VYPR

CVEs

31,785 total · page 340 of 636

  • CVE-2022-27962CriMay 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Bluecms 1.6 has a SQL injection vulnerability at cooike.

  • CVE-2022-28561CriMay 3, 2022
    risk 0.64cvss 9.8epss 0.10

    There is a stack overflow vulnerability in the /goform/setMacFilterCfg function in the httpd service of Tenda ax12 22.03.01.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload

  • CVE-2022-28560CriMay 3, 2022
    risk 0.64cvss 9.8epss 0.02

    There is a stack overflow vulnerability in the goform/fast_setting_wifi_set function in the httpd service of Tenda ac9 15.03.2.21_cn router. An attacker can obtain a stable shell through a carefully constructed payload

  • CVE-2022-28118CriMay 3, 2022
    risk 0.64cvss 9.8epss 0.03

    SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.

  • CVE-2020-23621CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.02

    The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.

  • CVE-2020-23620CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.02

    The Java Remote Management Interface of all versions of Orlansoft ERP was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.

  • CVE-2022-1378CriMay 2, 2022
    risk 0.65cvss 9.8epss 0.19

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_pgHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-1377CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_rltHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-1376CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_privgrpHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-1375CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_slogHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-1374CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_unHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-1372CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in dlSlog.aspx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-1371CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegf. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-1370CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadREGbyID. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-1369CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in ReadRegIND. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-1367CriMay 2, 2022
    risk 0.65cvss 9.8epss 0.19

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handler_TCV.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2021-3643CriMay 2, 2022
    risk 0.59cvss 9.1epss 0.02

    A flaw was found in sox 14.4.1. The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw allows an attacker to input a malicious file, leading to the disclosure of sensitive information.

  • CVE-2022-1366CriMay 2, 2022
    risk 0.65cvss 9.8epss 0.19

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerChart.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-1281CriMay 2, 2022
    risk 0.66cvss 9.8epss 0.23

    The Photo Gallery WordPress plugin through 1.6.3 does not properly escape the $_POST['filter_tag'] parameter, which is appended to an SQL query, making SQL Injection attacks possible.

  • CVE-2022-0783CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.08

    The Multiple Shipping Address Woocommerce WordPress plugin before 2.0 does not properly sanitise and escape numerous parameters before using them in SQL statements via some AJAX actions available to unauthenticated users, leading to unauthenticated SQL injections

  • CVE-2022-0773CriMay 2, 2022
    risk 0.67cvss 9.8epss 0.43

    The Documentor WordPress plugin through 1.5.3 fails to sanitize and escape user input before it is being interpolated in an SQL statement and then executed, leading to an SQL Injection exploitable by unauthenticated users.

  • CVE-2022-0771CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.02

    The SiteSuperCharger WordPress plugin before 5.2.0 does not validate, sanitise and escape various user inputs before using them in SQL statements via AJAX actions (available to both unauthenticated and authenticated users), leading to Unauthenticated SQL Injections

  • CVE-2022-28573CriMay 2, 2022
    risk 0.66cvss 9.8epss 0.28

    D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNTPserverSeting. This vulnerability allows attackers to execute arbitrary commands via the system_time_timezone parameter.

  • CVE-2022-28056CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.01

    ShopXO v2.2.5 and below was discovered to contain a system re-install vulnerability via the Add function in app/install/controller/Index.php.

  • CVE-2022-28054CriMay 2, 2022
    risk 0.66cvss 9.8epss 0.31

    Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value.

  • CVE-2022-27982CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.02

    RG-NBR-E Enterprise Gateway RG-NBR2100G-E was discovered to contain a remote code execution (RCE) vulnerability via the fileName parameter at /guest_auth/cfg/upLoadCfg.php.

  • CVE-2022-27466CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.02

    MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.

  • CVE-2022-28571CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.06

    D-link 882 DIR882A1_FW130B06 was discovered to contain a command injection vulnerability in`/usr/bin/cli.

  • CVE-2022-1300CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple Version of TRUMPF TruTops products expose a service function without necessary authentication. Execution of this function may result in unauthorized access to change of data or disruption of the whole service.

  • CVE-2022-25767CriMay 1, 2022
    risk 0.64cvss 9.8epss 0.03

    All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.

  • CVE-2022-24437CriMay 1, 2022
    risk 0.57cvss 9.8epss 0.04

    The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to…

  • CVE-2022-28481CriMay 1, 2022
    risk 0.57cvss 9.8epss 0.02

    CSV-Safe gem < 3.0.0 doesn't filter out special characters which could trigger CSV Injection.

  • CVE-2022-28994CriApr 29, 2022
    risk 0.64cvss 9.8epss 0.02

    Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request.

  • CVE-2022-28480CriApr 29, 2022
    risk 0.64cvss 9.8epss 0.02

    ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe.

  • CVE-2022-28452CriApr 29, 2022
    risk 0.65cvss 9.8epss 0.17

    Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.

  • CVE-2022-24900CriApr 29, 2022
    risk 0.01cvss 9.9epss 0.08

    Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulnerable to a path traversal attack. The `os.path.join` call is unsafe for use with untrusted input. When the `os.path.join` call…

  • CVE-2021-44596CriApr 29, 2022
    risk 0.68cvss 9.8epss 0.23

    Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an unauthenticated user can communicate over UDP with the "InstallAssistService.exe" service(the service is running under SYSTEM privileges) and manipulate it to…

  • CVE-2022-1531CriApr 29, 2022
    risk 0.00cvss 9.8epss 0.04

    SQL injection vulnerability in ARAX-UI Synonym Lookup functionality in GitHub repository rtxteam/rtx prior to checkpoint_2022-04-20 . This vulnerability is critical as it can lead to remote code execution and thus complete server takeover.

  • CVE-2022-29906CriApr 29, 2022
    risk 0.64cvss 9.8epss 0.01

    The admin API module in the QuizGame extension for MediaWiki through 1.37.2 (before 665e33a68f6fa1167df99c0aa18ed0157cdf9f66) omits a check for the quizadmin user.

  • CVE-2022-29904CriApr 29, 2022
    risk 0.65cvss 9.8epss 0.17

    The SemanticDrilldown extension for MediaWiki through 1.37.2 (before e688bdba6434591b5dff689a45e4d53459954773) allows SQL injection with certain '-' and '_' constraints.

  • CVE-2022-24449CriApr 28, 2022
    risk 0.64cvss 9.8epss 0.02

    Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document.

  • CVE-2022-29556CriApr 28, 2022
    risk 0.64cvss 9.8epss 0.01

    The iot-manager microservice 1.0.0 in Northern.tech Mender Enterprise before 3.2.2 allows SSRF because the Azure IoT Hub integration provides several SSRF primitives that can execute cross-tenant actions via internal API endpoints.

  • CVE-2022-29081CriApr 28, 2022
    risk 0.70cvss 9.8epss 0.84

    Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via…

  • CVE-2022-28114CriApr 28, 2022
    risk 0.59cvss 9.1epss 0.01

    DSCMS v3.0 was discovered to contain an arbitrary file deletion vulnerability via /controller/Adv.php.

  • CVE-2021-43934CriApr 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling a malicious user to potentially upload arbitrary files.

  • CVE-2021-43932CriApr 28, 2022
    risk 0.59cvss 9.0epss 0.01

    Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page.

  • CVE-2022-28101CriApr 28, 2022
    risk 0.59cvss 9.0epss 0.01

    Turtlapp Turtle Note v0.7.2.6 does not filter the tag during markdown parsing, allowing attackers to execute HTML injection.

  • CVE-2021-41945CriApr 28, 2022
    risk 0.52cvss 9.1epss 0.02

    Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.

  • CVE-2021-41921CriApr 28, 2022
    risk 0.64cvss 9.8epss 0.02

    novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.

  • CVE-2022-1509CriApr 28, 2022
    risk 0.00cvss 9.9epss 0.05

    Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.