VYPR

CVEs

38,096 total · page 419 of 762

  • CVE-2022-37832CriDec 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Mutiny 7.2.0-10788 suffers from Hardcoded root password.

  • CVE-2021-38241CriDec 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.

  • CVE-2021-31650CriDec 16, 2022
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in Sourcecodester Online Grading System 1.0 allows remote attackers to execute arbitrary SQL commands via the uname parameter.

  • CVE-2022-45796CriDec 16, 2022
    risk 0.59cvss 9.1epss 0.03

    Command injection vulnerability in nw_interface.html in SHARP multifunction printers (MFPs)'s Digital Full-color Multifunctional System 202 or earlier, 120 or earlier, 600 or earlier, 121 or earlier, 500 or earlier, 402 or earlier, 790 or earlier, and Digital Multifunctional…

  • CVE-2022-42529CriDec 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A

  • CVE-2022-47377CriDec 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Password recovery vulnerability in SICK SIM2000ST Partnumber 2086502 with firmware version <1.13.4 allows an unprivileged remote attacker to gain access to the userlevel defined as RecoverableUserLevel by invocating the password recovery mechanism method. This leads to an…

  • CVE-2022-46393CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX.

  • CVE-2022-45969CriDec 15, 2022
    risk 0.57cvss 9.8epss 0.01

    Alist v3.4.0 is vulnerable to Directory Traversal,

  • CVE-2022-40004CriDec 15, 2022
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting (XSS) vulnerability in Things Board 3.4.1 allows remote attackers to escalate privilege via crafted URL to the Audit Log.

  • CVE-2022-46634CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiWpsCfg function.

  • CVE-2022-46631CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiSignalCfg function.

  • CVE-2022-44588CriDec 15, 2022
    risk 0.65cvss 9.9epss 0.02

    Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.

  • CVE-2022-44236CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Beijing Zed-3 Technologies Co.,Ltd VoIP simpliclty ASG 8.5.0.17807 (20181130-16:12) has a Weak password vulnerability.

  • CVE-2022-42842CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.02

    The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.

  • CVE-2022-42837CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, watchOS 9.2. A remote user may be able to cause unexpected app termination or…

  • CVE-2021-4226CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.01

    RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to the way it is implemented.

  • CVE-2021-39426CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter when the action parameter equals set.

  • CVE-2021-33420CriDec 15, 2022
    risk 0.57cvss 9.8epss 0.02

    A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable function in TypedArray object.

  • CVE-2022-32573CriDec 15, 2022
    risk 0.65cvss 9.9epss 0.04

    A directory traversal vulnerability exists in the AssetActions.aspx addDoc functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-29517CriDec 15, 2022
    risk 0.69cvss 9.9epss 0.58

    A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-47411CriDec 14, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via unsubscribeAction operations.

  • CVE-2022-47410CriDec 14, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via createAction operations.

  • CVE-2022-47409CriDec 14, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Attackers can unsubscribe everyone via a series of modified subscription UIDs in deleteAction…

  • CVE-2022-47408CriDec 14, 2022
    risk 0.52cvss 9.1epss 0.01

    An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. There is a CAPTCHA bypass that can lead to subscribing many people.

  • CVE-2022-38488CriDec 14, 2022
    risk 0.65cvss 9.8epss 0.14

    logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter.

  • CVE-2022-31702CriDec 14, 2022
    risk 0.64cvss 9.8epss 0.02

    vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication.

  • CVE-2022-46255CriDec 14, 2022
    risk 0.64cvss 9.8epss 0.02

    An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. A check was added within Pages to ensure the working directory is clean before unpacking new content to prevent an…

  • CVE-2022-46072CriDec 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection.

  • CVE-2022-46071CriDec 14, 2022
    risk 0.64cvss 9.8epss 0.04

    There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.

  • CVE-2022-46997CriDec 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

  • CVE-2022-46996CriDec 14, 2022
    risk 0.64cvss 9.8epss 0.01

    vSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

  • CVE-2022-46609CriDec 14, 2022
    risk 0.00cvss 9.8epss 0.01

    Python3-RESTfulAPI commit d9907f14e9e25dcdb54f5b22252b0e9452e3970e and e772e0beee284c50946e94c54a1d43071ca78b74 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital…

  • CVE-2022-44832CriDec 14, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function.

  • CVE-2022-31358CriDec 14, 2022
    risk 0.59cvss 9.0epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/.

  • CVE-2022-41653CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to an attacker obtaining user login credentials and control the system.

  • CVE-2022-2757CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Due to the lack of adequately implemented access-control rules, all versions Kingspan TMS300 CS are vulnerable to an attacker viewing and modifying the application settings without authenticating by accessing a specific uniform resource locator (URL) on the webserver.

  • CVE-2022-2660CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Industrial Automation DIALink versions 1.4.0.0 and prior are vulnerable to the use of a hard-coded cryptographic key which could allow an attacker to decrypt sensitive data and compromise the machine.

  • CVE-2022-46404CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Manager (8 before R2.22.18, 10 before 0.28.13, and 10 R1 before R1.34.4) that may allow an unauthenticated attacker to upload arbitrary files and achieve…

  • CVE-2022-45005CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.05

    IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output function.

  • CVE-2022-41563CriDec 13, 2022
    risk 0.59cvss 9.0epss 0.01

    The Dashboard component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for…

  • CVE-2022-41561CriDec 13, 2022
    risk 0.59cvss 9.1epss 0.01

    The JNDI Data Sources component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports…

  • CVE-2022-46364CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.02

    A SSRF vulnerability in parsing the href attribute of XOP:Include in MTOM requests in versions of Apache CXF before 3.5.5 and 3.4.10 allows an attacker to perform SSRF style attacks on webservices that take at least one parameter of any type. 

  • CVE-2022-27518CriKEVDec 13, 2022
    risk 0.76cvss 9.8epss 0.07

    Unauthenticated remote arbitrary code execution

  • CVE-2022-46353CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All…

  • CVE-2022-43724CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0). Affected software transmits the database credentials for the inbuilt SQL server in cleartext. In combination with the by default enabled xp_cmdshell feature unauthenticated remote attackers could execute…

  • CVE-2022-20473CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.09

    In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20472CriDec 13, 2022
    risk 0.64cvss 9.8epss 0.07

    In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-4446CriDec 13, 2022
    risk 0.00cvss 9.8epss 0.01

    PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.

  • CVE-2022-41272CriDec 13, 2022
    risk 0.64cvss 9.9epss 0.01

    An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to access services which can be used to…

  • CVE-2022-41271CriDec 13, 2022
    risk 0.61cvss 9.4epss 0.01

    An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Process Integration (PI) - version 7.50. This user can make use of an open naming and directory API to access services that could perform unauthorized…