VYPR

CVEs

31,785 total · page 351 of 636

  • CVE-2022-23812CriMar 16, 2022
    risk 0.57cvss 9.8epss 0.04

    This affects the package node-ipc from 10.1.1 and before 10.1.3. This package contains malicious code, that targets users with IP located in Russia or Belarus, and overwrites their files with a heart emoji. **Note**: from versions 11.0.0 onwards, instead of having malicious code…

  • CVE-2022-25251CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.02

    When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain XML messages to a specific port without proper authentication. Successful exploitation of this vulnerability could allow a…

  • CVE-2022-25247CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.04

    Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an attacker to send certain commands to a specific port without authentication. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to obtain full…

  • CVE-2022-25246CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) uses hard-coded credentials for its UltraVNC installation. Successful exploitation of this vulnerability could allow a remote authenticated attacker to take full remote control of the host operating…

  • CVE-2022-0982CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    The telnet_input_char function in opt/src/accel-pppd/cli/telnet.c suffers from a memory corruption vulnerability, whereby user input cmdline_len is copied into a fixed buffer b->buf without any bound checks. If the server connects with a malicious client, crafted client requests…

  • CVE-2021-39737CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-208229524References: N/A

  • CVE-2021-39723CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-209014813References: N/A

  • CVE-2021-39720CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-207433926References: N/A

  • CVE-2021-39710CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-202160245References: N/A

  • CVE-2021-39708CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-23165CriMar 16, 2022
    risk 0.00cvss 9.8epss 0.03

    A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service.

  • CVE-2021-23158CriMar 16, 2022
    risk 0.00cvss 9.8epss 0.02

    A flaw was found in htmldoc in v1.9.12. Double-free in function pspdf_export(),in ps-pdf.cxx may result in a write-what-where condition, allowing an attacker to execute arbitrary code and denial of service.

  • CVE-2021-45786CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.

  • CVE-2021-43958CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing…

  • CVE-2022-27005CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.06

    Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the setWanCfg function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted…

  • CVE-2022-27004CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6in4 function via the remote6in4 parameter. This vulnerability allows attackers to execute arbitrary commands via a…

  • CVE-2022-27003CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6rd function via the relay6rd parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted…

  • CVE-2022-27002CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.06

    Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-27001CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-27000CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_backup_ntp_server, and h_time_zone parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted…

  • CVE-2022-26999CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_stat, wan_gw_stat, and wan_dns1_stat parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted…

  • CVE-2022-26998CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-26997CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-26996CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd, and pppoe_servicename parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-26995CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, pptp_fix_mask, pptp_fix_gw, and wan_dns1_stat parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted…

  • CVE-2022-26994CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the pptp function via the pptpUserName and pptpPassword parameters. This vulnerability allows attackers to execute arbitrary…

  • CVE-2022-26993CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the pppoe function via the pppoeUserName, pppoePassword, and pppoe_Service parameters. This vulnerability allows attackers to…

  • CVE-2022-26992CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the ddns function via the DdnsUserName, DdnsHostName, and DdnsPassword parameters. This vulnerability allows attackers to execute…

  • CVE-2022-26991CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the ntp function via the TimeZone parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted…

  • CVE-2022-26990CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the firewall-local log function via the EmailAddress, SmtpServerName, SmtpUsername, and SmtpPassword parameters. This…

  • CVE-2022-26214CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26213CriMar 15, 2022
    risk 0.66cvss 9.8epss 0.26

    Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-26212CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26211CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26210CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.06

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26209CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26208CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26207CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26206CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-25498CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.

  • CVE-2022-25495CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file.

  • CVE-2022-25494CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via staff_login.php.

  • CVE-2022-25492CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php.

  • CVE-2022-25490CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.

  • CVE-2022-25488CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.07

    Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.

  • CVE-2022-25487CriMar 15, 2022
    risk 0.68cvss 9.8epss 0.55

    Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.

  • CVE-2022-24752CriMar 15, 2022
    risk 0.57cvss 9.8epss 0.01

    SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query sorting were passed directly to the database. The maintainers do not know if this could lead to direct SQL injections but took…

  • CVE-2022-26320CriMar 14, 2022
    risk 0.59cvss 9.1epss 0.01

    The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with…

  • CVE-2022-0658CriMar 14, 2022
    risk 0.64cvss 9.8epss 0.09

    The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection

  • CVE-2022-0254CriMar 14, 2022
    risk 0.57cvss 9.8epss 0.02

    The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection