VYPR

CVEs

31,785 total · page 344 of 636

  • CVE-2022-28035CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.php

  • CVE-2022-28034CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    AtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.php

  • CVE-2022-28033CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.05

    Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php

  • CVE-2022-28032CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.06

    AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php

  • CVE-2022-27473CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Topics Searching feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely.

  • CVE-2022-27472CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Topics Counting feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely.

  • CVE-2022-27165CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus

  • CVE-2022-27164CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers

  • CVE-2022-27163CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_editUser

  • CVE-2022-27162CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_editUser

  • CVE-2022-27161CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers

  • CVE-2021-31805CriApr 12, 2022
    risk 0.71cvss 9.8epss 0.85

    The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted…

  • CVE-2022-0142CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.03

    The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

  • CVE-2022-25752CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 230V, coated), SCALANCE X302-7 EEC (2x 24V), SCALANCE…

  • CVE-2022-23450CriApr 12, 2022
    risk 0.67cvss 9.8epss 0.36

    A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of…

  • CVE-2022-29080CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.02

    The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions with a JSON object in which pkgs is a key, and there are shell metacharacters in a value.

  • CVE-2022-28347CriApr 12, 2022
    risk 0.57cvss 9.8epss 0.03

    A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.

  • CVE-2022-28346CriApr 12, 2022
    risk 0.58cvss 9.8epss 0.19

    An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

  • CVE-2022-27577CriApr 11, 2022
    risk 0.59cvss 9.1epss 0.01

    The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number. When the TCP sequence is predictable, an attacker can send packets that are forged to appear to come from a trusted computer. These forged packets could…

  • CVE-2022-22954CriKEVApr 11, 2022
    risk 0.93cvss 9.8epss 1.00

    VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

  • CVE-2022-22258CriApr 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The Wi-Fi module has an event notification vulnerability.Successful exploitation of this vulnerability may allow third-party applications to intercept event notifications and add information and result in elevation-of-privilege.

  • CVE-2022-1161CriApr 11, 2022
    risk 0.65cvss 10.0epss 0.05

    An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an…

  • CVE-2021-46742CriApr 11, 2022
    risk 0.59cvss 9.1epss 0.01

    The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful exploitation of this vulnerability may affect the availability.

  • CVE-2021-38125CriApr 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Unauthenticated remote code execution in Micro Focus Operations Bridge containerized, affecting versions 2021.05, 2021.08, and newer versions of Micro Focus Operations Bridge containerized if the deployment was upgraded from 2021.05 or 2021.08. The vulnerability could be…

  • CVE-2021-37291CriApr 11, 2022
    risk 0.64cvss 9.8epss 0.08

    An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.

  • CVE-2022-27115CriApr 11, 2022
    risk 0.59cvss 9.8epss 0.29

    In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.

  • CVE-2022-0949CriApr 11, 2022
    risk 0.64cvss 9.8epss 0.08

    The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to…

  • CVE-2022-1297CriApr 11, 2022
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.

  • CVE-2022-1296CriApr 11, 2022
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds read in `r_bin_ne_get_relocs` function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.

  • CVE-2022-1295CriApr 11, 2022
    risk 0.57cvss 9.8epss 0.01

    Prototype Pollution in GitHub repository alvarotrigo/fullpage.js prior to 4.0.2.

  • CVE-2021-32157CriApr 11, 2022
    risk 0.63cvss 9.6epss 0.04

    A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.

  • CVE-2022-27477CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit.

  • CVE-2022-27277CriApr 10, 2022
    risk 0.59cvss 9.1epss 0.01

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file deletion vulnerability via the function sub_17C08.

  • CVE-2022-27276CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_10F2C. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27275CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_122D0. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27274CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12028. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27273CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12168. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27272CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_1791C. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27271CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component python-lib. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27270CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component ipsec_secrets. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27269CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.04

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component config_ovpn. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27268CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.04

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component get_cgi_from_memory. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27133CriApr 10, 2022
    risk 0.59cvss 9.1epss 0.01

    zbzcms v1.0 was discovered to contain an arbitrary file deletion vulnerability via /include/up.php.

  • CVE-2022-27131CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability at /zbzedit/php/zbz.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27129CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability at /admin/ajax.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27128CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.01

    An incorrect access control issue at /admin/run_ajax.php in zbzcms v1.0 allows attackers to arbitrarily add administrator accounts.

  • CVE-2022-27126CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.01

    zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the art parameter at /include/make.php.

  • CVE-2022-1286CriApr 10, 2022
    risk 0.00cvss 9.8epss 0.01

    heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

  • CVE-2022-1276CriApr 10, 2022
    risk 0.00cvss 9.8epss 0.01

    Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

  • CVE-2022-26851CriApr 8, 2022
    risk 0.59cvss 9.1epss 0.01

    Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss.