VYPR

CVEs

31,785 total · page 352 of 636

  • CVE-2022-0169CriMar 14, 2022
    risk 0.73cvss 9.8epss 0.75

    The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an…

  • CVE-2021-25007CriMar 14, 2022
    risk 0.64cvss 9.8epss 0.02

    The MOLIE WordPress plugin through 0.5 does not validate and escape a post parameter before using in a SQL statement, leading to an SQL Injection

  • CVE-2021-25003CriMar 14, 2022
    risk 0.68cvss 9.8epss 0.56

    The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE

  • CVE-2022-24387CriMar 14, 2022
    risk 0.59cvss 9.1epss 0.02

    With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml file. THis is possible in SmarterTrack v100.0.8019.14010

  • CVE-2022-23943CriMar 14, 2022
    risk 0.68cvss 9.8epss 0.50

    Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.

  • CVE-2022-22721CriMar 14, 2022
    risk 0.62cvss 9.1epss 0.42

    If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

  • CVE-2022-22720CriMar 14, 2022
    risk 0.66cvss 9.8epss 0.28

    Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

  • CVE-2021-45887CriMar 13, 2022
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in PONTON X/P Messenger before 3.11.2. Due to path traversal in private/SchemaSetUpload.do for uploaded ZIP files, an executable script can be uploaded by web application administrators, giving the attacker remote code execution on the underlying server…

  • CVE-2022-24760CriMar 12, 2022
    risk 0.62cvss 10.0epss 0.49

    Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects Parse Server in the default configuration with MongoDB. The main weakness that leads to RCE is the…

  • CVE-2022-25621CriMar 11, 2022
    risk 0.64cvss 9.8epss 0.01

    UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVERGE WA 1512 Ver8.2.11 and prior, UNIVERGE WA 2020 Ver8.2.11 and prior, UNIVERGE WA 2021 Ver8.2.11 and prior, UNIVERGE WA 2610-AP Ver8.2.11 and prior, UNIVERGE…

  • CVE-2022-23730CriMar 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The public API error causes for the attacker to be able to bypass API access control.

  • CVE-2021-44620CriMar 11, 2022
    risk 0.64cvss 9.8epss 0.02

    A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.

  • CVE-2021-44618CriMar 11, 2022
    risk 0.57cvss 9.8epss 0.01

    A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php via the host header.

  • CVE-2022-0860CriMar 11, 2022
    risk 0.52cvss 9.1epss 0.02

    Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.

  • CVE-2022-0871CriMar 11, 2022
    risk 0.52cvss 9.1epss 0.01

    Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.

  • CVE-2022-23402CriMar 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00

  • CVE-2022-21194CriMar 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00.

  • CVE-2022-26520CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP…

  • CVE-2022-26143CriKEVMar 10, 2022
    risk 0.83cvss 9.8epss 0.88

    The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in…

  • CVE-2022-26131CriMar 10, 2022
    risk 0.61cvss 9.3epss 0.01

    Power Line Communications PLC4TRUCKS J2497 trailer receivers are susceptible to remote RF induced signals.

  • CVE-2022-26100CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR process may crash, and the attacker may obtain privileged access to the system.

  • CVE-2022-24995CriMar 10, 2022
    risk 0.65cvss 9.8epss 0.14

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.

  • CVE-2022-24652CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution in /admin/upload/upload.

  • CVE-2022-24651CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload.

  • CVE-2022-24609CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file.

  • CVE-2022-24607CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php.

  • CVE-2022-24606CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php.

  • CVE-2022-24605CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php.

  • CVE-2022-24604CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.

  • CVE-2022-24603CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php.

  • CVE-2022-24602CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.

  • CVE-2022-24600CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements.

  • CVE-2022-24193CriMar 10, 2022
    risk 0.57cvss 9.8epss 0.06

    CasaOS before v0.2.7 was discovered to contain a command injection vulnerability.

  • CVE-2022-23383CriMar 10, 2022
    risk 0.59cvss 9.1epss 0.01

    YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home…

  • CVE-2022-22814CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    The System Diagnosis service of MyASUS before 3.1.2.0 allows privilege escalation.

  • CVE-2021-4045CriMar 10, 2022
    risk 0.73cvss 9.8epss 0.72

    TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera.

  • CVE-2021-44632CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/upgrade_info feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.

  • CVE-2021-44631CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/reset_cloud_pwd feature, which allows malicous users to execute arbitrary code on the system via a crafted post request.

  • CVE-2021-44630CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/modify_account_pwd feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.

  • CVE-2021-44629CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    A Buffer Overflow vulnerabilitiy exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/register feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.

  • CVE-2021-44628CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    A Buffer Overflow vulnerabiltiy exists in TP-LINK WR-886N 20190826 2.3.8 in thee /cloud_config/router_post/login feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.

  • CVE-2021-44627CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/get_reset_pwd_veirfy_code feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.

  • CVE-2021-44626CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/get_reg_verify_code feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.

  • CVE-2021-44625CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in /cloud_config/cloud_device/info interface, which allows a malicious user to executee arbitrary code on the system via a crafted post request.

  • CVE-2021-44623CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 via the /cloud_config/router_post/check_reset_pwd_verify_code interface.

  • CVE-2021-44622CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/check_reg_verify_code function which could let a remove malicious user execute arbitrary code via a crafted post request.

  • CVE-2021-42854CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" API. The affected endpoint does not have any input validation of the user's input that allows a…

  • CVE-2021-42853CriMar 10, 2022
    risk 0.59cvss 9.1epss 0.02

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent/diagnostic/logs" API. The affected endpoint does not have any input validation of the user's input…

  • CVE-2021-42787CriMar 10, 2022
    risk 0.61cvss 9.4epss 0.01

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/configuration" API. The affected endpoint does not have any input validation of the user's…

  • CVE-2021-42786CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) has Remote Code Execution vulnerabilities in multiple instances of the API requests. The affected endpoints do not have any input validation of the user's input that allowed a malicious payload to…