VYPR

CVEs

31,785 total · page 341 of 636

  • CVE-2022-28719CriApr 28, 2022
    risk 0.64cvss 9.8epss 0.04

    Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to…

  • CVE-2022-29859CriApr 27, 2022
    risk 0.00cvss 9.8epss 0.01

    component/common/network/dhcp/dhcps.c in ambiot amb1_sdk (aka SDK for Ameba1) before 2022-03-11 mishandles data structures for DHCP packet data.

  • CVE-2022-27336CriApr 27, 2022
    risk 0.65cvss 9.8epss 0.21

    Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.

  • CVE-2021-38869CriApr 27, 2022
    risk 0.64cvss 9.8epss 0.01

    IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341.

  • CVE-2021-34601CriApr 27, 2022
    risk 0.64cvss 9.8epss 0.01

    In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below is prone to hardcoded ssh credentials. An attacker may use the password to gain administrative access to the web-UI.

  • CVE-2022-28464CriApr 27, 2022
    risk 0.59cvss 9.0epss 0.01

    Apifox through 2.1.6 is vulnerable to Cross Site Scripting (XSS) which can lead to remote code execution.

  • CVE-2021-46424CriApr 27, 2022
    risk 0.65cvss 9.1epss 0.36

    Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request.

  • CVE-2021-46422CriApr 27, 2022
    risk 0.74cvss 9.8epss 0.95

    Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands without any authentication.

  • CVE-2021-46442CriApr 27, 2022
    risk 0.68cvss 9.8epss 0.56

    In the "webupg" binary of D-Link DIR-825 G1, attackers can bypass authentication through parameters "autoupgrade.asp", and perform functions such as downloading configuration files and updating firmware without authorization.

  • CVE-2022-27332CriApr 27, 2022
    risk 0.59cvss 9.1epss 0.01

    An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log without authentication. This vulnerability can allow attackers to execute phishing attacks or cause a Denial of Service (DoS).

  • CVE-2022-28524CriApr 26, 2022
    risk 0.64cvss 9.8epss 0.01

    ED01-CMS v20180505 was discovered to contain a SQL injection vulnerability via the component post.php.

  • CVE-2022-28521CriApr 26, 2022
    risk 0.64cvss 9.8epss 0.02

    ZCMS v20170206 was discovered to contain a file inclusion vulnerability via index.php?m=home&c=home&a=sp_set_config.

  • CVE-2022-24882CriApr 26, 2022
    risk 0.00cvss 9.1epss 0.03

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP…

  • CVE-2022-27985CriApr 26, 2022
    risk 0.64cvss 9.8epss 0.07

    CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

  • CVE-2022-27984CriApr 26, 2022
    risk 0.64cvss 9.8epss 0.07

    CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

  • CVE-2022-27469CriApr 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Monstaftp v2.10.3 was discovered to allow attackers to execute Server-Side Request Forgery (SSRF).

  • CVE-2022-27468CriApr 26, 2022
    risk 0.64cvss 9.8epss 0.02

    Monstaftp v2.10.3 was discovered to contain an arbitrary file upload which allows attackers to execute arbitrary code via a crafted file uploaded to the web server.

  • CVE-2022-27299CriApr 26, 2022
    risk 0.64cvss 9.8epss 0.02

    Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php.

  • CVE-2022-24706CriKEVApr 26, 2022
    risk 0.79cvss 9.8epss 0.93

    In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a…

  • CVE-2022-29806CriApr 26, 2022
    risk 0.08cvss 9.8epss 0.67

    ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.

  • CVE-2022-29499CriKEVApr 26, 2022
    risk 0.86cvss 9.8epss 0.57

    The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.

  • CVE-2022-1391CriApr 25, 2022
    risk 0.65cvss 9.8epss 0.14

    The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.

  • CVE-2022-1390CriApr 25, 2022
    risk 0.65cvss 9.8epss 0.22

    The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the null byte technique. This could also…

  • CVE-2022-0782CriApr 25, 2022
    risk 0.64cvss 9.8epss 0.02

    The Donations WordPress plugin through 1.8 does not sanitise and escape the nd_donations_id parameter before using it in a SQL statement via the nd_donations_single_cause_form_validate_fields_php_function AJAX action (available to unauthenticated users), leading to an…

  • CVE-2022-0769CriApr 25, 2022
    risk 0.64cvss 9.8epss 0.09

    The Users Ultra WordPress plugin through 3.1.0 fails to properly sanitize and escape the data_target parameter before it is being interpolated in an SQL statement and then executed via the rating_vote AJAX action (available to both unauthenticated and authenticated users),…

  • CVE-2022-0693CriApr 25, 2022
    risk 0.64cvss 9.8epss 0.07

    The Master Elements WordPress plugin through 8.0 does not validate and escape the meta_ids parameter of its remove_post_meta_condition AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL…

  • CVE-2022-0657CriApr 25, 2022
    risk 0.64cvss 9.8epss 0.02

    The 5 Stars Rating Funnel WordPress Plugin | RRatingg WordPress plugin before 1.2.54 does not properly sanitise, validate and escape lead ids before using them in a SQL statement via the rrtngg_delete_leads AJAX action, available to unauthenticated users, leading to an…

  • CVE-2022-0541CriApr 25, 2022
    risk 0.64cvss 9.8epss 0.02

    The flo-launch WordPress plugin before 2.4.1 injects code into wp-config.php when creating a cloned site, allowing any attacker to initiate a new site install by setting the flo_custom_table_prefix cookie to an arbitrary value.

  • CVE-2022-29078CriApr 25, 2022
    risk 0.59cvss 9.8epss 0.33

    The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is…

  • CVE-2022-28093CriApr 25, 2022
    risk 0.64cvss 9.8epss 0.02

    SCBS Online Sports Venue Reservation System v1.0 was discovered to contain a local file inclusion vulnerability which allow attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27429CriApr 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/update.html.

  • CVE-2022-27311CriApr 25, 2022
    risk 0.57cvss 9.8epss 0.02

    Gibbon v3.4.4 and below allows attackers to execute a Server-Side Request Forgery (SSRF) via a crafted URL.

  • CVE-2021-45840CriApr 25, 2022
    risk 0.64cvss 9.8epss 0.04

    It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending specifically crafted input to /tos/index.php?app/app_start_stop.

  • CVE-2021-45837CriApr 25, 2022
    risk 0.68cvss 9.8epss 0.16

    It is possible to execute arbitrary commands as root in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) by sending a specifically crafted input to /tos/index.php?app/del.

  • CVE-2022-29264CriApr 25, 2022
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in coreboot 4.13 through 4.16. On APs, arbitrary code execution in SMM may occur.

  • CVE-2022-29077CriApr 25, 2022
    risk 0.64cvss 9.8epss 0.02

    A heap-based buffer overflow exists in rippled before 1.8.5. The vulnerability allows attackers to cause a crash or execute commands remotely on a rippled node, which may lead to XRPL mainnet DoS or compromise. This exposes all digital assets on the XRPL to a security threat.

  • CVE-2021-3897CriApr 22, 2022
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not…

  • CVE-2021-3849CriApr 22, 2022
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected.

  • CVE-2022-27342CriApr 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Link-Admin v0.0.1 was discovered to contain a SQL injection vulnerability via DictRest.ResponseResult().

  • CVE-2022-27341CriApr 22, 2022
    risk 0.64cvss 9.8epss 0.01

    JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function.

  • CVE-2022-1440CriApr 22, 2022
    risk 0.57cvss 9.8epss 0.04

    Command Injection vulnerability in git-interface@2.1.1 in GitHub repository yarkeev/git-interface prior to 2.1.2. If both are provided by user input, then the use of a `--upload-pack` command-line argument feature of git is also supported for `git clone`, which would then allow…

  • CVE-2022-27404CriApr 22, 2022
    risk 0.64cvss 9.8epss 0.03

    FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.

  • CVE-2022-26674CriApr 22, 2022
    risk 0.64cvss 9.8epss 0.03

    ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service.

  • CVE-2022-28443CriApr 21, 2022
    risk 0.59cvss 9.1epss 0.01

    UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability.

  • CVE-2022-28439CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&&action=delete&userid=4.

  • CVE-2022-28438CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=User&userid=.

  • CVE-2022-28437CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=type&userrole=Admin&userid=3.

  • CVE-2022-28436CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/uesrs.php&action=display&value=Hide&userid=.

  • CVE-2022-28435CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/siteoptions.php&action=displaygoal&value=1&roleid=1.

  • CVE-2022-28434CriApr 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=siteoptions&social=edit&sid=2.