VYPR

CVEs

38,073 total · page 483 of 762

  • CVE-2022-25139CriFeb 14, 2022
    risk 0.00cvss 9.8epss 0.02

    njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.

  • CVE-2022-24705CriFeb 14, 2022
    risk 0.00cvss 9.8epss 0.01

    The rad_packet_recv function in radius/packet.c suffers from a memcpy buffer overflow, resulting in an overly-large recvfrom into a fixed buffer that causes a buffer overflow and overwrites arbitrary memory. If the server connects with a malicious client, crafted client requests…

  • CVE-2022-24704CriFeb 14, 2022
    risk 0.00cvss 9.8epss 0.01

    The rad_packet_recv function in opt/src/accel-pppd/radius/packet.c suffers from a buffer overflow vulnerability, whereby user input len is copied into a fixed buffer &attr->val.integer without any bound checks. If the client connects to the server and sends a large radius…

  • CVE-2022-23992CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.02

    XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validation that could potentially allow remote attackers to execute arbitrary commands with elevated privileges.

  • CVE-2021-4201CriFeb 14, 2022
    risk 0.63cvss 9.6epss 0.02

    Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthenticated attackers to hijack sessions, including potentially admin-level sessions. This issue affects: ForgeRock Access Management 7.1 versions prior to 7.1.1;…

  • CVE-2021-46463CriFeb 14, 2022
    risk 0.00cvss 9.8epss 0.02

    njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_then().

  • CVE-2021-46461CriFeb 14, 2022
    risk 0.00cvss 9.8epss 0.03

    njs through 0.7.0, used in NGINX, was discovered to contain an out-of-bounds array access via njs_vmcode_typeof in /src/njs_vmcode.c.

  • CVE-2021-45005CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Artifex MuJS v1.1.3 was discovered to contain a heap buffer overflow which is caused by conflicting JumpList of nested try/finally statements.

  • CVE-2022-24206CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LIST parameter.

  • CVE-2022-23902CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in export_data.php via the d_name parameter.

  • CVE-2022-23390CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files.

  • CVE-2022-23389CriFeb 14, 2022
    risk 0.65cvss 9.8epss 0.22

    PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.

  • CVE-2022-23337CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.02

    DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.

  • CVE-2022-23336CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.01

    S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter.

  • CVE-2022-23335CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.02

    Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in language_general.class.php via doModifyParameter.

  • CVE-2022-22295CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.02

    Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in parameter_admin.class.php via the table_para parameter.

  • CVE-2022-24988CriFeb 14, 2022
    risk 0.64cvss 9.8epss 0.01

    In galois_2p8 before 0.1.2, PrimitivePolynomialField::new has an off-by-one buffer overflow for a vector.

  • CVE-2021-45420CriFeb 14, 2022
    risk 0.65cvss 9.8epss 0.18

    Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism,…

  • CVE-2022-24977CriFeb 14, 2022
    risk 0.57cvss 9.8epss 0.06

    ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHP_SESSION_UPLOAD_PROGRESS when the PHP…

  • CVE-2022-24976CriFeb 14, 2022
    risk 0.00cvss 9.1epss 0.02

    Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.

  • CVE-2022-0570CriFeb 14, 2022
    risk 0.00cvss 9.8epss 0.01

    Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.

  • CVE-2022-0290CriFeb 12, 2022
    risk 0.63cvss 9.6epss 0.02

    Use after free in Site isolation in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2022-0097CriFeb 12, 2022
    risk 0.62cvss 9.6epss 0.01

    Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to to potentially allow extension to escape the sandbox via a crafted HTML page.

  • CVE-2021-46362CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.05

    A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.

  • CVE-2021-46361CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.03

    An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload.

  • CVE-2021-23555CriFeb 11, 2022
    risk 0.57cvss 9.8epss 0.03

    The package vm2 before 3.9.6 are vulnerable to Sandbox Bypass via direct access to host error objects generated by node internals during generation of a stacktraces, which can lead to execution of arbitrary code on the host machine.

  • CVE-2021-20001CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.02

    It was discovered, that debian-edu-config, a set of configuration files used for the Debian Edu blend, before 2.12.16 configured insecure permissions for the user web shares (~/public_html), which could result in privilege escalation.

  • CVE-2020-26728CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.04

    A vulnerability was discovered in Tenda AC9 v3.0 V15.03.06.42_multi and Tenda AC9 V1.0 V15.03.05.19(6318)_CN which allows for remote code execution via shell metacharacters in the guestuser field to the __fastcall function with a POST request.

  • CVE-2021-39675CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.06

    In GKI_getbuf of gki_buffer.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2021-39658CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.01

    ismsEx service is a vendor service in unisoc equipment。ismsEx service is an extension of sms system service,but it does not check the permissions of the caller,resulting in permission leaks。Third-party apps can use this service to arbitrarily modify and set system…

  • CVE-2021-39635CriFeb 11, 2022
    risk 0.59cvss 9.1epss 0.01

    ims_ex is a vendor system service used to manage VoLTE in unisoc devices,But it does not verify the caller's permissions,so that normal apps (No phone permissions) can obtain some VoLTE sensitive information and manage VoLTE calls.Product: AndroidVersions: Android SoCAndroid…

  • CVE-2021-39616CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.01

    Summary:Product: AndroidVersions: Android SoCAndroid ID: A-204686438

  • CVE-2021-34235CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Tokheim Profleet DiaLOG 11.005.02 is affected by SQL Injection. The component is the Field__UserLogin parameter on the logon page.

  • CVE-2021-31932CriFeb 11, 2022
    risk 0.65cvss 9.8epss 0.22

    Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web panel, circumventing the authentication process, by using URL encoding for the . (dot) character.

  • CVE-2021-22823CriFeb 11, 2022
    risk 0.61cvss 9.1epss 0.21

    A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector…

  • CVE-2021-22805CriFeb 11, 2022
    risk 0.59cvss 9.1epss 0.01

    A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector…

  • CVE-2021-22803CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.02

    A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, when an attacker, writes arbitrary files to folders in context of the DC module, by sending constructed messages on the network.…

  • CVE-2021-22802CriFeb 11, 2022
    risk 0.65cvss 9.8epss 0.20

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on user supplied data, when a constructed message is received on the network. Affected Product: Interactive Graphical SCADA System…

  • CVE-2021-22801CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.02

    A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary command execution when the software is configured with specially crafted event actions. Affected Product: ConneXium Network Manager Software (All Versions)

  • CVE-2021-42940CriFeb 11, 2022
    risk 0.64cvss 9.9epss 0.01

    A Cross Site Scripting (XSS) vulnerability exists in Projeqtor 9.3.1 via /projeqtor/tool/saveAttachment.php, which allows an attacker to upload a SVG file containing malicious JavaScript code.

  • CVE-2020-36062CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.02

    Dairy Farm Shop Management System v1.0 was discovered to contain hardcoded credentials in the source code which allows attackers access to the control panel if compromised.

  • CVE-2020-13675CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.01

    Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker might be able to upload files that bypass the file validation process implemented by…

  • CVE-2022-24112CriKEVFeb 11, 2022
    risk 0.79cvss 9.8epss 0.96

    An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed…

  • CVE-2021-44521CriFeb 11, 2022
    risk 0.64cvss 9.1epss 0.58

    When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would…

  • CVE-2021-30317CriFeb 11, 2022
    risk 0.61cvss 9.3epss 0.01

    Improper validation of program headers containing ELF metadata can lead to image verification bypass in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon…

  • CVE-2022-24961CriFeb 11, 2022
    risk 0.00cvss 9.8epss 0.02

    In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in the past few days.

  • CVE-2022-24955CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.01

    Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.

  • CVE-2022-24954CriFeb 11, 2022
    risk 0.65cvss 9.8epss 0.12

    Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substrings.

  • CVE-2022-23806CriFeb 11, 2022
    risk 0.59cvss 9.1epss 0.03

    Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.

  • CVE-2022-24568CriFeb 10, 2022
    risk 0.64cvss 9.8epss 0.01

    Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input.