VYPR

CVEs

31,785 total · page 330 of 636

  • CVE-2022-30308CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.03

    In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control…

  • CVE-2022-1768CriJun 13, 2022
    risk 0.65cvss 9.8epss 0.12

    The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to…

  • CVE-2022-2067CriJun 13, 2022
    risk 0.52cvss 9.1epss 0.02

    SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0.

  • CVE-2022-0885CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.09

    The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.

  • CVE-2022-0827CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.09

    The Bestbooks WordPress plugin through 2.6.3 does not sanitise and escape some parameters before using them in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

  • CVE-2022-0786CriJun 13, 2022
    risk 0.65cvss 9.8epss 0.13

    The KiviCare WordPress plugin before 2.3.9 does not sanitise and escape some parameters before using them in SQL statements via the ajax_post AJAX action with the get_doctor_details route, leading to SQL Injections exploitable by unauthenticated users

  • CVE-2021-37404CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.03

    There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitrary code execution. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

  • CVE-2022-29525CriJun 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a remote unauthenticated attacker to log in with the root privilege and perform an arbitrary operation.

  • CVE-2021-41749CriJun 12, 2022
    risk 0.58cvss 9.8epss 0.17

    In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution.

  • CVE-2017-20039CriJun 11, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been classified as very critical. This affects an unknown part. The manipulation leads to weak authentication. It is possible to initiate the attack remotely.

  • CVE-2021-41756CriJun 10, 2022
    risk 0.64cvss 9.8epss 0.01

    dynamicMarkt <= 3.10 is affected by SQL injection in the kat parameter of index.php.

  • CVE-2021-41755CriJun 10, 2022
    risk 0.64cvss 9.8epss 0.01

    dynamicMarkt <= 3.10 is affected by SQL injection in the kat1 parameter of index.php.

  • CVE-2021-41754CriJun 10, 2022
    risk 0.64cvss 9.8epss 0.01

    dynamicMarkt <= 3.10 is affected by SQL injection in the parent parameter of index.php.

  • CVE-2022-31788CriJun 10, 2022
    risk 0.65cvss 9.8epss 0.14

    IdeaLMS 2022 allows SQL injection via the IdeaLMS/ChatRoom/ClassAccessControl/6?isBigBlueButton=0&ClassID= pathname.

  • CVE-2022-32563CriJun 10, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentication from Sync Gateway to Couchbase Server. When Sync Gateway is configured to authenticate with Couchbase Server using X.509…

  • CVE-2022-29226CriJun 9, 2022
    risk 0.00cvss 10.0epss 0.01

    Envoy is a cloud-native high-performance proxy. In versions prior to 1.22.1 the OAuth filter implementation does not include a mechanism for validating access tokens, so by design when the HMAC signed cookie is missing a full authentication flow should be triggered. However, the…

  • CVE-2022-31813CriJun 9, 2022
    risk 0.64cvss 9.8epss 0.03

    Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.

  • CVE-2022-28615CriJun 9, 2022
    risk 0.60cvss 9.1epss 0.06

    Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua…

  • CVE-2022-25152CriJun 9, 2022
    risk 0.64cvss 9.9epss 0.02

    The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures. It is possible to require a mandatory approval process. Due to a vulnerability in the approval process, present in any version prior to 6.35.37347.20040, a…

  • CVE-2022-1992CriJun 9, 2022
    risk 0.52cvss 9.1epss 0.02

    Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.

  • CVE-2022-1986CriJun 9, 2022
    risk 0.57cvss 9.8epss 0.04

    OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.

  • CVE-2022-31031CriJun 9, 2022
    risk 0.00cvss 9.8epss 0.02

    PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions prior to and including 2.12.1 a stack buffer overflow vulnerability affects PJSIP users that use…

  • CVE-2022-32272CriJun 9, 2022
    risk 0.67cvss 9.8epss 0.09

    OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP before 4.12.1, and MetaDefender Email Gateway Security before 5.6.1 have incorrect access control, resulting in privilege escalation.

  • CVE-2022-31830CriJun 9, 2022
    risk 0.60cvss 9.1epss 0.15

    Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php.

  • CVE-2022-31827CriJun 9, 2022
    risk 0.61cvss 9.1epss 0.20

    MonstaFTP v2.10.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the function performFetchRequest at HTTPFetcher.php.

  • CVE-2022-31393CriJun 9, 2022
    risk 0.59cvss 9.1epss 0.01

    Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in app/admin/c/PluginsController.php.

  • CVE-2022-31390CriJun 9, 2022
    risk 0.59cvss 9.1epss 0.01

    Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in app/admin/c/TemplateController.php.

  • CVE-2022-31386CriJun 9, 2022
    risk 0.59cvss 9.1epss 0.01

    A Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the URL parameter.

  • CVE-2022-24840CriJun 9, 2022
    risk 0.52cvss 9.1epss 0.02

    django-s3file is a lightweight file upload input for Django and Amazon S3 . In versions prior to 5.5.1 it was possible to traverse the entire AWS S3 bucket and in most cases to access or delete files. If the `AWS_LOCATION` setting was set, traversal was limited to that location…

  • CVE-2022-29013CriJun 9, 2022
    risk 0.70cvss 9.8epss 0.77

    A command injection in the command parameter of Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to execute arbitrary commands via a crafted POST request.

  • CVE-2022-31313CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    api-res-py package in PyPI 0.1 is vulnerable to a code execution backdoor in the request package.

  • CVE-2022-30882CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    pyanxdns package in PyPI version 0.2 is vulnerable to code execution backdoor. The impact is: execute arbitrary code (remote). When installing the pyanxdns package of version 0.2, the request package will be installed.

  • CVE-2022-30877CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.

  • CVE-2021-40589CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.01

    ZAngband zangband-data 2.7.5 is affected by an integer underflow vulnerability in src/tk/plat.c through the variable fileheader.bfOffBits.

  • CVE-2022-30926CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the EditMacList parameter at /goform/aspForm.

  • CVE-2022-30925CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the AddMacList parameter at /goform/aspForm.

  • CVE-2022-30924CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the SetAPWifiorLedInfoById parameter at /goform/aspForm.

  • CVE-2022-30923CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Asp_SetTimingtimeWifiAndLed parameter at /goform/aspForm.

  • CVE-2022-30922CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the EditWlanMacList parameter at /goform/aspForm.

  • CVE-2022-30921CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the SetMobileAPInfoById parameter at /goform/aspForm.

  • CVE-2022-30920CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Edit_BasicSSID parameter at /goform/aspForm.

  • CVE-2022-30919CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Edit_BasicSSID_5G parameter at /goform/aspForm.

  • CVE-2022-30918CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Asp_SetTelnet parameter at /goform/aspForm.

  • CVE-2022-30917CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the AddWlanMacList parameter at /goform/aspForm.

  • CVE-2022-30916CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the Asp_SetTelnetDebug parameter at /goform/aspForm.

  • CVE-2022-30915CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the UpdateSnat parameter at /goform/aspForm.

  • CVE-2022-30914CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the UpdateMacClone parameter at /goform/aspForm.

  • CVE-2022-30913CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the ipqos_set_bandwidth parameter at /goform/aspForm.

  • CVE-2022-30912CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the UpdateWanParams parameter at /goform/aspForm.

  • CVE-2022-30910CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the GO parameter at /goform/aspForm.