VYPR

CVEs

38,073 total · page 477 of 762

  • CVE-2021-45786CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.

  • CVE-2021-43958CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login credentials as rest resources did not check if users were beyond their max failed login limits and therefore required solving a CAPTCHA in addition to providing…

  • CVE-2022-27005CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.05

    Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the setWanCfg function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted…

  • CVE-2022-27004CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6in4 function via the remote6in4 parameter. This vulnerability allows attackers to execute arbitrary commands via a…

  • CVE-2022-27003CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink routers s X5000R V9.1.0u.6118_B20201102 and A7000R V9.1.0u.6115_B20201022 were discovered to contain a command injection vulnerability in the Tunnel 6rd function via the relay6rd parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted…

  • CVE-2022-27002CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.05

    Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-27001CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-27000CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_backup_ntp_server, and h_time_zone parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted…

  • CVE-2022-26999CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_stat, wan_gw_stat, and wan_dns1_stat parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted…

  • CVE-2022-26998CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-26997CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-26996CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd, and pppoe_servicename parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-26995CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, pptp_fix_mask, pptp_fix_gw, and wan_dns1_stat parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted…

  • CVE-2022-26994CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the pptp function via the pptpUserName and pptpPassword parameters. This vulnerability allows attackers to execute arbitrary…

  • CVE-2022-26993CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the pppoe function via the pppoeUserName, pppoePassword, and pppoe_Service parameters. This vulnerability allows attackers to…

  • CVE-2022-26992CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the ddns function via the DdnsUserName, DdnsHostName, and DdnsPassword parameters. This vulnerability allows attackers to execute…

  • CVE-2022-26991CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the ntp function via the TimeZone parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted…

  • CVE-2022-26990CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Arris routers SBR-AC1900P 1.0.7-B05, SBR-AC3200P 1.0.7-B05 and SBR-AC1200P 1.0.5-B05 were discovered to contain a command injection vulnerability in the firewall-local log function via the EmailAddress, SmtpServerName, SmtpUsername, and SmtpPassword parameters. This…

  • CVE-2022-26214CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26213CriMar 15, 2022
    risk 0.66cvss 9.8epss 0.26

    Totolink X5000R_Firmware v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function setNtpCfg, via the tz parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-26212CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26211CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26210CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.06

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26209CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26208CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26207CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-26206CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function…

  • CVE-2022-25498CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.03

    CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.

  • CVE-2022-25495CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file.

  • CVE-2022-25494CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via staff_login.php.

  • CVE-2022-25492CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php.

  • CVE-2022-25490CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.02

    HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php.

  • CVE-2022-25488CriMar 15, 2022
    risk 0.64cvss 9.8epss 0.07

    Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php.

  • CVE-2022-25487CriMar 15, 2022
    risk 0.68cvss 9.8epss 0.54

    Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php.

  • CVE-2022-24752CriMar 15, 2022
    risk 0.57cvss 9.8epss 0.01

    SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query sorting were passed directly to the database. The maintainers do not know if this could lead to direct SQL injections but took…

  • CVE-2022-26320CriMar 14, 2022
    risk 0.59cvss 9.1epss 0.01

    The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with…

  • CVE-2022-0658CriMar 14, 2022
    risk 0.64cvss 9.8epss 0.09

    The CommonsBooking WordPress plugin before 2.6.8 does not sanitise and escape the location parameter of the calendar_data AJAX action (available to unauthenticated users) before it is used in dynamically constructed SQL queries, leading to an unauthenticated SQL injection

  • CVE-2022-0254CriMar 14, 2022
    risk 0.57cvss 9.8epss 0.02

    The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby parameters before using them in a SQL statement in the admin dashboard, leading to a SQL injection

  • CVE-2022-0169CriMar 14, 2022
    risk 0.73cvss 9.8epss 0.75

    The Photo Gallery by 10Web WordPress plugin before 1.6.0 does not validate and escape the bwg_tag_id_bwg_thumbnails_0 parameter before using it in a SQL statement via the bwg_frontend_data AJAX action (available to unauthenticated and authenticated users), leading to an…

  • CVE-2021-25007CriMar 14, 2022
    risk 0.64cvss 9.8epss 0.02

    The MOLIE WordPress plugin through 0.5 does not validate and escape a post parameter before using in a SQL statement, leading to an SQL Injection

  • CVE-2021-25003CriMar 14, 2022
    risk 0.68cvss 9.8epss 0.56

    The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE

  • CVE-2022-24387CriMar 14, 2022
    risk 0.59cvss 9.1epss 0.02

    With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml file. THis is possible in SmarterTrack v100.0.8019.14010

  • CVE-2022-23943CriMar 14, 2022
    risk 0.68cvss 9.8epss 0.50

    Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.

  • CVE-2022-22721CriMar 14, 2022
    risk 0.62cvss 9.1epss 0.42

    If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

  • CVE-2022-22720CriMar 14, 2022
    risk 0.66cvss 9.8epss 0.28

    Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

  • CVE-2021-45887CriMar 13, 2022
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in PONTON X/P Messenger before 3.11.2. Due to path traversal in private/SchemaSetUpload.do for uploaded ZIP files, an executable script can be uploaded by web application administrators, giving the attacker remote code execution on the underlying server…

  • CVE-2022-24760CriMar 12, 2022
    risk 0.62cvss 10.0epss 0.49

    Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects Parse Server in the default configuration with MongoDB. The main weakness that leads to RCE is the…

  • CVE-2022-25621CriMar 11, 2022
    risk 0.64cvss 9.8epss 0.01

    UUNIVERGE WA 1020 Ver8.2.11 and prior, UNIVERGE WA 1510 Ver8.2.11 and prior, UNIVERGE WA 1511 Ver8.2.11 and prior, UNIVERGE WA 1512 Ver8.2.11 and prior, UNIVERGE WA 2020 Ver8.2.11 and prior, UNIVERGE WA 2021 Ver8.2.11 and prior, UNIVERGE WA 2610-AP Ver8.2.11 and prior, UNIVERGE…

  • CVE-2022-23730CriMar 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The public API error causes for the attacker to be able to bypass API access control.

  • CVE-2021-44620CriMar 11, 2022
    risk 0.64cvss 9.8epss 0.01

    A Command Injection vulnerability exits in TOTOLINK A3100R <=V4.1.2cu.5050_B20200504 in adm/ntm.asp via the hosTime parameters.