VYPR

CVEs

38,095 total · page 433 of 762

  • CVE-2022-40314CriSep 30, 2022
    risk 0.00cvss 9.8epss 0.02

    A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.

  • CVE-2022-2778CriSep 30, 2022
    risk 0.64cvss 9.8epss 0.01

    In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.

  • CVE-2022-36066CriSep 29, 2022
    risk 0.00cvss 9.1epss 0.02

    Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, admins can upload a maliciously crafted Zip or Gzip Tar archive to write files at arbitrary locations and…

  • CVE-2022-33880CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.01

    hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the type parameter.

  • CVE-2022-39266CriSep 29, 2022
    risk 0.56cvss 9.6epss 0.01

    isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, if the untrusted v8 cached data is passed to the API through CachedDataOptions, attackers can bypass the sandbox and run arbitrary code in the nodejs process.…

  • CVE-2022-40887CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.01

    SourceCodester Best Student Result Management System 1.0 is vulnerable to SQL Injection.

  • CVE-2022-29503CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.01

    A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability.

  • CVE-2022-40475CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.04

    TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi.

  • CVE-2021-45790CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to arbitrary directory, where attackers can write a cron job to execute commands.

  • CVE-2020-35674CriSep 29, 2022
    risk 0.57cvss 9.8epss 0.01

    BigProf Online Invoicing System before 2.9 suffers from an unauthenticated SQL Injection found in /membership_passwordReset.php (the endpoint that is responsible for issuing self-service password resets). An unauthenticated attacker is able to send a request containing a crafted…

  • CVE-2020-27602CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.01

    BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in meetingId, userId, and authToken.

  • CVE-2020-15347CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.

  • CVE-2020-15332CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has weak /opt/axess/etc/default/axess permissions.

  • CVE-2020-15331CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a hardcoded OAUTH_SECRET_KEY in /opt/axess/etc/default/axess.

  • CVE-2016-2338CriSep 29, 2022
    risk 0.64cvss 9.8epss 0.05

    An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Specially constructed object passed as element of tags array can…

  • CVE-2022-40929CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.02

    XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).

  • CVE-2022-40942CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.08

    Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time.

  • CVE-2022-40083CriSep 28, 2022
    risk 0.56cvss 9.6epss 0.03

    Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged by attackers to cause a Server-Side Request Forgery (SSRF).

  • CVE-2022-28814CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arbitrary files and gain full control of the device.

  • CVE-2022-28812CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain SuperUser access to the device.

  • CVE-2022-28811CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could utilize an improper input validation on an API-submitted parameter to execute arbitrary OS commands.

  • CVE-2022-22526CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a missing authentication allows for full access via API.

  • CVE-2022-22524CriSep 28, 2022
    risk 0.61cvss 9.4epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 an unauthenticated remote attacker could utilize a SQL-Injection vulnerability to gain full database access, modify users and stop services .

  • CVE-2022-22522CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.01

    In Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 a remote, unauthenticated attacker could make use of hard-coded credentials to gain full access to the device.

  • CVE-2022-30935CriSep 28, 2022
    risk 0.59cvss 9.1epss 0.01

    An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users, and optionally reset their password.…

  • CVE-2022-39033CriSep 28, 2022
    risk 0.64cvss 9.8epss 0.02

    Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication, access restricted paths to…

  • CVE-2022-41571CriSep 27, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur.

  • CVE-2022-41570CriSep 27, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur.

  • CVE-2022-40877CriSep 27, 2022
    risk 0.64cvss 9.8epss 0.01

    Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.

  • CVE-2022-37346CriSep 27, 2022
    risk 0.64cvss 9.8epss 0.01

    EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an…

  • CVE-2021-41433CriSep 27, 2022
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability exists in version 1.0 of the Resumes Management and Job Application Website application login form by EGavilan Media that allows authentication bypass through login.php.

  • CVE-2022-39256CriSep 27, 2022
    risk 0.52cvss 9.0epss 0.02

    Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote attackers to execute arbitrary code on affected installations of Orckestra C1 CMS. Authentication is required to exploit this vulnerability. The authenticated…

  • CVE-2022-40050CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.01

    ZFile v4.1.1 was discovered to contain an arbitrary file upload vulnerability via the component /file/upload/1.

  • CVE-2022-30004CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.02

    Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..

  • CVE-2022-3075CriKEVSep 26, 2022
    risk 0.75cvss 9.6epss 0.06

    Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2022-28722CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Certain HP Print Products are potentially vulnerable to Buffer Overflow.

  • CVE-2022-28721CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.02

    Certain HP Print Products are potentially vulnerable to Remote Code Execution.

  • CVE-2022-40485CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php.

  • CVE-2022-40484CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_edit.php.

  • CVE-2022-40483CriSep 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /wedding_details.php.

  • CVE-2022-41352CriKEVSep 26, 2022
    risk 0.92cvss 9.8epss 0.95

    An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends…

  • CVE-2022-23463CriSep 24, 2022
    risk 0.61cvss 9.4epss 0.02

    Nepxion Discovery is a solution for Spring Cloud. Discover is vulnerable to SpEL Injection in discovery-commons. DiscoveryExpressionResolver’s eval method is evaluating expression with a StandardEvaluationContext, allowing the expression to reach and interact with Java classes…

  • CVE-2022-36025CriSep 24, 2022
    risk 0.59cvss 9.1epss 0.01

    Besu is a Java-based Ethereum client. In versions newer than 22.1.3 and prior to 22.7.1, Besu is subject to an Incorrect Conversion between Numeric Types. An error in 32 bit signed and unsigned types in the calculation of available gas in the CALL operations (including…

  • CVE-2022-40122CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer_action.php.

  • CVE-2022-40121CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/manage_customers.php.

  • CVE-2022-40120CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/customer_transactions.php.

  • CVE-2022-40119CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/transactions.php.

  • CVE-2022-40118CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds_action.php.

  • CVE-2022-40117CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_customer.php.

  • CVE-2022-40116CriSep 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/beneficiary.php.