VYPR

CVEs

38,073 total · page 479 of 762

  • CVE-2022-0441CriMar 7, 2022
    risk 0.67cvss 9.8epss 0.85

    The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin

  • CVE-2022-0434CriMar 7, 2022
    risk 0.65cvss 9.8epss 0.15

    The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL…

  • CVE-2022-0349CriMar 7, 2022
    risk 0.66cvss 9.8epss 0.34

    The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection

  • CVE-2022-0767CriMar 7, 2022
    risk 0.57cvss 9.9epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

  • CVE-2022-0766CriMar 7, 2022
    risk 0.57cvss 9.8epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

  • CVE-2021-46704CriMar 6, 2022
    risk 0.58cvss 9.8epss 0.22

    In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from insufficient input validation combined with a missing authorization check.

  • CVE-2022-26496CriMar 6, 2022
    risk 0.64cvss 9.8epss 0.04

    In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO or NBD_OPT_GO message with an large value as the length of the name.

  • CVE-2022-26495CriMar 6, 2022
    risk 0.64cvss 9.8epss 0.03

    In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists…

  • CVE-2021-46703CriMar 6, 2022
    risk 0.64cvss 9.8epss 0.02

    In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer…

  • CVE-2022-0845CriMar 5, 2022
    risk 0.57cvss 9.8epss 0.01

    Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.

  • CVE-2022-25069CriMar 5, 2022
    risk 0.00cvss 9.6epss 0.02

    Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.

  • CVE-2022-25312CriMar 5, 2022
    risk 0.59cvss 9.1epss 0.03

    An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions < 2.7. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with…

  • CVE-2021-46384CriMar 4, 2022
    risk 0.64cvss 9.8epss 0.02

    https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated…

  • CVE-2021-32008CriMar 4, 2022
    risk 0.64cvss 9.9epss 0.01

    This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.

  • CVE-2022-26318CriKEVMar 4, 2022
    risk 0.85cvss 9.8epss 0.78

    On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

  • CVE-2022-0839CriMar 4, 2022
    risk 0.57cvss 9.8epss 0.03

    Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.

  • CVE-2022-26201CriMar 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Victor CMS v1.0 was discovered to contain a SQL injection vulnerability.

  • CVE-2021-46394CriMar 4, 2022
    risk 0.64cvss 9.8epss 0.03

    There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v13 variable is directly retrieved from the http request parameter startIp. Then v13 will be splice to stack by function sscanf without any security check,…

  • CVE-2021-46393CriMar 4, 2022
    risk 0.65cvss 9.8epss 0.16

    There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v10 variable is directly retrieved from the http request parameter startIp. Then v10 will be splice to stack by function sscanf without any security…

  • CVE-2022-0848CriMar 4, 2022
    risk 0.06cvss 9.8epss 0.35

    OS Command Injection in GitHub repository part-db/part-db prior to 0.5.11.

  • CVE-2022-0730CriMar 3, 2022
    risk 0.64cvss 9.8epss 0.04

    Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.

  • CVE-2022-22947CriKEVMar 3, 2022
    risk 0.81cvss 10.0epss 0.98

    In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote…

  • CVE-2022-0265CriMar 3, 2022
    risk 0.57cvss 9.8epss 0.03

    Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.

  • CVE-2021-3762CriMar 3, 2022
    risk 0.57cvss 9.8epss 0.05

    A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentially allowing for remote code execution.

  • CVE-2022-25125CriMar 3, 2022
    risk 0.64cvss 9.8epss 0.07

    MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.

  • CVE-2022-23899CriMar 3, 2022
    risk 0.64cvss 9.8epss 0.01

    MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.

  • CVE-2022-23898CriMar 3, 2022
    risk 0.64cvss 9.8epss 0.08

    MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.

  • CVE-2022-0841CriMar 3, 2022
    risk 0.57cvss 9.8epss 0.03

    OS Command Injection in GitHub repository ljharb/npm-lockfile in v2.0.3 and v2.0.4.

  • CVE-2022-25089CriMar 3, 2022
    risk 0.68cvss 9.8epss 0.18

    Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL_MACHINE via UITasks.PersistentRegistryData.

  • CVE-2022-26171CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Bank Management System v1.o was discovered to contain a SQL injection vulnerability via the email parameter.

  • CVE-2022-26170CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.

  • CVE-2022-26169CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Air Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter.

  • CVE-2022-25399CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.

  • CVE-2022-25398CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Auto Spare Parts Management v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.

  • CVE-2022-25396CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.

  • CVE-2022-25395CriMar 2, 2022
    risk 0.62cvss 9.6epss 0.01

    Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) attacks via the search parameter under the /cbpos/ app.

  • CVE-2022-25394CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.02

    Medical Store Management System v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter under customer-add.php.

  • CVE-2022-25045CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Home Owners Collection Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel.

  • CVE-2022-23640CriMar 2, 2022
    risk 0.57cvss 9.8epss 0.01

    Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser that was used did apply all the necessary settings to prevent XML Entity Expansion issues. Upgrade to version 2.1.0 to receive a…

  • CVE-2022-23878CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.02

    seacms V11.5 is affected by an arbitrary code execution vulnerability in admin_config.php.

  • CVE-2022-25016CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.02

    Home Owners Collection Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /student_attendance/index.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-24306CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.02

    Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.

  • CVE-2022-24305CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.03

    Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation.

  • CVE-2022-25010CriMar 1, 2022
    risk 0.00cvss 9.1epss 0.01

    The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.

  • CVE-2022-24720CriMar 1, 2022
    risk 0.57cvss 9.8epss 0.03

    image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, using the `#apply` method from image_processing to apply a series of operations that are coming from unsanitized user input allows the attacker to execute shell…

  • CVE-2021-41193CriMar 1, 2022
    risk 0.57cvss 9.8epss 0.02

    wire-avs is the audio visual signaling (AVS) component of Wire, an open-source messenger. A remote format string vulnerability in versions prior to 7.1.12 allows an attacker to cause a denial of service or possibly execute arbitrary code. The issue has been fixed in wire-avs…

  • CVE-2021-36166CriMar 1, 2022
    risk 0.64cvss 9.8epss 0.01

    An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's properties.

  • CVE-2021-4039CriMar 1, 2022
    risk 0.72cvss 9.8epss 0.71

    A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.

  • CVE-2021-42767CriMar 1, 2022
    risk 0.59cvss 9.1epss 0.02

    A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1.

  • CVE-2020-12775CriMar 1, 2022
    risk 0.64cvss 9.8epss 0.03

    Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injection attack to execute arbitrary system command, disrupt…