VYPR

CVEs

38,096 total · page 428 of 762

  • CVE-2022-40876CriOct 27, 2022
    risk 0.64cvss 9.8epss 0.02

    In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE).

  • CVE-2022-3386CriOct 27, 2022
    risk 0.64cvss 9.8epss 0.01

    Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can use an outsized filename to overflow the stack buffer and enable remote code execution.

  • CVE-2022-3385CriOct 27, 2022
    risk 0.64cvss 9.8epss 0.01

    Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stack buffer and enable remote code execution.

  • CVE-2022-39976CriOct 27, 2022
    risk 0.64cvss 9.8epss 0.01

    School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=.

  • CVE-2022-43367CriOct 27, 2022
    risk 0.64cvss 9.8epss 0.05

    IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.

  • CVE-2022-3095CriOct 27, 2022
    risk 0.64cvss 9.8epss 0.01

    The implementation of backslash parsing in the Dart URI class for versions prior to 2.18 and Flutter versions prior to 3.30 differs from the WhatWG URL standards. Dart uses the RFC 3986 syntax, which creates incompatibilities with the '\' characters in URIs, which can lead to…

  • CVE-2022-39365CriOct 27, 2022
    risk 0.57cvss 9.8epss 0.02

    Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout\Text` is vulnerable to server-side template injection, which could lead to remote code execution.…

  • CVE-2022-2782CriOct 27, 2022
    risk 0.59cvss 9.1epss 0.01

    In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the session token parameters.

  • CVE-2022-3363CriOct 26, 2022
    risk 0.57cvss 9.8epss 0.01

    Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.0a7.

  • CVE-2022-39355CriOct 26, 2022
    risk 0.00cvss 9.1epss 0.01

    Discourse Patreon enables syncronization between Discourse Groups and Patreon rewards. On sites with Patreon login enabled, an improper authentication vulnerability could be used to take control of a victim's forum account. This vulnerability is patched in commit number…

  • CVE-2022-43003CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecurity function.

  • CVE-2022-43002CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep54_pskpwd parameter at /goform/form2WizardStep54.

  • CVE-2022-43001CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity function.

  • CVE-2022-43000CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/form2WizardStep4.

  • CVE-2022-42998CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the srcip parameter at /goform/form2IPQoSTcAdd.

  • CVE-2022-43775CriOct 26, 2022
    risk 0.65cvss 9.8epss 0.21

    The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.

  • CVE-2022-43774CriOct 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.

  • CVE-2022-42468CriOct 26, 2022
    risk 0.57cvss 9.8epss 0.03

    Apache Flume versions 1.4.0 through 1.10.1 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with an unsafe providerURL. This issue is fixed by limiting JNDI to allow only the use of the java protocol or no protocol.

  • CVE-2022-2422CriOct 26, 2022
    risk 0.58cvss 10.0epss 0.01

    Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the back-end database, in case the feathers-sequelize package is used.

  • CVE-2022-2421CriOct 26, 2022
    risk 0.58cvss 10.0epss 0.01

    Due to improper type validation in attachment parsing the Socket.io js library, it is possible to overwrite the _placeholder object which allows an attacker to place references to functions at arbitrary places in the resulting query object.

  • CVE-2022-29823CriOct 26, 2022
    risk 0.58cvss 10.0epss 0.02

    Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This results in a Remote Code Execution (RCE) with privileges of application.

  • CVE-2022-29822CriOct 26, 2022
    risk 0.58cvss 10.0epss 0.01

    Due to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection

  • CVE-2022-41711CriOct 25, 2022
    risk 0.57cvss 9.8epss 0.02

    Badaso version 2.6.0 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate the data uploaded by users.

  • CVE-2022-36452CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the web conferencing component of Mitel MiCollab through 9.5.0.101 could allow an unauthenticated attacker to upload malicious files. A successful exploit could allow an attacker to execute arbitrary code within the context of the application.

  • CVE-2022-3393CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection

  • CVE-2022-39345CriOct 25, 2022
    risk 0.57cvss 9.8epss 0.01

    Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin prior to 2.5.4 is vulnerable to path traversal, which leads to file upload vulnerabilities. Version 2.5.4 contains a patch for this issue.…

  • CVE-2022-39322CriOct 25, 2022
    risk 0.52cvss 9.1epss 0.01

    @keystone-6/core is a core package for Keystone 6, a content management system for Node.js. Starting with version 2.2.0 and prior to version 2.3.1, users who expected their `multiselect` fields to use the field-level access control - if configured - are vulnerable to their…

  • CVE-2022-39312CriOct 25, 2022
    risk 0.57cvss 9.8epss 0.02

    Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize the JDBC connection parameters and the Mysql server target to be connected. In…

  • CVE-2022-38580CriOct 25, 2022
    risk 0.61cvss 9.8epss 0.12

    Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).

  • CVE-2022-35877CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An…

  • CVE-2022-35876CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An…

  • CVE-2022-35875CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An…

  • CVE-2022-35874CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An…

  • CVE-2022-35244CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    A format string injection vulnerability exists in the XCMD getVarHA functionality of abode systems, inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to memory corruption, information disclosure, and denial of service. An attacker can send a…

  • CVE-2022-33938CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.01

    A format string injection vulnerability exists in the ghome_process_control_packet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted XCMD can lead to memory corruption, information disclosure and denial of service. An attacker…

  • CVE-2022-33897CriOct 25, 2022
    risk 0.59cvss 9.1epss 0.01

    A directory traversal vulnerability exists in the web_server /ajax/remove/ functionality of Robustel R1510 3.1.16. A specially-crafted network request can lead to arbitrary file deletion. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2022-33207CriOct 25, 2022
    risk 0.65cvss 9.9epss 0.04

    Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an…

  • CVE-2022-33206CriOct 25, 2022
    risk 0.65cvss 9.9epss 0.04

    Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an…

  • CVE-2022-33205CriOct 25, 2022
    risk 0.65cvss 9.9epss 0.04

    Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an…

  • CVE-2022-33204CriOct 25, 2022
    risk 0.65cvss 9.9epss 0.04

    Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an…

  • CVE-2022-33195CriOct 25, 2022
    risk 0.65cvss 10.0epss 0.03

    Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these…

  • CVE-2022-33194CriOct 25, 2022
    risk 0.65cvss 10.0epss 0.03

    Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these…

  • CVE-2022-33193CriOct 25, 2022
    risk 0.65cvss 10.0epss 0.03

    Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these…

  • CVE-2022-33192CriOct 25, 2022
    risk 0.65cvss 10.0epss 0.03

    Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these…

  • CVE-2022-33189CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.03

    An OS command injection vulnerability exists in the XCMD setAlexa functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send a malicious XML payload to trigger this vulnerability.

  • CVE-2022-33150CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.04

    An OS command injection vulnerability exists in the js_package install functionality of Robustel R1510 3.1.16. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2022-32773CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.03

    An OS command injection vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send a malicious XML payload to trigger this…

  • CVE-2022-32765CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.04

    An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this…

  • CVE-2022-32454CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.02

    A stack-based buffer overflow vulnerability exists in the XCMD setIPCam functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to remote code execution. An attacker can send a malicious XML payload to trigger this…

  • CVE-2022-30541CriOct 25, 2022
    risk 0.64cvss 9.8epss 0.03

    An OS command injection vulnerability exists in the XCMD setUPnP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send a malicious XML payload to trigger this…