VYPR

CVEs

38,098 total · page 415 of 762

  • CVE-2022-38490CriJan 10, 2023
    risk 0.62cvss 9.6epss 0.01

    An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 corrects this issue.

  • CVE-2022-4422CriJan 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Call Center System developed by Bulutses Information Technologies before version 3.0 has an unauthenticated Sql Injection vulnerability. This has been fixed in the version 3.0

  • CVE-2022-3792CriJan 10, 2023
    risk 0.65cvss 9.8epss 0.14

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in GullsEye GullsEye terminal operating system allows SQL Injection. This issue affects GullsEye terminal operating system: from unspecified before 5.0.13.

  • CVE-2022-46823CriJan 10, 2023
    risk 0.60cvss 9.3epss 0.00

    A vulnerability has been identified in Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.3.4), Mendix SAML (Mendix 9 compatible, New Track) (All versions >= V3.3.0 < V3.3.9), Mendix SAML (Mendix 9 compatible, Upgrade Track) (All versions >= V3.3.0 < V3.3.8). The…

  • CVE-2022-45092CriJan 10, 2023
    risk 0.67cvss 9.9epss 0.31

    A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially read and write arbitrary files from and to the device's file system.…

  • CVE-2023-22903CriJan 10, 2023
    risk 0.00cvss 9.8epss 0.01

    api/views/user.py in LibrePhotos before e19e539 has incorrect access control.

  • CVE-2017-20166CriJan 10, 2023
    risk 0.57cvss 9.8epss 0.01

    Ecto 2.2.0 lacks a certain protection mechanism associated with the interaction between is_nil and raise.

  • CVE-2023-0022CriJan 10, 2023
    risk 0.64cvss 9.9epss 0.01

    SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may completely compromise…

  • CVE-2023-0018CriJan 10, 2023
    risk 0.65cvss 10.0epss 0.01

    Due to improper input sanitization of user-controlled input in SAP BusinessObjects Business Intelligence Platform CMC application - versions 420, and 430, an attacker with basic user-level privileges can modify/upload crystal reports containing a malicious payload. Once these…

  • CVE-2023-0017CriJan 10, 2023
    risk 0.62cvss 9.4epss 0.16

    An unauthenticated attacker in SAP NetWeaver AS for Java - version 7.50, due to improper access control, can attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and…

  • CVE-2023-0016CriJan 10, 2023
    risk 0.64cvss 9.9epss 0.01

    SAP BPC MS 10.0 - version 810, allows an unauthorized attacker to execute crafted database queries. The exploitation of this issue could lead to SQL injection vulnerability and could allow an attacker to access, modify, and/or delete data from the backend database.

  • CVE-2023-0014CriJan 10, 2023
    risk 0.59cvss 9.0epss 0.01

    SAP NetWeaver ABAP Server and ABAP Platform - versions SAP_BASIS 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, KERNEL 7.22, 7.53, 7.77, 7.81, 7.85, 7.89, KRNL64UC 7.22, 7.22EXT, 7.53, KRNL64NUC 7.22, 7.22EXT, creates information about system…

  • CVE-2022-47790CriJan 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Dynamic Transaction Queuing System v1.0 is vulnerable to SQL Injection via /queuing/index.php?page=display&id=.

  • CVE-2022-33219CriJan 9, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Automotive due to integer overflow to buffer overflow while registering a new listener with shared buffer.

  • CVE-2022-22088CriJan 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory corruption in Bluetooth HOST due to buffer overflow while parsing the command response received from remote

  • CVE-2022-39073CriJan 6, 2023
    risk 0.64cvss 9.8epss 0.03

    There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.

  • CVE-2023-22671CriJan 6, 2023
    risk 0.00cvss 9.8epss 0.03

    Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when calling analyzeHeadless with untrusted input.

  • CVE-2022-44877CriKEVJan 5, 2023
    risk 0.87cvss 9.8epss 1.00

    login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.

  • CVE-2022-47544CriJan 5, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Siren Investigate before 12.1.7. Script variable whitelisting is insufficiently sandboxed.

  • CVE-2022-45995CriJan 5, 2023
    risk 0.64cvss 9.8epss 0.01

    There is an unauthorized buffer overflow vulnerability in Tenda AX12 v22.03.01.21 _ cn. This vulnerability can cause the web service not to restart or even execute arbitrary code. It is a different vulnerability from CVE-2022-2414.

  • CVE-2022-47523CriJan 5, 2023
    risk 0.69cvss 9.8epss 0.71

    Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.

  • CVE-2023-22463CriJan 4, 2023
    risk 0.62cvss 9.8epss 0.70

    KubePi is a k8s panel. The jwt authentication function of KubePi through version 1.6.2 uses hard-coded Jwtsigkeys, resulting in the same Jwtsigkeys for all online projects. This means that an attacker can forge any jwt token to take over the administrator account of any online…

  • CVE-2023-22457CriJan 4, 2023
    risk 0.53cvss 9.0epss 0.19

    CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a protection against Cross-Site Request Forgery (CSRF), allowing to execute macros with the rights of the current user. If a…

  • CVE-2022-45875CriJan 4, 2023
    risk 0.64cvss 9.8epss 0.03

    Improper validation of script alert plugin parameters in Apache DolphinScheduler to avoid remote command execution vulnerability. This issue affects Apache DolphinScheduler version 3.0.1 and prior versions; version 3.1.0 and prior versions. This attack can be performed only by…

  • CVE-2022-38627CriJan 3, 2023
    risk 0.64cvss 9.8epss 0.04

    Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter.

  • CVE-2022-32665CriJan 3, 2023
    risk 0.64cvss 9.8epss 0.02

    In Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20220026; Issue ID: OSBNB00144124.

  • CVE-2021-32824CriJan 3, 2023
    risk 0.64cvss 9.8epss 0.03

    Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service port can be used to access a Telnet Handler which offers…

  • CVE-2022-43931CriJan 3, 2023
    risk 0.66cvss 10.0epss 0.17

    Out-of-bounds write vulnerability in Remote Desktop Functionality in Synology VPN Plus Server before 1.4.3-0534 and 1.4.4-0635 allows remote attackers to execute arbitrary commands via unspecified vectors.

  • CVE-2022-47618CriJan 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Merit LILIN AH55B04 & AH55B08 DVR firm has hard-coded administrator credentials. An unauthenticated remote attacker can use these credentials to log in administrator page, to manipulate system or disrupt service.

  • CVE-2022-39042CriJan 3, 2023
    risk 0.64cvss 9.8epss 0.01

    aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system command or disrupt service.

  • CVE-2022-39041CriJan 3, 2023
    risk 0.64cvss 9.8epss 0.01

    aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.

  • CVE-2022-39039CriJan 3, 2023
    risk 0.64cvss 9.8epss 0.01

    aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.

  • CVE-2022-4357CriJan 2, 2023
    risk 0.64cvss 9.8epss 0.01

    The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

  • CVE-2022-4298CriJan 2, 2023
    risk 0.64cvss 9.8epss 0.02

    The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

  • CVE-2022-4297CriJan 2, 2023
    risk 0.67cvss 9.8epss 0.04

    The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX available to unauthenticated users, leading to an unauthenticated SQL injection

  • CVE-2022-4099CriJan 2, 2023
    risk 0.64cvss 9.8epss 0.01

    The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using them in SQL statements accessible to unauthenticated users, leading to unauthenticated SQL injection

  • CVE-2022-4059CriJan 2, 2023
    risk 0.64cvss 9.8epss 0.05

    The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

  • CVE-2022-4049CriJan 2, 2023
    risk 0.64cvss 9.8epss 0.05

    The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

  • CVE-2022-3241CriJan 2, 2023
    risk 0.64cvss 9.8epss 0.01

    The Build App Online WordPress plugin before 1.0.19 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

  • CVE-2022-42475CriKEVJan 2, 2023
    risk 0.90cvss 9.8epss 0.99

    A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated…

  • CVE-2022-34322CriJan 1, 2023
    risk 0.59cvss 9.0epss 0.01

    Multiple XSS issues were discovered in Sage Enterprise Intelligence 2021 R1.1 that allow an attacker to execute JavaScript code in the context of users' browsers. The attacker needs to be authenticated to reach the vulnerable features. An issue is present in the Notify Users…

  • CVE-2022-48198CriJan 1, 2023
    risk 0.64cvss 9.8epss 0.01

    The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. This occurs because a topic name depends on the…

  • CVE-2022-4866CriDec 31, 2022
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-4865CriDec 31, 2022
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

  • CVE-2022-48195CriDec 31, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Mellium mellium.im/sasl before 0.3.1. When performing SCRAM-based SASL authentication, if the remote end advertises support for channel binding, no random nonce is generated (instead, the nonce is empty). This causes authentication to fail in the best…

  • CVE-2022-47128CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey2 parameter at /goform/WifiBasicSet.

  • CVE-2022-47127CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlPwd parameter at /goform/WifiBasicSet.

  • CVE-2022-47126CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlEn parameter at /goform/WifiBasicSet.

  • CVE-2022-47125CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wrlEn_5g parameter at /goform/WifiBasicSet.

  • CVE-2022-47124CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey4 parameter at /goform/WifiBasicSet.