VYPR

CVEs

31,785 total · page 334 of 636

  • CVE-2022-29660CriMay 26, 2022
    risk 0.65cvss 9.8epss 0.12

    CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del.

  • CVE-2022-1664CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.03

    Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the…

  • CVE-2022-26833CriMay 25, 2022
    risk 0.64cvss 9.4epss 0.37

    An improper authentication vulnerability exists in the REST API functionality of Open Automation Software OAS Platform V16.00.0121. A specially-crafted series of HTTP requests can lead to unauthenticated use of the REST API. An attacker can send a series of HTTP requests to…

  • CVE-2022-26082CriMay 25, 2022
    risk 0.61cvss 9.1epss 0.20

    A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger…

  • CVE-2021-27779CriMay 25, 2022
    risk 0.59cvss 9.1epss 0.01

    VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on communications with the server.

  • CVE-2022-23775CriMay 25, 2022
    risk 0.64cvss 9.8epss 0.01

    TrueStack Direct Connect 1.4.7 has Incorrect Access Control.

  • CVE-2021-32989CriMay 25, 2022
    risk 0.61cvss 9.3epss 0.02

    When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns error messages which may allow reflected cross-site scripting.

  • CVE-2022-29650CriMay 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php.

  • CVE-2022-29379CriMay 25, 2022
    risk 0.00cvss 9.8epss 0.02

    Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not part of the 0.7.2,…

  • CVE-2022-30595CriMay 25, 2022
    risk 0.57cvss 9.8epss 0.02

    libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.

  • CVE-2022-28862CriMay 25, 2022
    risk 0.64cvss 9.8epss 0.01

    In Archibus Web Central before 26.2, multiple SQL Injection vulnerabilities occur in dwr/call/plaincall/workflow.runWorkflowRule.dwr. Through the injection of arbitrary SQL statements, a potential attacker can modify query syntax and perform unauthorized (and unexpected)…

  • CVE-2022-26945CriMay 25, 2022
    risk 0.57cvss 9.8epss 0.02

    go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.

  • CVE-2022-29361CriMay 25, 2022
    risk 0.01cvss 9.8epss 0.08

    Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body. NOTE: the vendor's position is that this behavior can only occur in unsupported…

  • CVE-2022-29337CriMay 24, 2022
    risk 0.67cvss 9.8epss 0.36

    C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerability allows attackers to execute arbitrary commands via a crafted HTTP request.

  • CVE-2022-29334CriMay 24, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue in H v1.0 allows attackers to bypass authentication via a session replay attack.

  • CVE-2020-4926CriMay 24, 2022
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191600.

  • CVE-2022-30838CriMay 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Covid-19 Travel Pass Management System v1.0 is vulnerable to SQL Injection via /ctpms/classes/Master.php?f=update_application_status

  • CVE-2022-29246CriMay 24, 2022
    risk 0.64cvss 9.8epss 0.02

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. Prior to version 6.1.11, he USBX DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memory contents. In particular cases this may allow an attacker to bypass…

  • CVE-2021-45915CriMay 24, 2022
    risk 0.64cvss 9.8epss 0.02

    In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a cookie value. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.

  • CVE-2021-45914CriMay 24, 2022
    risk 0.64cvss 9.8epss 0.02

    In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request. This allows the attacker's session to be authenticated as any registered LuxCal user, including the site administrator.

  • CVE-2022-30461CriMay 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Water-billing-management-system v1.0 is vulnerable to SQL Injection via /wbms/classes/Master.php?f=delete_client, id

  • CVE-2022-30455CriMay 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Badminton Center Management System 1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_court_rental, id.

  • CVE-2022-30454CriMay 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Merchandise Online Store 1.0 is vulnerable to SQL Injection via /vloggers_merch/classes/Master.php?f=delete_product.

  • CVE-2021-42654CriMay 24, 2022
    risk 0.64cvss 9.8epss 0.02

    SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.

  • CVE-2021-32941CriMay 23, 2022
    risk 0.62cvss 9.4epss 0.14

    Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow, which allows an unauthorized remote attacker to execute arbitrary code with the same privileges as the server user (root).

  • CVE-2022-28932CriMay 23, 2022
    risk 0.64cvss 9.8epss 0.02

    D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions.

  • CVE-2022-29599CriMay 23, 2022
    risk 0.57cvss 9.8epss 0.04

    In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks.

  • CVE-2022-1014CriMay 23, 2022
    risk 0.64cvss 9.8epss 0.02

    The WP Contacts Manager WordPress plugin through 2.2.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to an SQL injection vulnerability.

  • CVE-2022-0781CriMay 23, 2022
    risk 0.65cvss 9.8epss 0.13

    The Nirweb support WordPress plugin before 2.8.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action (available to unauthenticated users), leading to an SQL injection

  • CVE-2022-1813CriMay 22, 2022
    risk 0.00cvss 9.8epss 0.03

    OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.

  • CVE-2022-31267CriMay 21, 2022
    risk 0.58cvss 9.8epss 0.18

    Gitblit 1.9.2 allows privilege escalation via the Config User Service: a control character can be placed in a profile data field, such as an emailAddress%3Atext 'attacker@example.com\n\trole = "#admin"' value.

  • CVE-2022-31259CriMay 21, 2022
    risk 0.58cvss 9.8epss 0.22

    The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /p1/p2/:name route is configured, attackers can access it by appending .xml in various places (e.g., p1.xml instead of p1).

  • CVE-2022-1775CriMay 20, 2022
    risk 0.00cvss 9.8epss 0.02

    Weak Password Requirements in GitHub repository polonel/trudesk prior to 1.2.2.

  • CVE-2022-29186CriMay 20, 2022
    risk 0.00cvss 9.1epss 0.01

    Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Rundeck community and rundeck-enterprise docker images contained a pre-generated SSH keypair. If the id_rsa.pub public key of the keypair was copied to authorized_keys files on…

  • CVE-2022-28618CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has…

  • CVE-2022-22972CriMay 20, 2022
    risk 0.68cvss 9.8epss 0.56

    VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

  • CVE-2022-28995CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.02

    Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function.

  • CVE-2022-28531CriMay 20, 2022
    risk 0.65cvss 9.8epss 0.14

    Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field.

  • CVE-2022-29165CriMay 20, 2022
    risk 0.58cvss 10.0epss 0.02

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered in Argo CD starting with version 1.4.0 and prior to versions 2.1.15, 2.2.9, and 2.3.4 which would allow unauthenticated users to impersonate as any Argo CD user…

  • CVE-2022-28660CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.01

    The querier component in Grafana Enterprise Logs 1.1.x through 1.3.x before 1.4.0 does not require authentication when X-Scope-OrgID is used. Versions 1.2.1, 1.3.1, and 1.4.0 contain the bugfix. This affects -auth.type=enterprise in microservices mode

  • CVE-2022-30887CriMay 20, 2022
    risk 0.66cvss 9.8epss 0.26

    Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.

  • CVE-2022-30886CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.02

    School Dormitory Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /dms/admin/reports/daily_collection_report.php.

  • CVE-2022-30518CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.02

    ChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /simple_chat_bot/admin/responses/view_response.php.

  • CVE-2022-29873CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been identified in SICAM T (All versions < V3.0). Affected devices do not properly validate parameters of certain GET and POST requests. This could allow an unauthenticated attacker to set the device to a denial of service state or to control the program…

  • CVE-2022-29023CriMay 20, 2022
    risk 0.00cvss 9.8epss 0.02

    A buffer overflow vulnerability exists in the razermouse driver of OpenRazer up to version v3.3.0 allows attackers to cause a Denial of Service (DoS) and possibly escalate their privileges via a crafted buffer sent to the matrix_custom_frame device.

  • CVE-2022-29022CriMay 20, 2022
    risk 0.00cvss 9.8epss 0.02

    A buffer overflow vulnerability exists in the razeraccessory driver of OpenRazer up to version v3.3.0 allows attackers to cause a Denial of Service (DoS) and possibly escalate their privileges via a crafted buffer sent to the matrix_custom_frame device.

  • CVE-2022-29021CriMay 20, 2022
    risk 0.00cvss 9.8epss 0.02

    A buffer overflow vulnerability exists in the razerkbd driver of OpenRazer up to version v3.3.0 allows attackers to cause a Denial of Service (DoS) and possibly escalate their privileges via a crafted buffer sent to the matrix_custom_frame device.

  • CVE-2022-28993CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.02

    Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.

  • CVE-2022-28106CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Sports Complex Booking System v1.0 was discovered to allow attackers to take over user accounts via a crafted POST request.

  • CVE-2022-28105CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Sports Complex Booking System v1.0 was discovered to contain a blind SQL injection vulnerability via the id parameter in /scbs/view_facility.php.