VYPR

CVEs

38,075 total · page 470 of 762

  • CVE-2022-27161CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    Csz Cms 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Members_viewUsers

  • CVE-2021-31805CriApr 12, 2022
    risk 0.71cvss 9.8epss 0.85

    The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{...} syntax. Using forced OGNL evaluation on untrusted…

  • CVE-2022-0142CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.03

    The Visual Form Builder WordPress plugin before 3.0.8 is vulnerable to CSV injection allowing a user with low level or no privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

  • CVE-2022-25752CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 EEC (24V), SCALANCE X302-7 EEC (24V, coated), SCALANCE X302-7 EEC (2x 230V), SCALANCE X302-7 EEC (2x 230V, coated), SCALANCE X302-7 EEC (2x 24V), SCALANCE…

  • CVE-2022-23450CriApr 12, 2022
    risk 0.67cvss 9.8epss 0.36

    A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versions < V7.3 Update 1). The affected system allows remote users to send maliciously crafted objects. Due to insecure deserialization of…

  • CVE-2022-29080CriApr 12, 2022
    risk 0.64cvss 9.8epss 0.02

    The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call dependencyVersions with a JSON object in which pkgs is a key, and there are shell metacharacters in a value.

  • CVE-2022-28347CriApr 12, 2022
    risk 0.57cvss 9.8epss 0.03

    A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. This occurs by passing a crafted dictionary (with dictionary expansion) as the **options argument, and placing the injection payload in an option name.

  • CVE-2022-28346CriApr 12, 2022
    risk 0.58cvss 9.8epss 0.19

    An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggregate(), and extra() methods are subject to SQL injection in column aliases via a crafted dictionary (with dictionary expansion) as the passed **kwargs.

  • CVE-2022-27577CriApr 11, 2022
    risk 0.59cvss 9.1epss 0.01

    The vulnerability in the MSC800 in all versions before 4.15 allows for an attacker to predict the TCP initial sequence number. When the TCP sequence is predictable, an attacker can send packets that are forged to appear to come from a trusted computer. These forged packets could…

  • CVE-2022-22954CriKEVApr 11, 2022
    risk 0.93cvss 9.8epss 1.00

    VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

  • CVE-2022-22258CriApr 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The Wi-Fi module has an event notification vulnerability.Successful exploitation of this vulnerability may allow third-party applications to intercept event notifications and add information and result in elevation-of-privilege.

  • CVE-2022-1161CriApr 11, 2022
    risk 0.65cvss 10.0epss 0.05

    An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an…

  • CVE-2021-46742CriApr 11, 2022
    risk 0.59cvss 9.1epss 0.01

    The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful exploitation of this vulnerability may affect the availability.

  • CVE-2021-38125CriApr 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Unauthenticated remote code execution in Micro Focus Operations Bridge containerized, affecting versions 2021.05, 2021.08, and newer versions of Micro Focus Operations Bridge containerized if the deployment was upgraded from 2021.05 or 2021.08. The vulnerability could be…

  • CVE-2021-37291CriApr 11, 2022
    risk 0.64cvss 9.8epss 0.07

    An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id POST parameter in index.php.

  • CVE-2022-27115CriApr 11, 2022
    risk 0.59cvss 9.8epss 0.29

    In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload.

  • CVE-2022-0949CriApr 11, 2022
    risk 0.64cvss 9.8epss 0.08

    The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection WordPress plugin before 6.930 does not properly sanitise and escape the fingerprint parameter before using it in a SQL statement via the stopbadbots_grava_fingerprint AJAX action, available to…

  • CVE-2022-1297CriApr 11, 2022
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in r_bin_ne_get_entrypoints function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.

  • CVE-2022-1296CriApr 11, 2022
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds read in `r_bin_ne_get_relocs` function in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability may allow attackers to read sensitive information or cause a crash.

  • CVE-2022-1295CriApr 11, 2022
    risk 0.57cvss 9.8epss 0.01

    Prototype Pollution in GitHub repository alvarotrigo/fullpage.js prior to 4.0.2.

  • CVE-2021-32157CriApr 11, 2022
    risk 0.63cvss 9.6epss 0.04

    A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.

  • CVE-2022-27477CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit.

  • CVE-2022-27277CriApr 10, 2022
    risk 0.59cvss 9.1epss 0.01

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain an arbitrary file deletion vulnerability via the function sub_17C08.

  • CVE-2022-27276CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.04

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_10F2C. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27275CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_122D0. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27274CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12028. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27273CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_12168. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27272CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the function sub_1791C. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27271CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component python-lib. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27270CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.03

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component ipsec_secrets. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27269CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.04

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component config_ovpn. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27268CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.04

    InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the component get_cgi_from_memory. This vulnerability is triggered via a crafted packet.

  • CVE-2022-27133CriApr 10, 2022
    risk 0.59cvss 9.1epss 0.01

    zbzcms v1.0 was discovered to contain an arbitrary file deletion vulnerability via /include/up.php.

  • CVE-2022-27131CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability at /zbzedit/php/zbz.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27129CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability at /admin/ajax.php in zbzcms v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27128CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.01

    An incorrect access control issue at /admin/run_ajax.php in zbzcms v1.0 allows attackers to arbitrarily add administrator accounts.

  • CVE-2022-27126CriApr 10, 2022
    risk 0.64cvss 9.8epss 0.01

    zbzcms v1.0 was discovered to contain a SQL injection vulnerability via the art parameter at /include/make.php.

  • CVE-2022-1286CriApr 10, 2022
    risk 0.00cvss 9.8epss 0.01

    heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

  • CVE-2022-1276CriApr 10, 2022
    risk 0.00cvss 9.8epss 0.02

    Out-of-bounds Read in mrb_get_args in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

  • CVE-2022-26851CriApr 8, 2022
    risk 0.59cvss 9.1epss 0.01

    Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss.

  • CVE-2021-43517CriApr 8, 2022
    risk 0.64cvss 9.8epss 0.02

    FOSCAM Camera FI9805E with firmware V4.02.R12.00018510.10012.143900.00000 contains a backdoor that opens Telnet port when special command is sent on port 9530.

  • CVE-2022-27047CriApr 8, 2022
    risk 0.64cvss 9.8epss 0.01

    mogu_blog_cms 5.2 suffers from upload arbitrary files without any limitation.

  • CVE-2022-28001CriApr 8, 2022
    risk 0.64cvss 9.8epss 0.02

    Movie Seat Reservation v1 was discovered to contain a SQL injection vulnerability at /index.php?page=reserve via the id parameter.

  • CVE-2022-27357CriApr 8, 2022
    risk 0.64cvss 9.8epss 0.04

    Ecommerce-Website v1 was discovered to contain an arbitrary file upload vulnerability via /customer_register.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-27351CriApr 8, 2022
    risk 0.64cvss 9.8epss 0.03

    Zoo Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /public_html/apply_vacancy. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-28805CriApr 8, 2022
    risk 0.00cvss 9.1epss 0.03

    singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.

  • CVE-2021-43474CriApr 7, 2022
    risk 0.64cvss 9.8epss 0.03

    An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 function

  • CVE-2021-43453CriApr 7, 2022
    risk 0.64cvss 9.8epss 0.01

    A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in parser_parse_for_statement_start in the js-parser-statm.c file. This issue is similar to CVE-2020-29657.

  • CVE-2022-26676CriApr 7, 2022
    risk 0.64cvss 9.8epss 0.01

    aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scripts to control the system or disrupt service.

  • CVE-2022-26612CriApr 7, 2022
    risk 0.57cvss 9.8epss 0.04

    In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. A subsequent TAR entry…