VYPR

CVEs

38,096 total · page 416 of 762

  • CVE-2022-47121CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey parameter at /goform/WifiBasicSet.

  • CVE-2022-47120CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.

  • CVE-2022-47119CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the ssid parameter at /goform/WifiBasicSet.

  • CVE-2022-47118CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey1 parameter at /goform/WifiBasicSet.

  • CVE-2022-47117CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security parameter at /goform/WifiBasicSet.

  • CVE-2022-47115CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepauth parameter at /goform/WifiBasicSet.

  • CVE-2022-46601CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setbg_num parameter in the icp_setbg_img (sub_41DD68) function.

  • CVE-2022-46600CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_24g function.

  • CVE-2022-46599CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setlogo_num parameter in the icp_setlogo_img (sub_41DBF4) function.

  • CVE-2022-46598CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.02

    TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_5g function.

  • CVE-2022-46597CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.02

    TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function.

  • CVE-2022-46596CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the del_num parameter in the icp_delete_img (sub_41DEDC) function.

  • CVE-2022-46594CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the update_file_name parameter in the auto_up_fw (sub_420A04) function.

  • CVE-2022-46593CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the do_sta_enrollee_wifi function.

  • CVE-2022-46592CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the set_sta_enrollee_pin_5g function.

  • CVE-2022-46591CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reject_url parameter in the reject (sub_41BD60) function.

  • CVE-2022-46590CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_rsname parameter in the tools_netstat (sub_41E730) function.

  • CVE-2022-46589CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_option parameter in the tools_netstat (sub_41E730) function.

  • CVE-2022-46588CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the sys_service parameter in the setup_wizard_mydlink (sub_4104B8) function.

  • CVE-2022-46586CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_allow (sub_415B00) function.

  • CVE-2022-46585CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the REMOTE_USER parameter in the get_access (sub_45AC2C) function.

  • CVE-2022-46584CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_deny (sub_415D7C) function.

  • CVE-2022-46583CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reboot_type parameter in the wizard_ipv6 (sub_41C380) function.

  • CVE-2022-46582CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the login_name parameter in the do_graph_auth (sub_4061E0) function.

  • CVE-2022-46581CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.nslookup_target parameter in the tools_nslookup function.

  • CVE-2022-46580CriDec 30, 2022
    risk 0.64cvss 9.8epss 0.01

    TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the user_edit_page parameter in the wifi_captive_portal function.

  • CVE-2022-44621CriDec 30, 2022
    risk 0.57cvss 9.8epss 0.03

    Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.

  • CVE-2022-36437CriDec 29, 2022
    risk 0.59cvss 9.1epss 0.01

    The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and…

  • CVE-2022-46179CriDec 28, 2022
    risk 0.00cvss 9.2epss 0.00

    LiuOS is a small Python project meant to imitate the functions of a regular operating system. Version 0.1.0 and prior of LiuOS allow an attacker to set the GITHUB_ACTIONS environment variable to anything other than null or true and skip authentication checks. This issue is…

  • CVE-2022-23555CriDec 28, 2022
    risk 0.61cvss 9.4epss 0.01

    authentik is an open-source Identity Provider focused on flexibility and versatility. Versions prior to 2022.11.4 and 2022.10.4 are vulnerable to Improper Authentication. Token reuse in invitation URLs leads to access control bypass via the use of a different enrollment flow…

  • CVE-2022-46442CriDec 27, 2022
    risk 0.64cvss 9.8epss 0.01

    dedecms <=V5.7.102 is vulnerable to SQL Injection. In sys_ sql_ n query.php there are no restrictions on the sql query.

  • CVE-2022-45963CriDec 27, 2022
    risk 0.64cvss 9.8epss 0.01

    h3c firewall <= 3.10 ESS6703 has a privilege bypass vulnerability.

  • CVE-2022-45778CriDec 27, 2022
    risk 0.64cvss 9.8epss 0.01

    https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect Access Control. There is a permission bypass vulnerability in the Hillstone WEB application firewall. An attacker can enter the background of the firewall with super administrator…

  • CVE-2021-4238CriDec 27, 2022
    risk 0.52cvss 9.1epss 0.01

    Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short…

  • CVE-2021-4236CriDec 27, 2022
    risk 0.57cvss 9.8epss 0.01

    Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. This issue only affects WebSockets with an AuthenticateMethod hook. Request…

  • CVE-2020-36569CriDec 27, 2022
    risk 0.52cvss 9.1epss 0.01

    Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.

  • CVE-2020-36566CriDec 27, 2022
    risk 0.52cvss 9.1epss 0.01

    Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

  • CVE-2020-36561CriDec 27, 2022
    risk 0.52cvss 9.1epss 0.01

    Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

  • CVE-2020-36560CriDec 27, 2022
    risk 0.52cvss 9.1epss 0.01

    Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

  • CVE-2018-25046CriDec 27, 2022
    risk 0.52cvss 9.1epss 0.01

    Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

  • CVE-2017-20146CriDec 27, 2022
    risk 0.57cvss 9.8epss 0.01

    Usage of the CORS handler may apply improper CORS headers, allowing the requester to explicitly control the value of the Access-Control-Allow-Origin header, which bypasses the expected behavior of the Same Origin Policy.

  • CVE-2014-125026CriDec 27, 2022
    risk 0.57cvss 9.8epss 0.01

    LZ4 bindings use a deprecated C API that is vulnerable to memory corruption, which could lead to arbitrary code execution if called with untrusted user input.

  • CVE-2022-4724CriDec 27, 2022
    risk 0.57cvss 9.8epss 0.01

    Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.

  • CVE-2022-4719CriDec 27, 2022
    risk 0.57cvss 9.8epss 0.01

    Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5.

  • CVE-2022-46764CriDec 27, 2022
    risk 0.64cvss 9.8epss 0.02

    A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution.

  • CVE-2020-24600CriDec 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Shilpi CAPExWeb 1.1 allows SQL injection via a servlet/capexweb.cap_sendMail GET request.

  • CVE-2019-11851CriDec 26, 2022
    risk 0.64cvss 9.8epss 0.02

    The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x before 4.14.0 allows remote attackers to execute arbitrary code via a buffer overflow.

  • CVE-2020-11101CriDec 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Sierra Wireless AirLink Mobility Manager (AMM) before 2.17 mishandles sessions and thus an unauthenticated attacker can obtain a login session with administrator privileges.

  • CVE-2022-4120CriDec 26, 2022
    risk 0.65cvss 9.8epss 0.18

    The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the unserialize() PHP function when CAPTCHA are used as second challenge, which could lead to PHP Object injection if a plugin installed on the blog…

  • CVE-2022-4117CriDec 26, 2022
    risk 0.64cvss 9.8epss 0.05

    The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection.