VYPR

CVEs

38,073 total · page 480 of 762

  • CVE-2022-25411CriFeb 28, 2022
    risk 0.64cvss 9.8epss 0.03

    A Remote Code Execution (RCE) vulnerability at /admin/options in Maxsite CMS v180 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2021-45414CriFeb 28, 2022
    risk 0.64cvss 9.8epss 0.04

    A Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment or Java driver.

  • CVE-2022-24711CriFeb 28, 2022
    risk 0.54cvss 9.4epss 0.01

    CodeIgniter4 is the 4.x branch of CodeIgniter, a PHP full-stack web framework. Prior to version 4.1.9, an improper input validation vulnerability allows attackers to execute CLI routes via HTTP request. Version 4.1.9 contains a patch. There are currently no known workarounds for…

  • CVE-2021-43086CriFeb 28, 2022
    risk 0.64cvss 9.8epss 0.01

    ARM astcenc 3.2.0 is vulnerable to Buffer Overflow. When the compression function of the astc-encoder project with -cl option was used, a stack-buffer-overflow occurred in function encode_ise() in function compress_symbolic_block_for_partition_2planes() in…

  • CVE-2022-24571CriFeb 28, 2022
    risk 0.64cvss 9.8epss 0.02

    Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access.

  • CVE-2022-0768CriFeb 28, 2022
    risk 0.52cvss 9.1epss 0.02

    Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.

  • CVE-2022-0412CriFeb 28, 2022
    risk 0.70cvss 9.8epss 0.74

    The TI WooCommerce Wishlist WordPress plugin before 1.40.1, TI WooCommerce Wishlist Pro WordPress plugin before 1.40.1 do not sanitise and escape the item_id parameter before using it in a SQL statement via the wishlist/remove_product REST endpoint, allowing unauthenticated…

  • CVE-2021-25010CriFeb 28, 2022
    risk 0.62cvss 9.6epss 0.01

    The Post Snippets WordPress plugin before 3.1.4 does not have CSRF check when importing files, allowing attacker to make a logged In admin import arbitrary snippets. Furthermore, imported snippers are not sanitised and escaped, which could lead to Stored Cross-Site Scripting…

  • CVE-2022-25359CriFeb 26, 2022
    risk 0.65cvss 9.1epss 0.37

    On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.

  • CVE-2022-25096CriFeb 26, 2022
    risk 0.64cvss 9.8epss 0.02

    Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php.

  • CVE-2022-25095CriFeb 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Home Owners Collection Management System v1.0 allows unauthenticated attackers to compromise user accounts via a crafted POST request.

  • CVE-2022-25263CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.02

    JetBrains TeamCity before 2021.2.3 was vulnerable to OS command injection in the Agent Push feature configuration.

  • CVE-2022-25262CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    In JetBrains Hub before 2022.1.14434, SAML request takeover was possible.

  • CVE-2022-25260CriFeb 25, 2022
    risk 0.59cvss 9.1epss 0.02

    JetBrains Hub before 2021.1.14276 was vulnerable to blind Server-Side Request Forgery (SSRF).

  • CVE-2022-25064CriFeb 25, 2022
    risk 0.67cvss 9.8epss 0.36

    TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

  • CVE-2022-25061CriFeb 25, 2022
    risk 0.69cvss 9.8epss 0.59

    TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

  • CVE-2022-25060CriFeb 25, 2022
    risk 0.68cvss 9.8epss 0.40

    TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.

  • CVE-2022-24442CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.04

    JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

  • CVE-2021-42952CriFeb 25, 2022
    risk 0.64cvss 9.9epss 0.02

    Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata…

  • CVE-2021-40046CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    PCManager versions 11.1.1.95 has a privilege escalation vulnerability. Successful exploit could allow the attacker to access certain resource beyond its privilege.

  • CVE-2021-22480CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    The interface of a certain HarmonyOS module has an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to heap memory overflow.

  • CVE-2021-22448CriFeb 25, 2022
    risk 0.59cvss 9.1epss 0.01

    There is an improper verification vulnerability in smartphones. Successful exploitation of this vulnerability may cause unauthorized read and write of some files.

  • CVE-2021-22434CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a memory address out of bounds vulnerability in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.

  • CVE-2021-22433CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.

  • CVE-2021-22432CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.

  • CVE-2021-22431CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a vulnerability when configuring permission isolation in smartphones. Successful exploitation of this vulnerability may cause out-of-bounds access.

  • CVE-2021-22430CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a logic bypass vulnerability in smartphones. Successful exploitation of this vulnerability may cause code injection.

  • CVE-2021-22429CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.

  • CVE-2021-22426CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a memory address out of bounds in smartphones. Successful exploitation of this vulnerability may cause malicious code to be executed.

  • CVE-2021-22394CriFeb 25, 2022
    risk 0.59cvss 9.1epss 0.01

    There is a buffer overflow vulnerability in smartphones. Successful exploitation of this vulnerability may cause DoS of the apps during Multi-Screen Collaboration.

  • CVE-2022-24340CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.

  • CVE-2022-24331CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.

  • CVE-2021-45977CriFeb 25, 2022
    risk 0.64cvss 9.8epss 0.01

    JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2021.3.1 Preview, RubyMine 2021.3.1 RC, CLion 2021.3.1, WebStorm 2021.3.1 Preview, and WebStorm…

  • CVE-2021-39363CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved.

  • CVE-2022-25149CriFeb 24, 2022
    risk 0.70cvss 9.8epss 0.77

    The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to…

  • CVE-2022-25148CriFeb 24, 2022
    risk 0.73cvss 9.8epss 0.81

    The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL…

  • CVE-2022-25004CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.02

    Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php.

  • CVE-2022-25003CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.02

    Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/view_doctor.php.

  • CVE-2022-0651CriFeb 24, 2022
    risk 0.66cvss 9.8epss 0.32

    The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL…

  • CVE-2021-44663CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.04

    A Remote Code Execution (RCE) vulnerability exists in the Xerte Project Xerte through 3.8.4 via a crafted php file through elfinder in connetor.php.

  • CVE-2020-10640CriFeb 24, 2022
    risk 0.65cvss 10.0epss 0.03

    Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.

  • CVE-2022-25809CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in the case of physically…

  • CVE-2022-25643CriFeb 24, 2022
    risk 0.00cvss 9.8epss 0.02

    seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The attack vector is a user-supplied socket pathname.

  • CVE-2022-25418CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi.

  • CVE-2022-25417CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function saveparentcontrolinfo.

  • CVE-2022-25414CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.10

    Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the parameter NPTR.

  • CVE-2022-25406CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete_query.php via the DELETE_STR parameter.

  • CVE-2022-25405CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in change_box.php via the DELETE_STR parameter.

  • CVE-2022-25404CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in delete.php via the DELETE_STR parameter.

  • CVE-2022-25403CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.02

    HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php.