VYPR

CVEs

31,785 total · page 346 of 636

  • CVE-2022-25569CriApr 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthenticated attackers to login as root users via extracting a key from the software.

  • CVE-2022-0990CriApr 4, 2022
    risk 0.00cvss 9.1epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

  • CVE-2022-1165CriApr 4, 2022
    risk 0.52cvss 9.1epss 0.02

    The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as…

  • CVE-2022-0939CriApr 4, 2022
    risk 0.00cvss 9.9epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

  • CVE-2022-26530CriApr 3, 2022
    risk 0.00cvss 9.1epss 0.01

    swaylock before 1.6 allows attackers to trigger a crash and achieve unlocked access to a Wayland compositor.

  • CVE-2021-30064CriApr 3, 2022
    risk 0.64cvss 9.8epss 0.01

    On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state).

  • CVE-2022-28381CriApr 3, 2022
    risk 0.72cvss 9.8epss 0.69

    Mediaserver.exe in ALLMediaServer 1.6 has a stack-based buffer overflow that allows remote attackers to execute arbitrary code via a long string to TCP port 888, a related issue to CVE-2017-17932.

  • CVE-2022-28368CriApr 3, 2022
    risk 0.03cvss 9.8epss 0.82

    Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).

  • CVE-2022-27534CriApr 1, 2022
    risk 0.64cvss 9.8epss 0.03

    Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March 2022 had a bug in a data parsing module that potentially allowed an attacker to execute arbitrary code. The fix was delivered automatically. Credits: Georgy…

  • CVE-2022-27177CriApr 1, 2022
    risk 0.57cvss 9.8epss 0.02

    A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2

  • CVE-2022-25158CriApr 1, 2022
    risk 0.59cvss 9.1epss 0.01

    Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU all versions, Mitsubishi Electric…

  • CVE-2022-25157CriApr 1, 2022
    risk 0.59cvss 9.1epss 0.02

    Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric MELSEC iQ-F series FX5UJ CPU all versions, Mitsubishi Electric MELSEC iQ-R series R00/01/02CPU all versions,…

  • CVE-2022-22965CriKEVApr 1, 2022
    risk 0.16cvss 9.8epss 1.00

    A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar,…

  • CVE-2022-22963CriKEVApr 1, 2022
    risk 0.87cvss 9.8epss 1.00

    In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

  • CVE-2022-22570CriApr 1, 2022
    risk 0.65cvss 10.0epss 0.01

    A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a malicious actor who has gained access to a network to control all connected UA devices. This vulnerability is fixed in Version 3.8.31.13 and…

  • CVE-2021-32976CriApr 1, 2022
    risk 0.64cvss 9.8epss 0.03

    Five buffer overflows in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to initiate a denial-of-service attack and execute arbitrary code.

  • CVE-2021-32974CriApr 1, 2022
    risk 0.64cvss 9.8epss 0.03

    Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to execute commands.

  • CVE-2021-32953CriApr 1, 2022
    risk 0.64cvss 9.8epss 0.01

    An attacker could utilize SQL commands to create a new user MDT AutoSave versions prior to v6.02.06 and update the user’s permissions, granting the attacker the ability to login.

  • CVE-2021-32933CriApr 1, 2022
    risk 0.65cvss 10.0epss 0.01

    An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave versions prior to v6.02.06 and run a command line argument. This could then be leveraged to run a malicious process.

  • CVE-2021-23247CriApr 1, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary code execution in quick game engine

  • CVE-2022-26562CriApr 1, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to authenticate even if the user account or password is expired. It also exists in the predecessor Zarafa Collaboration Platform (ZCP) in…

  • CVE-2021-44135CriApr 1, 2022
    risk 0.64cvss 9.8epss 0.02

    pagekit all versions, as of 15-10-2021, is vulnerable to SQL Injection via Comment listing.

  • CVE-2022-25017CriApr 1, 2022
    risk 0.61cvss 9.1epss 0.29

    Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field.

  • CVE-2021-1942CriApr 1, 2022
    risk 0.60cvss 9.3epss 0.00

    Improper handling of permissions of a shared memory region can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables,…

  • CVE-2022-24803CriApr 1, 2022
    risk 0.58cvss 10.0epss 0.03

    Asciidoctor-include-ext is Asciidoctor’s standard include processor reimplemented as an extension. Versions prior to 0.4.0, when used to render user-supplied input in AsciiDoc markup, may allow an attacker to execute arbitrary system commands on the host operating system. This…

  • CVE-2022-24796CriMar 31, 2022
    risk 0.00cvss 10.0epss 0.04

    RaspberryMatic is a free and open-source operating system for running a cloud-free smart-home using the homematicIP / HomeMatic hardware line of IoT devices. A Remote Code Execution (RCE) vulnerability in the file upload facility of the WebUI interface of RaspberryMatic exists.…

  • CVE-2022-26546CriMar 31, 2022
    risk 0.59cvss 9.1epss 0.01

    Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and obtain the admin password.

  • CVE-2021-43722CriMar 31, 2022
    risk 0.64cvss 9.8epss 0.03

    D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow. The hnap_main function in the cgibin handler uses sprintf to format the soapaction header onto the stack and has no limit on the size.

  • CVE-2021-43479CriMar 31, 2022
    risk 0.64cvss 9.8epss 0.02

    A Remote Code Execution (RCE) vulnerability exists in The-Secretary 2.5 via install.php.

  • CVE-2021-43484CriMar 31, 2022
    risk 0.64cvss 9.8epss 0.03

    A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate the extension of the file being sent in a request.

  • CVE-2021-43506CriMar 31, 2022
    risk 0.64cvss 9.8epss 0.02

    An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter in Login.php.

  • CVE-2022-24136CriMar 31, 2022
    risk 0.64cvss 9.8epss 0.02

    Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php. To exploit, an attacker can upload any PHP file, and then execute it.

  • CVE-2022-26646CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter.

  • CVE-2022-26645CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.02

    A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.

  • CVE-2021-46009CriMar 30, 2022
    risk 0.65cvss 9.8epss 0.12

    In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without authentication. Additionally, admin configurations can be set without cookies.

  • CVE-2021-46007CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.03

    totolink a3100r V5.9c.4577 is vulnerable to os command injection. The backend of a page is executing the "ping" command, and the input field does not adequately filter special symbols. This can lead to command injection attacks.

  • CVE-2022-24790CriMar 30, 2022
    risk 0.52cvss 9.1epss 0.02

    Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack applications. When using Puma behind a proxy that does not properly validate that the incoming HTTP request matches the RFC7230 standard, Puma and the frontend proxy may disagree on where a request…

  • CVE-2021-43142CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.01

    An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput.

  • CVE-2022-28223CriMar 30, 2022
    risk 0.59cvss 9.1epss 0.01

    Tekon KIO devices through 2022-03-30 allow an authenticated admin user to escalate privileges to root by uploading a malicious Lua plugin.

  • CVE-2022-23799CriMar 30, 2022
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in Joomla! 4.0.0 through 4.1.0. Under specific circumstances, JInput pollutes method-specific input bags with $_REQUEST data.

  • CVE-2022-23797CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Inadequate filtering on the selected Ids on an request could resulted into an possible SQL injection.

  • CVE-2022-23795CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.

  • CVE-2022-28209CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Mediawiki through 1.37.1. The check for the override-antispoof permission in the AntiSpoof extension is incorrect.

  • CVE-2022-28206CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MediaWiki through 1.37.1. ImportPlanValidator.php in the FileImporter extension mishandles the check for edit rights.

  • CVE-2022-28205CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MediaWiki through 1.37.1. The CentralAuth extension mishandles a ttl issue for groups expiring in the future.

  • CVE-2022-24693CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.03

    Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)

  • CVE-2020-24770CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in modrules.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2020-24769CriMar 30, 2022
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in takeconfirm.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the classes parameter.

  • CVE-2022-26871CriKEVMar 29, 2022
    risk 0.77cvss 9.8epss 0.20

    An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.

  • CVE-2021-43118CriMar 29, 2022
    risk 0.66cvss 9.8epss 0.35

    A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a remote malicious user execute arbitrary…