VYPR

CVEs

38,096 total · page 425 of 762

  • CVE-2022-3574CriNov 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.

  • CVE-2022-3477CriNov 14, 2022
    risk 0.64cvss 9.8epss 0.04

    The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their…

  • CVE-2022-45378CriNov 14, 2022
    risk 0.64cvss 9.8epss 0.02

    In the default configuration of Apache SOAP, an RPCRouterServlet is available without authentication. This gives an attacker the possibility to invoke methods on the classpath that meet certain criteria. Depending on what classes are available on the classpath this might even…

  • CVE-2022-38652CriNov 12, 2022
    risk 0.64cvss 9.9epss 0.01

    A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host operating system with the privileges of…

  • CVE-2022-38651CriNov 12, 2022
    risk 0.64cvss 9.8epss 0.01

    A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects products that are no…

  • CVE-2022-38650CriNov 12, 2022
    risk 0.65cvss 10.0epss 0.01

    A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to run arbitrary code or malware within Hyperic Server and the host operating system with the privileges of the…

  • CVE-2022-43672CriNov 12, 2022
    risk 0.69cvss 9.8epss 0.67

    Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.

  • CVE-2022-43671CriNov 12, 2022
    risk 0.70cvss 9.8epss 0.75

    Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.

  • CVE-2022-45182CriNov 11, 2022
    risk 0.00cvss 9.8epss 0.01

    Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.

  • CVE-2022-36938CriNov 11, 2022
    risk 0.00cvss 9.8epss 0.01

    DexLoader function get_stringidx_fromdex() in Redex prior to commit 3b44c64 can load an out of bound address when loading the string index table, potentially allowing remote code execution during processing of a 3rd party Android APK file.

  • CVE-2022-43074CriNov 10, 2022
    risk 0.64cvss 9.8epss 0.01

    AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-39395CriNov 10, 2022
    risk 0.55cvss 9.6epss 0.01

    Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela Server and Vela Worker prior to version 0.16.0 and Vela UI prior to version 0.17.0, some default configurations for Vela allow exploitation and container breakouts.…

  • CVE-2022-44727CriNov 10, 2022
    risk 0.59cvss 9.1epss 0.03

    The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ).

  • CVE-2022-45063CriNov 10, 2022
    risk 0.57cvss 9.8epss 0.05

    xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.

  • CVE-2022-44089CriNov 10, 2022
    risk 0.64cvss 9.8epss 0.02

    ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.

  • CVE-2022-44088CriNov 10, 2022
    risk 0.65cvss 9.8epss 0.20

    ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.

  • CVE-2022-44087CriNov 10, 2022
    risk 0.64cvss 9.8epss 0.02

    ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.

  • CVE-2022-39036CriNov 10, 2022
    risk 0.64cvss 9.8epss 0.01

    The file upload function of Agentflow BPM has insufficient filtering for special characters in URLs. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary file and execute arbitrary code to manipulate system or disrupt service.

  • CVE-2022-38119CriNov 10, 2022
    risk 0.64cvss 9.8epss 0.01

    UPSMON Pro login function has insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and get administrator privilege to access, control system or disrupt service.

  • CVE-2022-39396CriNov 10, 2022
    risk 0.60cvss 9.8epss 0.39

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnerable to Remote Code Execution via prototype pollution. An attacker can use this prototype pollution…

  • CVE-2022-44562CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.

  • CVE-2022-44559CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.

  • CVE-2022-44558CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation.

  • CVE-2022-44551CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.00

    The iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.

  • CVE-2022-43058CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity.

  • CVE-2022-31689CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.

  • CVE-2022-31687CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.

  • CVE-2022-31686CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.

  • CVE-2022-31685CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.

  • CVE-2021-46851CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video playback.

  • CVE-2022-25932CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    The firmware of InHand Networks InRouter302 V3.5.45 introduces fixes for TALOS-2022-1472 and TALOS-2022-1474. The fixes are incomplete. An attacker can still perform, respectively, a privilege escalation and an information disclosure vulnerability.

  • CVE-2021-34569CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.01

    In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory.

  • CVE-2021-34566CriNov 9, 2022
    risk 0.59cvss 9.1epss 0.01

    In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.

  • CVE-2022-45062CriNov 9, 2022
    risk 0.00cvss 9.8epss 0.01

    In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.

  • CVE-2022-40797CriNov 9, 2022
    risk 0.64cvss 9.8epss 0.03

    Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)

  • CVE-2022-3890CriNov 9, 2022
    risk 0.62cvss 9.6epss 0.01

    Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-39328CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load.…

  • CVE-2022-37015CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are…

  • CVE-2022-34825CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated…

  • CVE-2022-34824CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote…

  • CVE-2022-34823CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated…

  • CVE-2022-34822CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlier allows a remote unauthenticated…

  • CVE-2022-27510CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Unauthorized access to Gateway user capabilities

  • CVE-2022-33321CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob,…

  • CVE-2022-44457CriNov 8, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions < V1.17.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.0 < V1.17.2), Mendix SAML (Mendix 8 compatible) (All versions < V2.3.0), Mendix SAML (Mendix 8 compatible) (All versions >=…

  • CVE-2022-43546CriNov 8, 2022
    risk 0.64cvss 9.9epss 0.02

    A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), SICAM P850 (All versions < V3.10), SICAM P850 (All…

  • CVE-2022-43545CriNov 8, 2022
    risk 0.64cvss 9.9epss 0.01

    A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versions < V2.50), SICAM P850 (All versions < V3.10), SICAM P850 (All…

  • CVE-2022-43439CriNov 8, 2022
    risk 0.64cvss 9.9epss 0.02

    A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions < V2.50), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions < V2.50), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (All versions < V2.50), POWER METER SICAM Q100…

  • CVE-2022-31199CriKEVNov 8, 2022
    risk 0.85cvss 9.8epss 0.36

    Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by…

  • CVE-2022-44054CriNov 7, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-utility package. The affected version of d8s-htm is 0.1.0.