VYPR

CVEs

38,073 total · page 482 of 762

  • CVE-2022-21141CriFeb 18, 2022
    risk 0.65cvss 10.0epss 0.03

    MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization checks on multiple API functions. An attacker may gain access to these functions and achieve…

  • CVE-2022-0671CriFeb 18, 2022
    risk 0.59cvss 9.1epss 0.01

    A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file.

  • CVE-2021-45401CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.03

    A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.03.06.49_multi via the setUsbUnload functionality. The vulnerability is caused because the client controlled "deviceName" value is passed directly to the…

  • CVE-2021-3657CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.03

    A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals, malicious or compromised IMAP servers, and hypothetically even external email senders, could cause several different buffer overflows, which could…

  • CVE-2021-20325CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.02

    Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux…

  • CVE-2022-25322CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.08

    ZEROF Web Server 2.0 allows /HandleEvent SQL Injection.

  • CVE-2022-0664CriFeb 18, 2022
    risk 0.57cvss 9.8epss 0.02

    Use of Hard-coded Cryptographic Key in Go github.com/gravitl/netmaker prior to 0.8.5,0.9.4,0.10.0,0.10.1.

  • CVE-2022-0631CriFeb 18, 2022
    risk 0.00cvss 9.8epss 0.01

    Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.

  • CVE-2022-25299CriFeb 18, 2022
    risk 0.00cvss 9.8epss 0.01

    This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.

  • CVE-2022-25315CriFeb 18, 2022
    risk 0.00cvss 9.8epss 0.05

    In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

  • CVE-2022-22922CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.01

    TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable session keys, allowing attackers to gain administrative privileges.

  • CVE-2022-22916CriFeb 17, 2022
    risk 0.67cvss 9.8epss 0.39

    O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke.

  • CVE-2021-46319CriFeb 17, 2022
    risk 0.64cvss 9.8epss 0.07

    Remote Code Execution (RCE) vulnerability exists in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicious users can use this vulnerability to use "\ " or backticks to bypass the shell metacharacters in the ssid0 or ssid1 parameters to execute…

  • CVE-2021-46315CriFeb 17, 2022
    risk 0.64cvss 9.8epss 0.07

    Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin. Malicoius users can use this vulnerability to use "\ " or backticks in the shell metacharacters in the…

  • CVE-2021-46314CriFeb 17, 2022
    risk 0.66cvss 9.8epss 0.33

    A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin because backticks can be used for command injection when judging whether it is a reasonable…

  • CVE-2021-45382CriKEVFeb 17, 2022
    risk 0.84cvss 9.8epss 0.98

    A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions,…

  • CVE-2022-22912CriFeb 17, 2022
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability via .parse() in Plist before v3.0.4 allows attackers to cause a Denial of Service (DoS) and may lead to remote code execution.

  • CVE-2021-44868CriFeb 17, 2022
    risk 0.64cvss 9.8epss 0.01

    A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do

  • CVE-2022-0623CriFeb 17, 2022
    risk 0.00cvss 9.1epss 0.02

    Out-of-bounds Read in Homebrew mruby prior to 3.2.

  • CVE-2022-24984CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.03

    Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executable files and achieve remote code execution. This occurs because file-extension checks occur on the client side, and because not all…

  • CVE-2022-22885CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Hutool v5.7.18's HttpRequest was discovered to ignore all TLS/SSL certificate validation.

  • CVE-2022-22881CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserComponentData.

  • CVE-2022-22880CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.

  • CVE-2021-43303CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer overflow, since supplying an output buffer smaller than 128 characters may overflow the output buffer, regardless of the 'maxlen' argument supplied

  • CVE-2021-43302CriFeb 16, 2022
    risk 0.59cvss 9.1epss 0.02

    Read out-of-bounds in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause an out-of-bounds read when the filename is shorter than 4 characters.

  • CVE-2021-43301CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Stack overflow in PJSUA API when calling pjsua_playlist_create. An attacker-controlled 'file_names' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.

  • CVE-2021-43300CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.

  • CVE-2021-43299CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.02

    Stack overflow in PJSUA API when calling pjsua_player_create. An attacker-controlled 'filename' argument may cause a buffer overflow since it is copied to a fixed-size stack buffer without any size validation.

  • CVE-2021-3242CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.01

    DuxCMS v3.1.3 was discovered to contain a SQL injection vulnerability via the component s/tools/SendTpl/index?keyword=.

  • CVE-2021-3781CriFeb 16, 2022
    risk 0.71cvss 9.9epss 0.84

    A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting a specially crafted pipe command. This flaw allows a specially crafted document to execute arbitrary commands on the system in the context of the ghostscript…

  • CVE-2021-3773CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.05

    A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.

  • CVE-2022-24665CriFeb 16, 2022
    risk 0.65cvss 9.9epss 0.03

    PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg block by any user able to edit posts.

  • CVE-2022-24664CriFeb 16, 2022
    risk 0.64cvss 9.9epss 0.02

    PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.

  • CVE-2022-24663CriFeb 16, 2022
    risk 0.65cvss 9.9epss 0.02

    PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, which can be used by any authenticated user.

  • CVE-2022-24086CriKEVFeb 16, 2022
    risk 0.84cvss 9.8epss 0.99

    Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

  • CVE-2022-0513CriFeb 16, 2022
    risk 0.68cvss 9.8epss 0.53

    The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without authentication to inject arbitrary…

  • CVE-2022-23358CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.01

    EasyCMS v1.6 allows for SQL injection via ArticlemAction.class.php. In the background, search terms provided by the user were not sanitized and were used directly to construct a SQL statement.

  • CVE-2022-0559CriFeb 16, 2022
    risk 0.00cvss 9.8epss 0.01

    Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.

  • CVE-2022-25236CriFeb 16, 2022
    risk 0.03cvss 9.8epss 0.34

    xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

  • CVE-2022-25235CriFeb 16, 2022
    risk 0.00cvss 9.8epss 0.05

    xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.

  • CVE-2021-46250CriFeb 15, 2022
    risk 0.00cvss 10.0epss 0.01

    An issue in SOA2Login::commented of ScratchOAuth2 before commit a91879bd58fa83b09283c0708a1864cdf067c64a allows attackers to authenticate as other users on downstream components that rely on ScratchOAuth2.

  • CVE-2021-46321CriFeb 15, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wifiBasicCfg module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

  • CVE-2021-46265CriFeb 15, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wanBasicCfg module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

  • CVE-2021-46264CriFeb 15, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the onlineList module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

  • CVE-2021-46263CriFeb 15, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the wifiTime module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

  • CVE-2021-46262CriFeb 15, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda AC Series Router AC11_V02.03.01.104_CN was discovered to contain a stack buffer overflow in the PPPoE module. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

  • CVE-2021-37354CriFeb 15, 2022
    risk 0.64cvss 9.8epss 0.01

    Xerox Phaser 4622 v35.013.01.000 was discovered to contain a buffer overflow in the function sub_3226AC via the TIMEZONE variable. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

  • CVE-2021-33945CriFeb 15, 2022
    risk 0.64cvss 9.8epss 0.02

    RICOH Printer series SP products 320DN, SP 325DNw, SP 320SN, SP 320SFN, SP 325SNw, SP 325SFNw, SP 330SN, Aficio SP 3500SF, SP 221S, SP 220SNw, SP 221SNw, SP 221SF, SP 220SFNw, SP 221SFNw v1.06 were discovered to contain a stack buffer overflow in the file…

  • CVE-2022-22770CriFeb 15, 2022
    risk 0.64cvss 9.8epss 0.01

    The Web Server component of TIBCO Software Inc.'s TIBCO AuditSafe contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute API methods on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO AuditSafe:…

  • CVE-2021-43049CriFeb 15, 2022
    risk 0.64cvss 9.8epss 0.01

    The Database component of TIBCO Software Inc.'s TIBCO BusinessConnect Container Edition contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to obtain the usernames and passwords of users of the affected system. Affected…