VYPR

CVEs

31,783 total · page 358 of 636

  • CVE-2020-36062CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.

  • CVE-2020-13675CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.01

    Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by…

  • CVE-2022-24112CriKEVFeb 11, 2022
    risk 0.79cvss 9.8epss 0.96

    An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed…

  • CVE-2021-44521CriFeb 11, 2022
    risk 0.64cvss 9.1epss 0.55

    When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would…

  • CVE-2021-30317CriFeb 11, 2022
    risk 0.61cvss 9.3epss 0.01

    Improper validation of program headers containing ELF metadata can lead to image verification bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2022-24961CriFeb 11, 2022
    risk 0.00cvss 9.8epss 0.02

    In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.

  • CVE-2022-24955CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.01

    Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.

  • CVE-2022-24954CriFeb 11, 2022
    risk 0.65cvss 9.8epss 0.12

    Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substrings.

  • CVE-2022-23806CriFeb 11, 2022
    risk 0.59cvss 9.1epss 0.03

    Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.

  • CVE-2022-24568CriFeb 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input.

  • CVE-2021-45364CriFeb 10, 2022
    risk 0.64cvss 9.8epss 0.02

    A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an error in publishing this CVE Record, and that all parties agree that the affected code was not used in any Statamic product

  • CVE-2022-20749CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.04

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20712CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.03

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20711CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.05

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20710CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.02

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20709CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.04

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20708CriKEVFeb 10, 2022
    risk 0.78cvss 10.0epss 0.15

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20707CriFeb 10, 2022
    risk 0.74cvss 10.0epss 0.75

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20706CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.06

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20705CriFeb 10, 2022
    risk 0.74cvss 10.0epss 0.80

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20704CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.02

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20703CriKEVFeb 10, 2022
    risk 0.78cvss 10.0epss 0.09

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20702CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.05

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20701CriKEVFeb 10, 2022
    risk 0.78cvss 10.0epss 0.10

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20700CriKEVFeb 10, 2022
    risk 0.77cvss 10.0epss 0.06

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20699CriKEVFeb 10, 2022
    risk 0.86cvss 10.0epss 0.72

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2021-25992CriFeb 10, 2022
    risk 0.00cvss 9.8epss 0.02

    In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetical attacks.

  • CVE-2022-24313CriFeb 9, 2022
    risk 0.67cvss 9.8epss 0.45

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data…

  • CVE-2022-24312CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.03

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by adding at end of file or create a new file in the context of the Data Server potentially leading to remote code execution when an…

  • CVE-2022-24311CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.04

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by inserting at beginning of file or create a new file in the context of the Data Server potentially leading to remote code execution when…

  • CVE-2022-24310CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.02

    A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Product: Interactive Graphical…

  • CVE-2022-22813CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.01

    A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the Courier tunneling communication network, they could potentially observe and manipulate traffic associated with product…

  • CVE-2022-22810CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.01

    A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk)…

  • CVE-2022-22544CriFeb 9, 2022
    risk 0.59cvss 9.1epss 0.01

    Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents and browse files on their systems. An attacker could thereby control the managed systems. It is considered that this is a missing…

  • CVE-2022-22536CriKEVFeb 9, 2022
    risk 0.88cvss 10.0epss 0.98

    SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary…

  • CVE-2022-22532CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.02

    In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an unauthenticated attacker could submit a crafted HTTP server request which triggers improper shared memory buffer handling. This…

  • CVE-2021-39997CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a vulnerability of unstrict input parameter verification in the audio assembly.Successful exploitation of this vulnerability may cause out-of-bounds access.

  • CVE-2021-39994CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.01

    There is an arbitrary address access vulnerability with the product line test code.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

  • CVE-2022-23631CriFeb 9, 2022
    risk 0.59cvss 9.0epss 0.02

    superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.1 superjson allows input to run arbitrary code on any server using superjson input without prior authentication or knowledge. The only requirement is that the…

  • CVE-2021-36302CriFeb 9, 2022
    risk 0.64cvss 9.9epss 0.01

    All Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability. A remote malicious user with standard level JEA credentials may potentially exploit this vulnerability to elevate privileges and take over the system.

  • CVE-2021-45331CriFeb 9, 2022
    risk 0.00cvss 9.8epss 0.01

    An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.

  • CVE-2021-45330CriFeb 9, 2022
    risk 0.00cvss 9.8epss 0.01

    An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.

  • CVE-2022-0525CriFeb 9, 2022
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in Homebrew mruby prior to 3.2.

  • CVE-2022-24677CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.02

    Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php.

  • CVE-2022-0139CriFeb 8, 2022
    risk 0.00cvss 9.8epss 0.01

    Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.

  • CVE-2021-45327CriFeb 8, 2022
    risk 0.57cvss 9.8epss 0.02

    Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.

  • CVE-2022-23340CriFeb 8, 2022
    risk 0.57cvss 9.8epss 0.02

    Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results.

  • CVE-2022-21241CriFeb 8, 2022
    risk 0.63cvss 9.6epss 0.03

    Cross-site scripting vulnerability in CSV+ prior to 0.8.1 allows a remote unauthenticated attacker to inject an arbitrary script or an arbitrary OS command via a specially crafted CSV file that contains HTML a tag.

  • CVE-2021-42833CriFeb 7, 2022
    risk 0.60cvss 9.3epss 0.00

    A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manipulate users and system settings.

  • CVE-2021-25114CriFeb 7, 2022
    risk 0.63cvss 9.8epss 0.82

    The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection