VYPR

CVEs

38,075 total · page 474 of 762

  • CVE-2022-26301CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.01

    TuziCMS v2.0.6 was discovered to contain a SQL injection vulnerability via the component App\Manage\Controller\ZhuantiController.class.php.

  • CVE-2022-26279CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.02

    EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.

  • CVE-2022-26272CriMar 24, 2022
    risk 0.65cvss 9.8epss 0.22

    A remote code execution (RCE) vulnerability in Ionize v1.0.8.1 allows attackers to execute arbitrary code via a crafted string written to the file application/config/config.php.

  • CVE-2022-26249CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.02

    Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers to execute arbitrary code or access sensitive information via a CSV injection attack.

  • CVE-2022-22374CriMar 24, 2022
    risk 0.59cvss 9.1epss 0.01

    The BMC (IBM Power 9 AC922 OP910, OP920, OP930, and OP940) may be subject to a firmware downgrade attack which may affect its ability to operate its host. IBM X-Force ID: 221442.

  • CVE-2021-43084CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.01

    An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter.

  • CVE-2022-26629CriMar 24, 2022
    risk 0.59cvss 9.1epss 0.03

    An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.

  • CVE-2021-43700CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8.

  • CVE-2022-27811CriMar 24, 2022
    risk 0.00cvss 9.8epss 0.03

    GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename.

  • CVE-2022-27083CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadAccessCodePic.

  • CVE-2022-27082CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetInternetLanInfo.

  • CVE-2022-27081CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetLanInfo.

  • CVE-2022-27080CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setWorkmode.

  • CVE-2022-27079CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setPicListItem.

  • CVE-2022-27078CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setAdInfoDetail.

  • CVE-2022-27077CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadWeiXinPic.

  • CVE-2022-27076CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/delAd.

  • CVE-2022-26536CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setFixTools.

  • CVE-2022-26290CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/WriteFacMac.

  • CVE-2022-26289CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/exeCommand.

  • CVE-2021-31326CriMar 24, 2022
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parameter to /goform/form2Reboot.cgi.

  • CVE-2022-24934CriMar 23, 2022
    risk 0.65cvss 9.8epss 0.20

    wpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEY_CURRENT_USER in the registry.

  • CVE-2022-24768CriMar 23, 2022
    risk 0.57cvss 9.9epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting with 1.0.0 are vulnerable to an improper access control bug, allowing a malicious user to potentially escalate their privileges to admin-level. Versions starting…

  • CVE-2022-23881CriMar 23, 2022
    risk 0.68cvss 9.8epss 0.57

    ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.

  • CVE-2022-23880CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in the File Management function module of taoCMS v3.0.2 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-25222CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.02

    Money Transfer Management System Version 1.0 allows an unauthenticated user to inject SQL queries in 'admin/maintenance/manage_branch.php' and 'admin/maintenance/manage_fee.php' via the 'id' parameter.

  • CVE-2022-24293CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.07

    Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution.

  • CVE-2022-24292CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.07

    Certain HP Print devices may be vulnerable to potential information disclosure, denial of service, or remote code execution.

  • CVE-2022-22952CriMar 23, 2022
    risk 0.59cvss 9.1epss 0.02

    VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface may be able to…

  • CVE-2022-22951CriMar 23, 2022
    risk 0.61cvss 9.1epss 0.20

    VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control…

  • CVE-2022-0888CriMar 23, 2022
    risk 0.67cvss 9.8epss 0.39

    The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to…

  • CVE-2021-27476CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.04

    A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and…

  • CVE-2021-27474CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.02

    Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre.

  • CVE-2021-27472CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.06

    A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.

  • CVE-2021-27470CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.04

    A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk…

  • CVE-2021-27468CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.03

    The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.

  • CVE-2021-27466CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.04

    A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk…

  • CVE-2021-27464CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.03

    The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.

  • CVE-2021-27462CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.04

    A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk…

  • CVE-2021-27460CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.03

    Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain…

  • CVE-2021-27428CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.01

    GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegitimate user could upgrade…

  • CVE-2021-27426CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.01

    GE UR IED firmware versions prior to version 8.1x with “Basic” security variant does not allow the disabling of the “Factory Mode,” which is used for servicing the IED by a “Factory” user.

  • CVE-2021-38278CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentControlInfo function.

  • CVE-2021-43736CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.02

    CmsWing CMS 1.3.7 is affected by a Remote Code Execution (RCE) vulnerability via parameter: log rule

  • CVE-2021-43735CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.01

    CmsWing 1.3.7 is affected by a SQLi vulnerability via parameter: behavior rule.

  • CVE-2021-45756CriMar 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Asus RT-AC68U <3.0.0.4.385.20633 and RT-AC5300 <3.0.0.4.384.82072 are affected by a buffer overflow in blocking_request.cgi.

  • CVE-2022-26189CriMar 22, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the langType parameter in the login interface.

  • CVE-2022-26188CriMar 22, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via /setting/NTPSyncWithHost.

  • CVE-2022-26187CriMar 22, 2022
    risk 0.65cvss 9.8epss 0.20

    TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the pingCheck function.

  • CVE-2022-26186CriMar 22, 2022
    risk 0.64cvss 9.8epss 0.04

    TOTOLINK N600R V4.3.0cu.7570_B20200620 was discovered to contain a command injection vulnerability via the exportOvpn interface at cstecgi.cgi.