VYPR

CVEs

31,785 total · page 333 of 636

  • CVE-2022-29712CriJun 2, 2022
    risk 0.57cvss 9.8epss 0.02

    LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters.

  • CVE-2022-29659CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.02

    Responsive Online Blog v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at single.php.

  • CVE-2022-28945CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.

  • CVE-2022-28605CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.02

    Hardcoded admin token in SoundBar apps in Linkplay SDK 1.00 allows remote attackers to gain admin privilege access in linkplay antifactory

  • CVE-2022-25237CriJun 2, 2022
    risk 0.68cvss 9.8epss 0.56

    Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude pattern used in the RestAPIAuthorizationFilter. By appending ;i18ntranslation or /../i18ntranslation/ to the end of a URL, users with no privileges can access…

  • CVE-2022-24702CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.06

    An issue was discovered in WinAPRS 2.9.0. A buffer overflow in the VHF KISS TNC component allows a remote attacker to achieve remote code execution via malicious AX.25 packets over the air. NOTE: This vulnerability only affects products that are no longer supported by the…

  • CVE-2022-24240CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in showschedule.awp.

  • CVE-2022-24239CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp.

  • CVE-2022-1660CriJun 2, 2022
    risk 0.65cvss 9.8epss 0.16

    The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication, which may allow an attacker to remotely execute arbitrary code.

  • CVE-2021-44098CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.

  • CVE-2021-44097CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    EGavilan Media Contact-Form-With-Messages-Entry-Management 1.0 is vulnerable to SQL Injection via Addmessage.php. This allows a remote attacker to compromise Application SQL database.

  • CVE-2021-44096CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database.

  • CVE-2021-44095CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.02

    A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database.

  • CVE-2021-42872CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.07

    TOTOLINK EX1200T V4.1.2cu.5215 is affected by a command injection vulnerability that can remotely execute arbitrary code.

  • CVE-2021-34084CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.03

    OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function.

  • CVE-2021-34082CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.05

    OS Command Injection vulnerability in allenhwkim proctree through 0.1.1 and commit 0ac10ae575459457838f14e21d5996f2fa5c7593 for Node.js, allows attackers to execute arbitrary commands via the fix function.

  • CVE-2021-34080CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.03

    OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands via unsanitized shell metacharacters provided to the createCertRequest() and the createCert() functions.

  • CVE-2021-34079CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.04

    OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands via shell metacharacters in the 'ports' entry of a crafted docker-compose.yml file.

  • CVE-2021-26634CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromising Maxboard, which may lead to arbitrary code execution or privilege escalation. Attackers can use these vulnerabilities to…

  • CVE-2020-28246CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.02

    A Server-Side Template Injection (SSTI) was discovered in Form.io 2.0.0. This leads to Remote Code Execution during deletion of the default Email template URL. NOTE: the email templating service was removed after 2020. Additionally, the vendor disputes this issue indicating this…

  • CVE-2019-12351CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing comma.

  • CVE-2019-12350CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trailing comma.

  • CVE-2019-12349CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter.

  • CVE-2022-29875CriJun 1, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM…

  • CVE-2022-31013CriMay 31, 2022
    risk 0.59cvss 9.1epss 0.01

    Chat Server is the chat server for Vartalap, an open-source messaging application. Versions 2.3.2 until 2.6.0 suffer from a bug in validating the access token, resulting in authentication bypass. The function `this.authProvider.verifyAccessKey` is an async function, as the code…

  • CVE-2022-31003CriMay 31, 2022
    risk 0.00cvss 9.1epss 0.04

    Sofia-SIP is an open-source Session Initiation Protocol (SIP) User-Agent library. Prior to version 1.13.8, when parsing each line of a sdp message, `rest = record + 2` will access the memory behind `\0` and cause an out-of-bounds write. An attacker can send a message with evil…

  • CVE-2022-1556CriMay 30, 2022
    risk 0.65cvss 9.8epss 0.20

    The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection

  • CVE-2022-30584CriMay 26, 2022
    risk 0.62cvss 9.6epss 0.01

    Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentially be exploited by malicious users to compromise the affected system. 6.10 P3 (6.10.0.3) and 6.9 SP3 P4 (6.9.3.4) are also fixed…

  • CVE-2022-29633CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    An access control issue in Linglong v1.0 allows attackers to access the background of the application via a crafted cookie.

  • CVE-2022-29632CriMay 26, 2022
    risk 0.65cvss 9.8epss 0.17

    An arbitrary file upload vulnerability in the component /course/api/upload/pic of Roncoo Education v9.0.0 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2022-26776CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.02

    This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. An attacker may be able to cause unexpected application termination or arbitrary code execution.

  • CVE-2022-26775CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.02

    An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4. An attacker may be able to cause unexpected application termination or arbitrary code execution.

  • CVE-2022-26723CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. Mounting a maliciously crafted Samba network share may lead to arbitrary code execution.

  • CVE-2022-26711CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.04

    An integer overflow issue was addressed with improved input validation. This issue is fixed in tvOS 15.5, iTunes 12.12.4 for Windows, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4. A remote attacker may be able to cause unexpected application termination or…

  • CVE-2022-26708CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.02

    This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. An attacker may be able to cause unexpected application termination or arbitrary code execution.

  • CVE-2022-26694CriMay 26, 2022
    risk 0.59cvss 9.1epss 0.01

    This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. A plug-in may be able to inherit the application's permissions and access user data.

  • CVE-2022-26693CriMay 26, 2022
    risk 0.59cvss 9.1epss 0.01

    This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4. A plug-in may be able to inherit the application's permissions and access user data.

  • CVE-2022-30516CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.02

    In Hospital-Management-System v1.0, the editid parameter in the doctor.php page is vulnerable to SQL injection attacks.

  • CVE-2022-30495CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    In oretnom23 Automotive Shop Management System v1.0, the name id parameter is vulnerable to IDOR - Broken Access Control allowing attackers to change the admin password(vertical privilege escalation)

  • CVE-2022-30493CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.02

    In oretnom23 Automotive Shop Management System v1.0, the product id parameter suffers from a blind SQL Injection Vulnerability allowing remote attackers to dump all database credential and gain admin access(privilege escalation).

  • CVE-2022-21831CriMay 26, 2022
    risk 0.57cvss 9.8epss 0.03

    A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.

  • CVE-2022-1899CriMay 26, 2022
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0.

  • CVE-2021-33016CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    An attacker can gain full access (read/write/delete) to sensitive folders due to hard-coded credentials on KUKA KR C4 control software for versions prior to 8.7 or any product running KSS.

  • CVE-2022-30500CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Jfinal cms 5.1.0 is vulnerable to SQL Injection.

  • CVE-2022-30477CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/SetClientState request.

  • CVE-2022-30476CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a stack-based buffer overflow in the httpd module when handling /goform/SetFirewallCfg request.

  • CVE-2022-30474CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC Series Router AC18_V15.03.05.19(6318) was discovered to contain a heap overflow in the httpd module when handling /goform/saveParentControlInfo request.

  • CVE-2022-30472CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC Seris Router AC18_V15.03.05.19(6318) has a stack-based buffer overflow vulnerability in function fromAddressNat

  • CVE-2022-26857CriMay 26, 2022
    risk 0.59cvss 9.0epss 0.01

    Dell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass blocked functionalities and perform unauthorized actions.

  • CVE-2022-24422CriMay 26, 2022
    risk 0.67cvss 9.6epss 0.57

    Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to gain access to the VNC Console.