VYPR

CVEs

31,785 total · page 355 of 636

  • CVE-2022-0651CriFeb 24, 2022
    risk 0.66cvss 9.8epss 0.33

    The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL…

  • CVE-2021-44663CriFeb 24, 2022
    risk 0.00cvss 9.8epss 0.04

    A Remote Code Execution (RCE) vulnerability exists in the Xerte Project Xerte through 3.8.4 via a crafted php file through elfinder in connetor.php.

  • CVE-2020-10640CriFeb 24, 2022
    risk 0.65cvss 10.0epss 0.03

    Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.

  • CVE-2022-25809CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in the case of physically…

  • CVE-2022-25643CriFeb 24, 2022
    risk 0.00cvss 9.8epss 0.02

    seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The attack vector is a user-supplied socket pathname.

  • CVE-2022-25418CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi.

  • CVE-2022-25417CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function saveparentcontrolinfo.

  • CVE-2022-25414CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.10

    Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR.

  • CVE-2022-25406CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete_query.php via the DELETE_STR parameter.

  • CVE-2022-25405CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in change_box.php via the DELETE_STR parameter.

  • CVE-2022-25404CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete.php via the DELETE_STR parameter.

  • CVE-2022-25403CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.02

    HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php.

  • CVE-2022-25402CriFeb 24, 2022
    risk 0.59cvss 9.1epss 0.02

    An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.

  • CVE-2022-25098CriFeb 24, 2022
    risk 0.59cvss 9.1epss 0.01

    ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter.

  • CVE-2022-25084CriFeb 24, 2022
    risk 0.66cvss 9.8epss 0.25

    TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25083CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLink A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25082CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.16

    TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25081CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLink T10 V5.9c.5061_B20200511 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25080CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25079CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLink A810R V4.1.2cu.5182_B20201026 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25078CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25077CriFeb 24, 2022
    risk 0.66cvss 9.8epss 0.33

    TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25076CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25075CriFeb 24, 2022
    risk 0.68cvss 9.8epss 0.56

    TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25074CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.13

    TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.

  • CVE-2022-25073CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.13

    TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.

  • CVE-2022-25072CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.13

    TP-Link Archer A54 Archer A54(US)_V1_210111 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.

  • CVE-2022-21142CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.02

    Authentication bypass vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versions prior to Ver.2.9.39, Ver.2.10.x series versions prior to Ver.2.10.43, and Ver.2.11.x series versions prior to Ver.2.11.41 allows a remote unauthenticated…

  • CVE-2021-44610CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php.

  • CVE-2021-44567CriFeb 24, 2022
    risk 0.05cvss 9.8epss 0.23

    An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.

  • CVE-2021-44550CriFeb 24, 2022
    risk 0.57cvss 9.8epss 0.01

    An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).

  • CVE-2022-25330CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.05

    Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the process or achieve remote code execution.

  • CVE-2022-25329CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and…

  • CVE-2021-35689CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.02

    A potential vulnerability in the Oracle Talent Acquisition Cloud - Taleo Enterprise Edition. This high severity potential vulnerability allows attackers to perform remote code execution on Taleo Enterprise Edition system. Successful attacks of this vulnerability can result in…

  • CVE-2021-4070CriFeb 23, 2022
    risk 0.52cvss 9.1epss 0.01

    Off-by-one Error in GitHub repository v2fly/v2ray-core prior to 4.44.0.

  • CVE-2022-0717CriFeb 23, 2022
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.

  • CVE-2021-27797CriFeb 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system.

  • CVE-2022-24553CriFeb 21, 2022
    risk 0.64cvss 9.8epss 0.03

    An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execution.

  • CVE-2021-24867CriFeb 21, 2022
    risk 0.65cvss 9.8epss 0.19

    Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were…

  • CVE-2022-0691CriFeb 21, 2022
    risk 0.57cvss 9.8epss 0.02

    Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.

  • CVE-2022-23848CriFeb 20, 2022
    risk 0.64cvss 9.8epss 0.01

    In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.

  • CVE-2022-0686CriFeb 20, 2022
    risk 0.52cvss 9.1epss 0.02

    Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.

  • CVE-2016-1239CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.01

    duck before 0.10 did not properly handle loading of untrusted code from the current directory.

  • CVE-2022-25137CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2022-25136CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2022-25135CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.03

    A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2022-25134CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.03

    A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2022-25133CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.03

    A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2022-25132CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.03

    A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2022-25131CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the function recvSlaveCloudCheckStatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.