affected by SQL injection through the "api.php" file and "user" parameter.

  • CVE-2022-30329CriJun 16, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was found on TRENDnet TEW-831DR 1.0 601.130.1.1356 devices. An OS injection vulnerability exists within the web interface, allowing an attacker with valid credentials to execute arbitrary shell commands.

  • CVE-2022-33754CriJun 16, 2022
    risk 0.64cvss 9.8epss 0.02

    CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.

  • CVE-2022-33752CriJun 16, 2022
    risk 0.64cvss 9.8epss 0.02

    CA Automic Automation 12.2 and 12.3 contain an insufficient input validation vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary code.

  • CVE-2022-33750CriJun 16, 2022
    risk 0.64cvss 9.8epss 0.02

    CA Automic Automation 12.2 and 12.3 contain an authentication error vulnerability in the Automic agent that could allow a remote attacker to potentially execute arbitrary commands.

  • CVE-2022-24562CriJun 16, 2022
    risk 0.71cvss 9.8epss 0.53

    In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution.

  • CVE-2021-41487CriJun 16, 2022
    risk 0.64cvss 9.8epss 0.02

    NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.

  • CVE-2022-31384CriJun 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.

  • CVE-2022-31383CriJun 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in view-directory.php.

  • CVE-2022-31382CriJun 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter in search-dirctory.php.

  • CVE-2021-41654CriJun 16, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerabilities exist in Wuzhicms v4.1.0 which allows attackers to execute arbitrary SQL commands via the $keyValue parameter in /coreframe/app/pay/admin/index.php

  • CVE-2022-2098CriJun 16, 2022
    risk 0.00cvss 9.8epss 0.01

    Weak Password Requirements in GitHub repository kromitgmbh/titra prior to 0.78.1.

  • CVE-2021-41411CriJun 16, 2022
    risk 0.00cvss 9.8epss 0.01

    drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.

  • CVE-2022-30136CriJun 15, 2022
    risk 0.70cvss 9.8epss 0.78

    Windows Network File System Remote Code Execution Vulnerability

  • CVE-2021-41403CriJun 15, 2022
    risk 0.65cvss 9.8epss 0.18

    flatCore-CMS version 2.0.8 calls dangerous functions, causing server-side request forgery vulnerabilities.

  • CVE-2021-41418CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    AriaNg v0.1.0~v1.2.2 is affected by an incorrect access control vulnerability through not authenticating visitors' access rights.

  • CVE-2022-20825CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service…

  • CVE-2022-20798CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass authentication and…

  • CVE-2017-20049CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability, was found in legacy Axis devices such as P3225 and M3005. This affects an unknown part of the component CGI Script. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely.

  • CVE-2022-32301CriJun 15, 2022
    risk 0.64cvss 9.8epss 0.01

    YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the IdList parameter at /App/Lib/Action/Home/ApiAction.class.php.

  • CVE-2022-32158CriJun 15, 2022
    risk 0.59cvss 9.0epss 0.01

    Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use the vulnerability to execute…