VYPR

CVEs

38,075 total · page 473 of 762

  • CVE-2022-26069CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerPage_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-26065CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in GetLatestDemandNode. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-26059CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in GetQueryData. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-26013CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.09

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in DIAE_dmdsetHandler.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-25980CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerCommon.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-25880CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in HandlerTag_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-25347CriMar 29, 2022
    risk 0.65cvss 9.8epss 0.11

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the file system.

  • CVE-2022-0923CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in HandlerDialog_KID.ashx. This allows an attacker to inject arbitrary SQL queries, retrieve and modify database contents, and execute system commands.

  • CVE-2022-23901CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.02

    A stack overflow re2c 2.2 exists due to infinite recursion issues in src/dfa/dead_rules.cc.

  • CVE-2021-46743CriMar 29, 2022
    risk 0.59cvss 9.1epss 0.01

    In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of keys are loaded in a key ring. This allows an attacker to forge tokens that validate under the incorrect key. NOTE: this provides a…

  • CVE-2022-25420CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.03

    NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows attackers to execute arbitrary code via a crafted HTTP request.

  • CVE-2022-25521CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.02

    NUUO v03.11.00 was discovered to contain access control issue.

  • CVE-2021-45865CriMar 29, 2022
    risk 0.64cvss 9.8epss 0.01

    A File Upload vulnerability exists in Sourcecodester Student Attendance Manageent System 1.0 via the file upload functionality.

  • CVE-2022-26278CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 v15.03.2.21_cn was discovered to contain a stack overflow via the time parameter in the PowerSaveSet function.

  • CVE-2022-0735CriMar 28, 2022
    risk 0.66cvss 10.0epss 0.13

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an…

  • CVE-2022-0846CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.09

    The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection exploitable by unauthenticated users

  • CVE-2022-0787CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.09

    The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters before using them in SQL statements via AJAX actions (available to unauthenticated users), leading to SQL Injections

  • CVE-2022-0784CriMar 28, 2022
    risk 0.65cvss 9.8epss 0.10

    The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it in a SQL statement via the wpex_titles AJAX action (available to unauthenticated users), leading to an unauthenticated SQL injection

  • CVE-2022-0679CriMar 28, 2022
    risk 0.68cvss 9.8epss 0.48

    The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated and authenticated users) which results…

  • CVE-2022-0479CriMar 28, 2022
    risk 0.60cvss 9.8epss 0.44

    The Popup Builder WordPress plugin before 4.1.1 does not sanitise and escape the sgpb-subscription-popup-id parameter before using it in a SQL statement in the All Subscribers admin dashboard, leading to a SQL injection, which could also be used to perform Reflected Cross-Site…

  • CVE-2021-25070CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    The Block Bad Bots WordPress plugin before 6.88 does not properly sanitise and escape the User Agent before using it in a SQL statement to record logs, leading to an SQL Injection issue

  • CVE-2022-23884CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.03

    Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by PurchaseReceiptPacket::_read (packet deserializer).

  • CVE-2022-0342CriMar 28, 2022
    risk 0.70cvss 9.8epss 0.95

    An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG…

  • CVE-2022-23882CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.01

    TuziCMS 2.0.6 is affected by SQL injection in \App\Manage\Controller\BannerController.class.php.

  • CVE-2021-46433CriMar 28, 2022
    risk 0.65cvss 10.0epss 0.01

    In fenom 2.12.1 and before, there is a way in fenom/src/Fenom/Template.php function getTemplateCode()to bypass sandbox to execute arbitrary PHP code when disable_native_funcs is true.

  • CVE-2022-25757CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSON with a duplicate key, the attacker can bypass the body_schema validation in the request-validation plugin. For example,…

  • CVE-2022-26273CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.01

    EyouCMS v1.5.4 was discovered to lack parameter filtering in \user\controller\shop.php, leading to payment logic vulnerabilities.

  • CVE-2022-24303CriMar 28, 2022
    risk 0.52cvss 9.1epss 0.03

    Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.

  • CVE-2021-45490CriMar 28, 2022
    risk 0.59cvss 9.1epss 0.01

    The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validation.

  • CVE-2021-44617CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.

  • CVE-2022-26268CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.01

    Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php.

  • CVE-2021-26600CriMar 28, 2022
    risk 0.57cvss 9.8epss 0.06

    ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).

  • CVE-2021-26599CriMar 28, 2022
    risk 0.61cvss 9.8epss 0.21

    ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.

  • CVE-2022-26258CriKEVMar 28, 2022
    risk 0.82cvss 9.8epss 0.92

    D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

  • CVE-2022-26255CriMar 28, 2022
    risk 0.64cvss 9.8epss 0.02

    Clash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxies name column.

  • CVE-2021-44127CriMar 27, 2022
    risk 0.64cvss 9.8epss 0.03

    In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execute arbitrary system commands when the parameter is "name=deleteFile" after being authorized.

  • CVE-2022-26245CriMar 27, 2022
    risk 0.65cvss 9.8epss 0.15

    Falcon-plus v0.3 was discovered to contain a SQL injection vulnerability via the parameter grpName in /config/service/host.go.

  • CVE-2022-1106CriMar 27, 2022
    risk 0.00cvss 9.1epss 0.01

    use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.

  • CVE-2022-26205CriMar 27, 2022
    risk 0.64cvss 9.8epss 0.02

    Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display text fields. This vulnerability allows attackers to execute arbitrary code via injection of a crafted payload.

  • CVE-2022-26198CriMar 27, 2022
    risk 0.64cvss 9.8epss 0.02

    Notable v1.8.4 does not filter text editing, allowing attackers to execute arbitrary code via a crafted payload injected into the Title text field.

  • CVE-2022-22995CriMar 25, 2022
    risk 0.65cvss 10.0epss 0.03

    The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.

  • CVE-2022-22274CriMar 25, 2022
    risk 0.68cvss 9.8epss 0.76

    A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution in the firewall.

  • CVE-2022-24783CriMar 25, 2022
    risk 0.58cvss 10.0epss 0.01

    Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where a malicious actor controlling the code executed in a Deno runtime could bypass all permission checks and execute arbitrary shell…

  • CVE-2022-27919CriMar 25, 2022
    risk 0.64cvss 9.8epss 0.02

    Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not specify an initial configuration file. The configuration allows certain anonymous access to administration and an API.

  • CVE-2021-26622CriMar 25, 2022
    risk 0.63cvss 9.6epss 0.03

    An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all connected nodes in NAC through this…

  • CVE-2021-43636CriMar 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Two Buffer Overflow vulnerabilities exists in T10 V2_Firmware V4.1.8cu.5207_B20210320 in the http_request_parse function when processing host data in the HTTP request process.

  • CVE-2022-25577CriMar 25, 2022
    risk 0.59cvss 9.1epss 0.01

    ALF-BanCO v8.2.5 and below was discovered to use a hardcoded password to encrypt the SQLite database containing the user's data. Attackers who are able to gain remote or local access to the system are able to read and modify the data.

  • CVE-2021-43090CriMar 25, 2022
    risk 0.57cvss 9.8epss 0.02

    An XML External Entity (XXE) vulnerability exists in soa-model before 1.6.4 in the WSDLParser function.

  • CVE-2022-1040CriKEVMar 25, 2022
    risk 0.87cvss 9.8epss 1.00

    An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.

  • CVE-2022-22687CriMar 25, 2022
    risk 0.64cvss 9.8epss 0.02

    Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in Authentication functionality in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via unspecified vectors.