VYPR

CVEs

38,073 total · page 481 of 762

  • CVE-2022-25402CriFeb 24, 2022
    risk 0.59cvss 9.1epss 0.02

    An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.

  • CVE-2022-25098CriFeb 24, 2022
    risk 0.59cvss 9.1epss 0.01

    ECTouch v2 suffers from arbitrary file deletion due to insufficient filtering of the filename parameter.

  • CVE-2022-25084CriFeb 24, 2022
    risk 0.66cvss 9.8epss 0.25

    TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25083CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLink A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25082CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.16

    TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25081CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLink T10 V5.9c.5061_B20200511 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25080CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25079CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLink A810R V4.1.2cu.5182_B20201026 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25078CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25077CriFeb 24, 2022
    risk 0.66cvss 9.8epss 0.33

    TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25076CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25075CriFeb 24, 2022
    risk 0.68cvss 9.8epss 0.56

    TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2022-25074CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.13

    TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.

  • CVE-2022-25073CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.13

    TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.

  • CVE-2022-25072CriFeb 24, 2022
    risk 0.65cvss 9.8epss 0.13

    TP-Link Archer A54 Archer A54(US)_V1_210111 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.

  • CVE-2022-21142CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.02

    Authentication bypass vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versions prior to Ver.2.9.39, Ver.2.10.x series versions prior to Ver.2.10.43, and Ver.2.11.x series versions prior to Ver.2.11.41 allows a remote unauthenticated…

  • CVE-2021-44610CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.01

    Multiple SQL Injection vulnerabilities exist in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) URLs, (2) lang_id, (3) tmpl_id, (4) mod_rewrite (5) eta_doctype. (6) meta_charset, (7) default_group, and (8) page group parameters in the settings mode in admin/index.php.

  • CVE-2021-44567CriFeb 24, 2022
    risk 0.69cvss 9.8epss 0.23

    An unauthenticated SQL Injection vulnerability exists in RosarioSIS before 7.6.1 via the votes parameter in ProgramFunctions/PortalPollsNotes.fnc.php.

  • CVE-2021-44550CriFeb 24, 2022
    risk 0.57cvss 9.8epss 0.01

    An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).

  • CVE-2022-25330CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.05

    Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the process or achieve remote code execution.

  • CVE-2022-25329CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.03

    Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and…

  • CVE-2021-35689CriFeb 24, 2022
    risk 0.64cvss 9.8epss 0.02

    A potential vulnerability in the Oracle Talent Acquisition Cloud - Taleo Enterprise Edition. This high severity potential vulnerability allows attackers to perform remote code execution on Taleo Enterprise Edition system. Successful attacks of this vulnerability can result in…

  • CVE-2021-4070CriFeb 23, 2022
    risk 0.52cvss 9.1epss 0.01

    Off-by-one Error in GitHub repository v2fly/v2ray-core prior to 4.44.0.

  • CVE-2022-0717CriFeb 23, 2022
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in GitHub repository mruby/mruby prior to 3.2.

  • CVE-2021-27797CriFeb 21, 2022
    risk 0.64cvss 9.8epss 0.01

    Brocade Fabric OS before Brocade Fabric OS v8.2.1c, v8.1.2h, and all versions of Brocade Fabric OS v8.0.x and v7.x contain documented hard-coded credentials, which could allow attackers to gain access to the system.

  • CVE-2022-24553CriFeb 21, 2022
    risk 0.64cvss 9.8epss 0.03

    An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execution.

  • CVE-2021-24867CriFeb 21, 2022
    risk 0.65cvss 9.8epss 0.18

    Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were…

  • CVE-2022-0691CriFeb 21, 2022
    risk 0.57cvss 9.8epss 0.02

    Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.

  • CVE-2022-23848CriFeb 20, 2022
    risk 0.64cvss 9.8epss 0.01

    In Alluxio before 2.7.3, the logserver does not validate the input stream. NOTE: this is not the same as the CVE-2021-44228 Log4j vulnerability.

  • CVE-2022-0686CriFeb 20, 2022
    risk 0.52cvss 9.1epss 0.02

    Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.

  • CVE-2016-1239CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.01

    duck before 0.10 did not properly handle loading of untrusted code from the current directory.

  • CVE-2022-25137CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2022-25136CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2022-25135CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.03

    A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2022-25134CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.03

    A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2022-25133CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.03

    A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2022-25132CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.03

    A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2022-25131CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the function recvSlaveCloudCheckStatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2022-25130CriFeb 19, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the function updateWifiInfo of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015 and T10 V2_Firmware V4.1.8cu.5207_B20210320 allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2021-29656CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation. The allow list is not properly checked.

  • CVE-2021-29655CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks. Thus, untrusted code may execute.

  • CVE-2021-46110CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Shopping Portal v3.1 was discovered to contain multiple time-based SQL injection vulnerabilities via the email and contactno parameters.

  • CVE-2022-24049CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.07

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 systems). Authentication is not required to exploit this vulnerability. The specific flaw exists within…

  • CVE-2022-24047CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.02

    This vulnerability allows remote attackers to bypass authentication on affected installations of BMC Track-It! 20.21.01.102. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authorization of HTTP requests. The issue results from…

  • CVE-2022-0543CriKEVFeb 18, 2022
    risk 0.88cvss 10.0epss 0.99

    It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.

  • CVE-2021-46063CriFeb 18, 2022
    risk 0.59cvss 9.1epss 0.03

    MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.

  • CVE-2021-46036CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.04

    An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.

  • CVE-2022-25337CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Ibexa DXP ezsystems/ezpublish-kernel 7.5.x before 7.5.26 and 1.3.x before 1.3.12 allows injection attacks via image filenames.

  • CVE-2022-21215CriFeb 18, 2022
    risk 0.65cvss 10.0epss 0.01

    This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server, or request pages that could perform some actions themselves. The attacker could force the server…

  • CVE-2022-21196CriFeb 18, 2022
    risk 0.65cvss 10.0epss 0.04

    MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An attacker may gain access to these API…