VYPR

CVEs

38,096 total · page 430 of 762

  • CVE-2022-43260CriOct 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.19(6318) was discovered to contain a stack overflow via the time parameter in the fromSetSysTime function.

  • CVE-2022-41544CriOct 18, 2022
    risk 0.67cvss 9.8epss 0.11

    GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php.

  • CVE-2022-33874CriOct 18, 2022
    risk 0.64cvss 9.8epss 0.03

    An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute…

  • CVE-2022-33872CriOct 18, 2022
    risk 0.64cvss 9.8epss 0.03

    An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute…

  • CVE-2022-40684CriKEVOct 18, 2022
    risk 0.93cvss 9.8epss 1.00

    An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated…

  • CVE-2022-40889CriOct 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Phpok 6.1 has a deserialization vulnerability via framework/phpok_call.php.

  • CVE-2022-31122CriOct 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Wire is an encrypted communication and collaboration platform. Versions prior to 2022-07-12/Chart 4.19.0 are subject to Token Recipient Confusion. If an attacker has certain details of SAML IdP metadata, and configures their own SAML on the same backend, the attacker can delete…

  • CVE-2022-39056CriOct 18, 2022
    risk 0.64cvss 9.8epss 0.01

    RAVA certificate validation system has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify and delete database.

  • CVE-2020-8976CriOct 17, 2022
    risk 0.62cvss 9.6epss 0.01

    The integrated server of the ZGR TPS200 NG on its 2.00 firmware version and 1.01 hardware version, allows a remote attacker to perform actions with the permissions of a victim user. For this to happen, the victim user has to have an active session and triggers the malicious…

  • CVE-2020-8974CriOct 17, 2022
    risk 0.65cvss 10.0epss 0.01

    In ZGR TPS200 NG 2.00 firmware version and 1.01 hardware version, the firmware upload process does not perform any type of restriction. This allows an attacker to modify it and re-upload it via web with malicious modifications, rendering the device unusable.

  • CVE-2020-8973CriOct 17, 2022
    risk 0.60cvss 9.3epss 0.00

    ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, does not properly accept specially constructed requests. This allows an attacker with access to the network where the affected asset is located, to operate and change several parameters without having to be…

  • CVE-2022-42149CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.02

    kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.

  • CVE-2022-32176CriOct 17, 2022
    risk 0.59cvss 9.0epss 0.01

    In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will…

  • CVE-2022-40055CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.

  • CVE-2022-2992CriOct 17, 2022
    risk 0.74cvss 9.9epss 0.86

    A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

  • CVE-2022-2884CriOct 17, 2022
    risk 0.73cvss 9.9epss 0.76

    A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

  • CVE-2022-22128CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.02

    Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only supports product versions for 24 months after release. Older versions have reached their End of…

  • CVE-2022-0699CriOct 17, 2022
    risk 0.00cvss 9.8epss 0.01

    A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified impact via control over malloc.

  • CVE-2022-42237CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection issue in Merchandise Online Store v.1.0 allows an attacker to log in to the admin account.

  • CVE-2022-42171CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/saveParentControlInfo.

  • CVE-2022-42170CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formWifiWpsStart.

  • CVE-2022-42169CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/addWifiMacFilter.

  • CVE-2022-42168CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromSetIpMacBind.

  • CVE-2022-42167CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetFirewallCfg.

  • CVE-2022-42166CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetSpeedWan.

  • CVE-2022-42154CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-42165CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetDeviceName.

  • CVE-2022-42164CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetClientState.

  • CVE-2022-42163CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/fromNatStaticSetting.

  • CVE-2022-2052CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system.

  • CVE-2022-42980CriOct 17, 2022
    risk 0.64cvss 9.8epss 0.01

    go-admin (aka GO Admin) 2.0.12 uses the string go-admin as a production JWT key.

  • CVE-2022-42968CriOct 16, 2022
    risk 0.57cvss 9.8epss 0.01

    Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.

  • CVE-2017-20149CriOct 15, 2022
    risk 0.64cvss 9.8epss 0.02

    The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chimay-Red. A remote and unauthenticated user can trigger the vulnerability by sending a crafted HTTP request. An attacker can use this vulnerability to execute…

  • CVE-2022-41436CriOct 14, 2022
    risk 0.59cvss 9.1epss 0.01

    An issue in OXHOO TP50 OXH1.50 allows unauthenticated attackers to access the administrative panel via browsing to the URL http://device_ip/index1.html.

  • CVE-2022-39311CriOct 14, 2022
    risk 0.00cvss 9.1epss 0.02

    GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 are vulnerable to remote code execution on the server from a malicious or compromised agent. The…

  • CVE-2022-38418CriOct 14, 2022
    risk 0.70cvss 9.8epss 0.80

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user.…

  • CVE-2022-35712CriOct 14, 2022
    risk 0.67cvss 9.8epss 0.37

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction,…

  • CVE-2022-35711CriOct 14, 2022
    risk 0.70cvss 9.8epss 0.73

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction,…

  • CVE-2022-35710CriOct 14, 2022
    risk 0.67cvss 9.8epss 0.43

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user…

  • CVE-2022-35698CriOct 14, 2022
    risk 0.66cvss 10.0epss 0.11

    Adobe Commerce versions 2.4.4-p1 (and earlier) and 2.4.5 (and earlier) are affected by a Stored Cross-site Scripting vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.

  • CVE-2022-35690CriOct 14, 2022
    risk 0.69cvss 9.8epss 0.72

    Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user…

  • CVE-2022-41477CriOct 14, 2022
    risk 0.59cvss 9.1epss 0.01

    A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inject payloads via theme parameters to read files across directories.

  • CVE-2022-41581CriOct 14, 2022
    risk 0.59cvss 9.1epss 0.00

    The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.

  • CVE-2022-41580CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.

  • CVE-2022-41578CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The MPTCP module has an out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause root privilege escalation attacks implemented by modifying program information.

  • CVE-2022-38986CriOct 14, 2022
    risk 0.59cvss 9.1epss 0.01

    The HIPP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause out-of-bounds access to the HIPP module and page table tampering, affecting device confidentiality and availability.

  • CVE-2022-38983CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The BT Hfp Client module has a Use-After-Free (UAF) vulnerability.Successful exploitation of this vulnerability may result in arbitrary code execution.

  • CVE-2022-38982CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The fingerprint module has service logic errors.Successful exploitation of this vulnerability will cause the phone lock to be cracked.

  • CVE-2022-38980CriOct 14, 2022
    risk 0.64cvss 9.8epss 0.01

    The HwAirlink module has a heap overflow vulnerability in processing data packets of the proprietary protocol.Successful exploitation of this vulnerability may allow attackers to obtain process control permissions.

  • CVE-2021-46840CriOct 14, 2022
    risk 0.59cvss 9.1epss 0.00

    The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.