VYPR

CVEs

38,096 total · page 421 of 762

  • CVE-2022-30123CriDec 5, 2022
    risk 0.58cvss 10.0epss 0.02

    A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.

  • CVE-2022-27773CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.03

    A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated privileges.

  • CVE-2022-46169CriKEVDec 5, 2022
    risk 0.23cvss 9.8epss 1.00

    Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if…

  • CVE-2022-46164CriDec 5, 2022
    risk 0.58cvss 9.4epss 0.47

    NodeBB is an open source Node.js based forum software. Due to a plain object with a prototype being used in socket.io message handling a specially crafted payload can be used to impersonate other users and takeover accounts. This vulnerability has been patched in version 2.6.1.…

  • CVE-2022-45481CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.02

    The default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute arbitrary code with no prior authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • CVE-2022-45479CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.02

    PC Keyboard allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • CVE-2022-44039CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.01

    Franklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker can overwrite system files like [system.conf] and [passwd], this occurs because the insecure usage of "fopen" system function with…

  • CVE-2022-45477CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.02

    Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • CVE-2022-45822CriDec 5, 2022
    risk 0.65cvss 10.0epss 0.01

    Unauth. SQL Injection (SQLi) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress.

  • CVE-2022-42496CriDec 5, 2022
    risk 0.64cvss 9.8epss 0.02

    OS command injection vulnerability in Nako3edit, editor component of nadesiko3 (PC Version) v3.3.74 and earlier allows a remote attacker to obtain appkey of the product and execute an arbitrary OS command on the product.

  • CVE-2022-41642CriDec 5, 2022
    risk 0.57cvss 9.8epss 0.02

    OS command injection vulnerability in Nadesiko3 (PC Version) v3.3.61 and earlier allows a remote attacker to execute an arbitrary OS command when processing compression and decompression on the product.

  • CVE-2022-35508CriDec 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on…

  • CVE-2022-46414CriDec 4, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal.

  • CVE-2022-44945CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the heading_field_id parameter.

  • CVE-2022-44291CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.04

    webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.

  • CVE-2022-44290CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.04

    webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.

  • CVE-2022-2641CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow an attacker to perform unauthorized changes to the device, remotely execute arbitrary code, or cause a denial-of-service condition.

  • CVE-2022-3520CriDec 2, 2022
    risk 0.00cvss 9.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.

  • CVE-2022-44367CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setUplinkInfo.

  • CVE-2022-44366CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.10

    Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setDiagnoseInfo.

  • CVE-2022-44365CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda i21 V1.0.0.14(4656) has a stack overflow vulnerability via /goform/setSysPwd.

  • CVE-2022-44363CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setSnmpInfo.

  • CVE-2022-44362CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/AddSysLogRule.

  • CVE-2022-45482CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execute arbitrary commands. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  • CVE-2022-46366CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.04

    Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version…

  • CVE-2022-2807CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Algan Software Prens Student Information System allows SQL Injection. This issue affects Prens Student Information System: before 2.1.11.

  • CVE-2022-44930CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.03

    D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.

  • CVE-2022-44929CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.01

    An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.

  • CVE-2022-44928CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.03

    D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.

  • CVE-2022-43325CriDec 2, 2022
    risk 0.64cvss 9.8epss 0.06

    An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input.

  • CVE-2022-43333CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.02

    Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_control.php.

  • CVE-2022-37016CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.01

    Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an…

  • CVE-2022-30528CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to execute arbitrary commands via the username parameter to /system/user/modules/mod_users/controller.php.

  • CVE-2022-3270CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.01

    In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.

  • CVE-2022-4221CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.05

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Asus NAS-M25 allows an unauthenticated attacker to inject arbitrary OS commands via unsanitized cookie values.This issue affects NAS-M25: through 1.0.1.7.

  • CVE-2022-36431CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.

  • CVE-2022-44262CriDec 1, 2022
    risk 0.57cvss 9.8epss 0.02

    ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).

  • CVE-2022-44151CriNov 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.

  • CVE-2022-44136CriNov 30, 2022
    risk 0.57cvss 9.8epss 0.01

    Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).

  • CVE-2022-44097CriNov 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

  • CVE-2022-44096CriNov 30, 2022
    risk 0.64cvss 9.8epss 0.01

    Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

  • CVE-2022-3751CriNov 29, 2022
    risk 0.57cvss 9.8epss 0.01

    SQL Injection in GitHub repository owncast/owncast prior to 0.0.13.

  • CVE-2022-44354CriNov 29, 2022
    risk 0.64cvss 9.8epss 0.02

    SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.

  • CVE-2022-44038CriNov 29, 2022
    risk 0.64cvss 9.8epss 0.02

    Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunner.cgi component.

  • CVE-2022-42109CriNov 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.

  • CVE-2022-44399CriNov 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Poultry Farm Management System v1.0 contains a SQL injection vulnerability via the del parameter at /Redcock-Farm/farm/category.php.

  • CVE-2022-44401CriNov 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.

  • CVE-2022-44400CriNov 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.

  • CVE-2022-44283CriNov 28, 2022
    risk 0.64cvss 9.8epss 0.01

    AVS Audio Converter 10.3 is vulnerable to Buffer Overflow.

  • CVE-2022-41912CriNov 28, 2022
    risk 0.52cvss 9.1epss 0.02

    The crewjam/saml go library prior to version 0.4.9 is vulnerable to an authentication bypass when processing SAML responses containing multiple Assertion elements. This issue has been corrected in version 0.4.9. There are no workarounds other than upgrading to a fixed version.