VYPR

CVEs

31,785 total · page 338 of 636

  • CVE-2022-1505CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers to steal…

  • CVE-2022-1453CriMay 10, 2022
    risk 0.57cvss 9.8epss 0.07

    The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive…

  • CVE-2022-23676CriMay 10, 2022
    risk 0.65cvss 9.8epss 0.22

    A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions;…

  • CVE-2022-0947CriMay 10, 2022
    risk 0.59cvss 9.0epss 0.01

    A vulnerability in ABB ARG600 Wireless Gateway series that could allow an attacker to exploit the vulnerability by remotely connecting to the serial port gateway, and/or protocol converter, depending on the configuration.

  • CVE-2022-29329CriMay 10, 2022
    risk 0.65cvss 9.8epss 0.13

    D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a heap overflow via the devicename parameter in /goform/setDeviceSettings.

  • CVE-2022-29328CriMay 10, 2022
    risk 0.65cvss 9.8epss 0.13

    D-Link DAP-1330_OSS-firmware_1.00b21 was discovered to contain a stack overflow via the function checkvalidupgrade.

  • CVE-2022-29327CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the urladd parameter in /goform/websURLFilterAddDel.

  • CVE-2022-29326CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addhostfilter parameter in /goform/websHostFilter.

  • CVE-2022-29325CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the addurlfilter parameter in /goform/websURLFilter.

  • CVE-2022-29324CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the proto parameter in /goform/form2IPQoSTcAdd.

  • CVE-2022-29323CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the MAC parameter in /goform/editassignment.

  • CVE-2022-29322CriMay 10, 2022
    risk 0.65cvss 9.8epss 0.16

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the IPADDR and nvmacaddr parameters in /goform/form2Dhcpip.

  • CVE-2022-29321CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a stack overflow via the lanip parameter in /goform/setNetworkLan.

  • CVE-2022-28915CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.07

    D-Link DIR-816 A2_v1.10CNB04 was discovered to contain a command injection vulnerability via the admuser and admpass parameters in /goform/setSysAdm.

  • CVE-2022-28913CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/setUploadSetting.

  • CVE-2022-28912CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/setUpgradeFW.

  • CVE-2022-28911CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the filename parameter in /setting/CloudACMunualUpdate.

  • CVE-2022-28910CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicename parameter in /setting/setDeviceName.

  • CVE-2022-28909CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the webwlanidx parameter in /setting/setWebWlanIdx.

  • CVE-2022-28908CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the ipdoamin parameter in /setting/setDiagnosisCfg.

  • CVE-2022-28907CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the hosttime function in /setting/NTPSyncWithHost.

  • CVE-2022-28906CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the langtype parameter in /setting/setLanguageCfg.

  • CVE-2022-28905CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOLink N600R V5.3c.7159_B20190425 was discovered to contain a command injection vulnerability via the devicemac parameter in /setting/setDeviceName.

  • CVE-2022-28901CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    A command injection vulnerability in the component /SetTriggerLEDBlink/Blink of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.

  • CVE-2022-28896CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    A command injection vulnerability in the component /setnetworksettings/SubnetMask of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.

  • CVE-2022-28895CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.04

    A command injection vulnerability in the component /setnetworksettings/IPAddress of D-Link DIR882 DIR882A1_FW130B06 allows attackers to escalate privileges to root via a crafted payload.

  • CVE-2022-29591CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda TX9 Pro 22.03.02.10 devices have a SetNetControlList buffer overflow.

  • CVE-2022-28110CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the login page.

  • CVE-2021-43094CriMay 10, 2022
    risk 0.64cvss 9.8epss 0.01

    An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via GET requests on arbitrary parameters in patient.page.

  • CVE-2021-42645CriMay 10, 2022
    risk 0.65cvss 10.0epss 0.04

    CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" parameter to upload a PHP payload to get a reverse shell from the vulnerable host.

  • CVE-2022-24042CriMay 10, 2022
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The web application returns an AuthToken that…

  • CVE-2022-24039CriMay 10, 2022
    risk 0.59cvss 9.0epss 0.02

    A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The “addCell” JavaScript function fails to properly sanitize user-controllable input before including it into the generated XML body of…

  • CVE-2021-42581CriMay 10, 2022
    risk 0.00cvss 9.1epss 0.01

    Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or availability of application via supplying a crafted object (that contains an own property "__proto__") as an argument to the function. NOTE: the vendor disputes…

  • CVE-2022-30335CriMay 9, 2022
    risk 0.64cvss 9.8epss 0.01

    Bonanza Wealth Management System (BWM) 7.3.2 allows SQL injection via the login form. Users who supply the application with a SQL injection payload in the User Name textbox could collect all passwords in encrypted format from the Microsoft SQL Server component.

  • CVE-2022-28738CriMay 9, 2022
    risk 0.64cvss 9.8epss 0.03

    A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untrusted user input, an attacker may be able to write to unexpected memory locations.

  • CVE-2022-27412CriMay 9, 2022
    risk 0.67cvss 9.8epss 0.04

    Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.

  • CVE-2022-1013CriMay 9, 2022
    risk 0.64cvss 9.8epss 0.08

    The Personal Dictionary WordPress plugin before 1.3.4 fails to properly sanitize user supplied POST data before it is being interpolated in an SQL statement and then executed, leading to a blind SQL injection vulnerability.

  • CVE-2022-0948CriMay 9, 2022
    risk 0.64cvss 9.8epss 0.10

    The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection

  • CVE-2022-0836CriMay 9, 2022
    risk 0.64cvss 9.8epss 0.02

    The SEMA API WordPress plugin before 4.02 does not properly sanitise and escape some parameters before using them in SQL statements via an AJAX action, leading to SQL Injections exploitable by unauthenticated users

  • CVE-2022-0826CriMay 9, 2022
    risk 0.64cvss 9.8epss 0.09

    The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

  • CVE-2022-0817CriMay 9, 2022
    risk 0.65cvss 9.8epss 0.12

    The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

  • CVE-2022-0814CriMay 9, 2022
    risk 0.64cvss 9.8epss 0.10

    The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters before using them in SQL statements via various AJAX actions, some of which are available to unauthenticated users, leading to SQL Injections

  • CVE-2022-0592CriMay 9, 2022
    risk 0.64cvss 9.8epss 0.10

    The MapSVG WordPress plugin before 6.2.20 does not validate and escape a parameter via a REST endpoint before using it in a SQL statement, leading to a SQL Injection exploitable by unauthenticated users.

  • CVE-2022-23066CriMay 9, 2022
    risk 0.52cvss 9.1epss 0.02

    In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution path, resulting in huge loss in specific cases. For example, the result of a sdiv instruction may…

  • CVE-2022-28470CriMay 8, 2022
    risk 0.57cvss 9.8epss 0.02

    marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor.

  • CVE-2019-12254CriMay 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented…

  • CVE-2022-1053CriMay 6, 2022
    risk 0.52cvss 9.1epss 0.01

    Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and the verifier for validating the integrity quote. This allows an attacker to use one AK, EK pair from a real TPM to pass EK validation and…

  • CVE-2022-28163CriMay 6, 2022
    risk 0.64cvss 9.8epss 0.01

    In Brocade SANnav before Brocade SANnav 2.2.0, multiple endpoints associated with Zone management are susceptible to SQL injection, allowing an attacker to run arbitrary SQL commands.

  • CVE-2022-28005CriMay 6, 2022
    risk 0.64cvss 9.8epss 0.06

    An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improperly secured access to arbitrary files on the server (via /Electron/download directory traversal in conjunction with a path…

  • CVE-2020-19213CriMay 6, 2022
    risk 0.65cvss 9.8epss 0.16

    SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.