VYPR

CVEs

31,785 total · page 347 of 636

  • CVE-2021-42911CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.03

    A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfunction.cgi file via a crafted HTTP message containing malformed QUERY STRING, which could let a remote malicious user execute…

  • CVE-2021-43110CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    An Access Conrol vulnerability exists in PuneethReddyHC online-shopping-system as of 11/01/2021 in add_products.

  • CVE-2022-27175CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetCalcTagList. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-26887CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.10

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in DIAE_loopmapHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-26836CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerExport.ashx/Calendar. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-26667CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetDemandAnalysisData. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-26666CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerECC.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-26514CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_tagHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-26349CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_eccoefficientHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-26338CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerPageP_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-26069CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerPage_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-26065CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in GetLatestDemandNode. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-26059CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetQueryData. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-26013CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.09

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_dmdsetHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-25980CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerCommon.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-25880CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerTag_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-25347CriMar 29, 2022
    risk 0.65cvss 9.8epss 0.11

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the file system.

  • CVE-2022-0923CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerDialog_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-23901CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.02

    A stack overflow re2c 2.2 exists due to infinite recursion issues in src/dfa/dead_rules.cc.

  • CVE-2021-46743CriMar 29, 2022
    risk 0.59cvss 9.1epss 0.01

    In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of keys are loaded in a key ring. This allows an attacker to forge tokens that validate under the incorrect key. NOTE: this provides a…

  • CVE-2022-25420CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.02

    NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows attackers to execute arbitrary code via a crafted HTTP request.

  • CVE-2022-25521CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.02

    NUUO v03.11.00 was discovered to contain access control issue.

  • CVE-2021-45865CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality.

  • CVE-2022-26278CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21_cn was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.

  • CVE-2022-0735CriMar 28, 2022
    risk 0.66cvss 10.0epss 0.13

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an…

  • CVE-2022-0846CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.09

    The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection exploitable by unauthenticated users

  • CVE-2022-0787CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.09

    The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections

  • CVE-2022-0784CriMar 28, 2022
    risk 0.65cvss 9.8epss 0.10

    The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

  • CVE-2022-0679CriMar 28, 2022
    risk 0.68cvss 9.8epss 0.48

    The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and authenticated users) which results…

  • CVE-2022-0479CriMar 28, 2022
    risk 0.60cvss 9.8epss 0.43

    The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site…

  • CVE-2021-25070CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue

  • CVE-2022-23884CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.03

    Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by PurchaseReceiptPacket::_read (packet deserializer).

  • CVE-2022-0342CriMar 28, 2022
    risk 0.70cvss 9.8epss 0.85

    An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG…

  • CVE-2022-23882CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.01

    TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php.

  • CVE-2021-46433CriMar 28, 2022
    risk 0.65cvss 10.0epss 0.01

    In fenom 2.12.1 and before, there is a way in fenom/src/Fenom/Template.php function getTemplateCode()to bypass sandbox to execute arbitrary PHP code when disable_native_funcs is true.

  • CVE-2022-25757CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSON with a duplicate key, the attacker can bypass the body_schema validation in the request-validation plugin. For example,…

  • CVE-2022-26273CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.01

    EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.

  • CVE-2022-24303CriMar 28, 2022
    risk 0.52cvss 9.1epss 0.03

    Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.

  • CVE-2021-45490CriMar 28, 2022
    risk 0.59cvss 9.1epss 0.01

    The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation.

  • CVE-2021-44617CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.

  • CVE-2022-26268CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php.

  • CVE-2021-26600CriMar 28, 2022
    risk 0.57cvss 9.8epss 0.06

    ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).

  • CVE-2021-26599CriMar 28, 2022
    risk 0.61cvss 9.8epss 0.22

    ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.

  • CVE-2022-26258CriKEVMar 28, 2022
    risk 0.82cvss 9.8epss 0.81

    D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

  • CVE-2022-26255CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    Clash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxies name column.

  • CVE-2021-44127CriMar 27, 2022
    risk 0.64cvss 9.8epss 0.03

    In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized.

  • CVE-2022-26245CriMar 27, 2022
    risk 0.65cvss 9.8epss 0.15

    Falcon-plus v0.3 was discovered to contain a SQL injection vulnerability via the parameter grpName in /config/service/host.go.

  • CVE-2022-1106CriMar 27, 2022
    risk 0.00cvss 9.1epss 0.01

    use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.

  • CVE-2022-26205CriMar 27, 2022
    risk 0.64cvss 9.8epss 0.02

    Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display text fields. This vulnerability allows attackers to execute arbitrary code via injection of a crafted payload.

  • CVE-2022-26198CriMar 27, 2022
    risk 0.64cvss 9.8epss 0.02

    Notable v1.8.4 does not filter text editing, allowing attackers to execute arbitrary code via a crafted payload injected into the Title text field.