VYPR

CVEs

31,785 total · page 339 of 636

  • CVE-2022-24877CriMay 6, 2022
    risk 0.57cvss 9.9epss 0.01

    Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to expose sensitive data from the controller’s pod filesystem and possibly privilege escalation in…

  • CVE-2022-24884CriMay 6, 2022
    risk 0.00cvss 10.0epss 0.01

    ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge…

  • CVE-2022-24817CriMay 6, 2022
    risk 0.64cvss 9.9epss 0.01

    Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, helm-controller 0.1.0 to v0.19.0, and kustomize-controller 0.1.0 to v0.23.0 are vulnerable to Code Injection via malicious Kubeconfig. In multi-tenancy…

  • CVE-2022-29535CriMay 5, 2022
    risk 0.71cvss 9.8epss 0.93

    Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.

  • CVE-2022-29176CriMay 5, 2022
    risk 0.64cvss 9.9epss 0.02

    Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action, it was possible for any RubyGems.org user to remove and replace certain gems even if that user was not authorized to do so. To be vulnerable, a gem needed:…

  • CVE-2022-27411CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLINK N600R v5.3c.5507_B20171031 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter in the "Main" function.

  • CVE-2022-27360CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.02

    SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.

  • CVE-2022-28584CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.03

    It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.

  • CVE-2022-28583CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.03

    It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.

  • CVE-2022-28582CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.03

    It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.

  • CVE-2022-28581CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.03

    It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.

  • CVE-2022-28580CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.03

    It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.

  • CVE-2022-28579CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.03

    It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.

  • CVE-2022-28578CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.03

    It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.

  • CVE-2022-28577CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.03

    It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows an attacker to execute arbitrary commands through a carefully constructed payload.

  • CVE-2022-28575CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.03

    It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7.4cu.2313_b20191024) router, which allows attackers to execute arbitrary commands through a carefully constructed payload

  • CVE-2022-29592CriMay 5, 2022
    risk 0.65cvss 9.8epss 0.20

    Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route).

  • CVE-2022-29502CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.02

    SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.

  • CVE-2022-28606CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server.

  • CVE-2022-28533CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.02

    Sourcecodester Medical Hub Directory Site 1.0 is vulnerable to SQL Injection via /mhds/clinic/view_details.php.

  • CVE-2022-28530CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.02

    Sourcecodester Covid-19 Directory on Vaccination System 1.0 is vulnerable to SQL Injection via cmdcategory.

  • CVE-2022-28120CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.01

    Beijing Runnier Network Technology Co., Ltd Open virtual simulation experiment teaching management platform software 2.0 has a file upload vulnerability, which can be exploited by an attacker to gain control of the server.

  • CVE-2022-27588CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.01

    We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.6 build 20220401 and later

  • CVE-2022-1388CriKEVMay 5, 2022
    risk 0.93cvss 9.8epss 1.00

    On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which…

  • CVE-2022-28461CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.01

    mingyuefusu Library Management System all versions as of 03-27-2022 is vulnerable to SQL Injection.

  • CVE-2021-42242CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.02

    A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.

  • CVE-2022-1575CriMay 5, 2022
    risk 0.00cvss 9.6epss 0.02

    Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app.

  • CVE-2021-41739CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.03

    A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.

  • CVE-2022-28890CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities.

  • CVE-2022-30292CriMay 4, 2022
    risk 0.00cvss 10.0epss 0.04

    Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call.

  • CVE-2022-30284CriMay 4, 2022
    risk 0.52cvss 9.0epss 0.05

    In the python-libnmap package through 0.7.2 for Python, remote command execution can occur (if used in a client application that does not validate arguments). NOTE: the vendor believes it would be unrealistic for an application to call NmapProcess with arguments taken from input…

  • CVE-2022-29155CriMay 4, 2022
    risk 0.69cvss 9.8epss 0.64

    In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search operation when the search filter is processed, due to a lack…

  • CVE-2022-20780CriMay 4, 2022
    risk 0.65cvss 9.9epss 0.11

    Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more…

  • CVE-2022-20779CriMay 4, 2022
    risk 0.65cvss 9.9epss 0.10

    Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more…

  • CVE-2022-20777CriMay 4, 2022
    risk 0.65cvss 9.9epss 0.11

    Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data from the host to the VM. For more…

  • CVE-2021-42235CriMay 4, 2022
    risk 0.00cvss 9.8epss 0.01

    SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTicket administration profile functionality.

  • CVE-2022-28557CriMay 4, 2022
    risk 0.65cvss 9.8epss 0.23

    There is a command injection vulnerability at the /goform/setsambacfg interface of Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin device web, which can also cooperate with CVE-2021-44971 to cause unconditional arbitrary command execution

  • CVE-2022-29347CriMay 4, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in Web@rchiv 1.0 allows attackers to execute arbitrary commands via a crafted PHP file.

  • CVE-2022-28568CriMay 4, 2022
    risk 0.64cvss 9.8epss 0.03

    Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored.

  • CVE-2022-28512CriMay 4, 2022
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Sourcecodester Fantastic Blog CMS 1.0 . An attacker can inject query in "/fantasticblog/single.php" via the "id=5" parameters.

  • CVE-2022-28082CriMay 4, 2022
    risk 0.64cvss 9.8epss 0.09

    Tenda AX12 v22.03.01.21_CN was discovered to contain a stack overflow via the list parameter at /goform/SetNetControlList.

  • CVE-2022-25784CriMay 4, 2022
    risk 0.59cvss 9.1epss 0.01

    Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue affects: Secomea SiteManager all versions prior to 9.7.

  • CVE-2022-28111CriMay 4, 2022
    risk 0.57cvss 9.8epss 0.02

    MyBatis PageHelper v1.x.x-v3.7.0 v4.0.0-v5.0.0,v5.1.0-v5.3.0 was discovered to contain a time-blind SQL injection vulnerability via the orderBy parameter.

  • CVE-2021-42185CriMay 4, 2022
    risk 0.64cvss 9.8epss 0.01

    wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function.

  • CVE-2022-28055CriMay 4, 2022
    risk 0.00cvss 9.8epss 0.01

    Fusionpbx v4.4 and below contains a command injection vulnerability via the download email logs function.

  • CVE-2022-27431CriMay 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/member/admin/group.php.

  • CVE-2022-27420CriMay 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php.

  • CVE-2021-43163CriMay 4, 2022
    risk 0.64cvss 9.8epss 0.02

    A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the checkNet function in /cgi-bin/luci/api/auth.

  • CVE-2022-27413CriMay 3, 2022
    risk 0.64cvss 9.8epss 0.03

    Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php.

  • CVE-2022-28585CriMay 3, 2022
    risk 0.64cvss 9.8epss 0.01

    EmpireCMS 7.5 has a SQL injection vulnerability in AdClass.php