VYPR

CVEs

38,073 total · page 478 of 762

  • CVE-2021-44618CriMar 11, 2022
    risk 0.57cvss 9.8epss 0.01

    A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php via the host header.

  • CVE-2022-0860CriMar 11, 2022
    risk 0.52cvss 9.1epss 0.02

    Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.

  • CVE-2022-0871CriMar 11, 2022
    risk 0.52cvss 9.1epss 0.01

    Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.

  • CVE-2022-23402CriMar 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00

  • CVE-2022-21194CriMar 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial configuration: CENTUM VP versions from R5.01.00 to R5.04.20 and versions from R6.01.00 to R6.08.0, Exaopc versions from R3.72.00 to R3.79.00.

  • CVE-2022-26520CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP…

  • CVE-2022-26143CriKEVMar 10, 2022
    risk 0.83cvss 9.8epss 0.87

    The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in…

  • CVE-2022-26131CriMar 10, 2022
    risk 0.61cvss 9.3epss 0.01

    Power Line Communications PLC4TRUCKS J2497 trailer receivers are susceptible to remote RF induced signals.

  • CVE-2022-26100CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR process may crash, and the attacker may obtain privileged access to the system.

  • CVE-2022-24995CriMar 10, 2022
    risk 0.65cvss 9.8epss 0.14

    Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the time parameter.

  • CVE-2022-24652CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in php code execution in /admin/upload/upload.

  • CVE-2022-24651CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, resulting in PHP code execution through /user/upload/upload.

  • CVE-2022-24609CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file.

  • CVE-2022-24607CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php.

  • CVE-2022-24606CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php.

  • CVE-2022-24605CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php.

  • CVE-2022-24604CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.

  • CVE-2022-24603CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php.

  • CVE-2022-24602CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.

  • CVE-2022-24600CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL injection statements.

  • CVE-2022-24193CriMar 10, 2022
    risk 0.57cvss 9.8epss 0.06

    CasaOS before v0.2.7 was discovered to contain a command injection vulnerability.

  • CVE-2022-23383CriMar 10, 2022
    risk 0.59cvss 9.1epss 0.01

    YzmCMS v6.3 is affected by broken access control. Without login, unauthorized access to the user's personal home page can be realized. It is necessary to judge the user's login status before accessing the personal home page, but the vulnerability can access other users' home…

  • CVE-2022-22814CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    The System Diagnosis service of MyASUS before 3.1.2.0 allows privilege escalation.

  • CVE-2021-4045CriMar 10, 2022
    risk 0.72cvss 9.8epss 0.72

    TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera.

  • CVE-2021-44632CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/upgrade_info feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.

  • CVE-2021-44631CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/reset_cloud_pwd feature, which allows malicous users to execute arbitrary code on the system via a crafted post request.

  • CVE-2021-44630CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/modify_account_pwd feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.

  • CVE-2021-44629CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    A Buffer Overflow vulnerabilitiy exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/register feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.

  • CVE-2021-44628CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    A Buffer Overflow vulnerabiltiy exists in TP-LINK WR-886N 20190826 2.3.8 in thee /cloud_config/router_post/login feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.

  • CVE-2021-44627CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/get_reset_pwd_veirfy_code feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.

  • CVE-2021-44626CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/get_reg_verify_code feature, which allows malicious users to execute arbitrary code on the system via a crafted post request.

  • CVE-2021-44625CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in /cloud_config/cloud_device/info interface, which allows a malicious user to executee arbitrary code on the system via a crafted post request.

  • CVE-2021-44623CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 via the /cloud_config/router_post/check_reset_pwd_verify_code interface.

  • CVE-2021-44622CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.03

    A Buffer Overflow vulnerability exists in TP-LINK WR-886N 20190826 2.3.8 in the /cloud_config/router_post/check_reg_verify_code function which could let a remove malicious user execute arbitrary code via a crafted post request.

  • CVE-2021-42854CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" API. The affected endpoint does not have any input validation of the user's input that allows a…

  • CVE-2021-42853CriMar 10, 2022
    risk 0.59cvss 9.1epss 0.02

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent/diagnostic/logs" API. The affected endpoint does not have any input validation of the user's input…

  • CVE-2021-42787CriMar 10, 2022
    risk 0.61cvss 9.4epss 0.01

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/configuration" API. The affected endpoint does not have any input validation of the user's…

  • CVE-2021-42786CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.02

    It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) has Remote Code Execution vulnerabilities in multiple instances of the API requests. The affected endpoints do not have any input validation of the user's input that allowed a malicious payload to…

  • CVE-2021-40053CriMar 10, 2022
    risk 0.59cvss 9.1epss 0.01

    There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity.

  • CVE-2021-40050CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    There is an out-of-bounds read vulnerability in the IFAA module. Successful exploitation of this vulnerability may cause stack overflow.

  • CVE-2021-33293CriMar 10, 2022
    risk 0.59cvss 9.1epss 0.02

    Panorama Tools libpano13 v2.9.20 was discovered to contain an out-of-bounds read in the function panoParserFindOLine() in parser.c.

  • CVE-2020-14115CriMar 10, 2022
    risk 0.64cvss 9.8epss 0.01

    A command injection vulnerability exists in the Xiaomi Router AX3600. The vulnerability is caused by a lack of inspection for incoming data detection. Attackers can exploit this vulnerability to execute code.

  • CVE-2022-0895CriMar 10, 2022
    risk 0.57cvss 9.8epss 0.02

    Static Code Injection in GitHub repository microweber/microweber prior to 1.3.

  • CVE-2022-22806CriMar 9, 2022
    risk 0.65cvss 9.8epss 0.12

    A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause an unauthenticated connection to the UPS when a malformed connection is sent. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and prior), SMC Series (SMC…

  • CVE-2022-22805CriMar 9, 2022
    risk 0.65cvss 9.8epss 0.12

    A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause remote code execution when an improperly handled TLS packet is reassembled. Affected Product: SmartConnect Family: SMT Series (SMT Series ID=1015: UPS 04.5 and…

  • CVE-2022-0715CriMar 9, 2022
    risk 0.60cvss 9.1epss 0.06

    A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to arbitrarily change the behavior of the UPS when a key is leaked and used to upload malicious firmware. Affected Product: APC Smart-UPS Family: SMT Series (SMT Series ID=18: UPS 09.8 and prior…

  • CVE-2022-0482CriMar 9, 2022
    risk 0.59cvss 9.1epss 0.44

    Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.

  • CVE-2022-26314CriMar 8, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are generated in an insecure manner. This could allow an…

  • CVE-2022-26313CriMar 8, 2022
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1). In certain configurations of the affected product, a threat actor could use the sign up flow to hijack arbitrary user accounts.

  • CVE-2021-37208CriMar 8, 2022
    risk 0.62cvss 9.6epss 0.01

    A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM…