VYPR

CVEs

38,095 total · page 435 of 762

  • CVE-2022-41220CriSep 21, 2022
    risk 0.64cvss 9.8epss 0.02

    md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: the vendor's position is that the product is not intended for untrusted input

  • CVE-2022-38619CriSep 21, 2022
    risk 0.64cvss 9.8epss 0.01

    SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /SVFE2/pages/feegroups/mcc_group.jsf.

  • CVE-2022-40357CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.02

    A security issue was discovered in Z-BlogPHP <= 1.7.2. A Server-Side Request Forgery (SSRF) vulnerability in the zb_users/plugin/UEditor/php/action_crawler.php file allows remote attackers to force the application to make arbitrary requests via injection of arbitrary URLs into…

  • CVE-2022-32882CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.4, macOS Big Sur 11.6.6. An app may be able to bypass Privacy preferences.

  • CVE-2022-32863CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2022-32788CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.03

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. A remote user may be able to cause kernel code execution.

  • CVE-2022-40009CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    SWFTools commit 772e55a was discovered to contain a heap-use-after-free via the function grow_unicode at /lib/ttf.c.

  • CVE-2022-40008CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    SWFTools commit 772e55a was discovered to contain a heap-buffer overflow via the function readU8 at /lib/ttf.c.

  • CVE-2022-41138CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.02

    In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.

  • CVE-2022-38340CriSep 20, 2022
    risk 0.59cvss 9.1epss 0.01

    Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the component fmedataupload.

  • CVE-2022-37265CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.02

    Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.

  • CVE-2017-20148CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck user because of insecure recursive chown calls.

  • CVE-2022-38916CriSep 20, 2022
    risk 0.65cvss 9.8epss 0.18

    A file upload vulnerability exists in the storage feature of pagekit 1.0.18, which allows an attacker to upload malicious files

  • CVE-2022-37204CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Final CMS 5.1.0 is vulnerable to SQL Injection.

  • CVE-2022-2177CriSep 20, 2022
    risk 0.61cvss 9.4epss 0.01

    Kayrasoft product before version 2 has an unauthenticated SQL Injection vulnerability. This is fixed in version 2.

  • CVE-2022-38545CriSep 19, 2022
    risk 0.58cvss 9.6epss 0.34

    Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2022-38509CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php.

  • CVE-2022-38339CriSep 19, 2022
    risk 0.62cvss 9.6epss 0.01

    Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login page.

  • CVE-2022-37032CriSep 19, 2022
    risk 0.00cvss 9.1epss 0.02

    An out-of-bounds read in the BGP daemon of FRRouting FRR before 8.4 may lead to a segmentation fault and denial of service. This occurs in bgp_capability_msg_parse in bgpd/bgp_packet.c.

  • CVE-2022-28321CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_access.so module doesn't correctly restrict login if a user tries to connect from an IP address that is not resolvable via DNS. In such conditions, a user with…

  • CVE-2022-0143CriSep 19, 2022
    risk 0.60cvss 9.3epss 0.01

    When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all versions of the LDAP connector prior to 1.5.20.9. The LDAP connector is bundled with Identity Management (IDM) and Remote Connector Server (RCS)

  • CVE-2022-40980CriSep 19, 2022
    risk 0.59cvss 9.1epss 0.01

    A potential unathenticated file deletion vulnerabilty on Trend Micro Mobile Security for Enterprise 9.8 SP5 could allow an attacker with access to the Management Server to delete files. This issue was resolved in 9.8 SP5 Critical Patch 2.

  • CVE-2022-40144CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product's login authentication by falsifying request parameters on affected installations.

  • CVE-2022-3218CriSep 19, 2022
    risk 0.09cvss 9.8epss 0.74

    Due to a reliance on client-side authentication, the WiFi Mouse (Mouse Server) from Necta LLC's authentication mechanism is trivially bypassed, which can result in remote code execution.

  • CVE-2022-40812CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

  • CVE-2022-40810CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-ip-addresses for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0

  • CVE-2022-40809CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-dicts for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0

  • CVE-2022-40432CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0.

  • CVE-2022-40431CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.

  • CVE-2022-40430CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-utility for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.

  • CVE-2022-40429CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-ip-addresses for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.

  • CVE-2022-40428CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-mpeg for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.

  • CVE-2022-40426CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-asns for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.

  • CVE-2022-40425CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-html for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.

  • CVE-2022-38887CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    The d8s-python for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38886CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    The d8s-xml for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38885CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    The d8s-netstrings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38884CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    The d8s-grammars for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38883CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    The d8s-math for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38882CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    The d8s-json for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-38881CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

  • CVE-2022-37203CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.02

    JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

  • CVE-2022-35914CriKEVSep 19, 2022
    risk 0.87cvss 9.8epss 1.00

    /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.

  • CVE-2022-40811CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

  • CVE-2022-40808CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-dates for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0

  • CVE-2022-40807CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-domains for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0

  • CVE-2022-40806CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-uuids for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0

  • CVE-2022-40805CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-urls for python 0.1.0, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-hypothesis package.

  • CVE-2022-40427CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-domains for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0

  • CVE-2022-40424CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-networking package. The affected version of d8s-urls is 0.1.0