VYPR

CVEs

38,073 total · page 484 of 762

  • CVE-2021-45364CriFeb 10, 2022
    risk 0.64cvss 9.8epss 0.02

    A Code Execution vulnerability exists in Statamic Version through 3.2.26 via SettingsController.php. NOTE: the vendor indicates that there was an error in publishing this CVE Record, and that all parties agree that the affected code was not used in any Statamic product

  • CVE-2022-20749CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.04

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20712CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.03

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20711CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.05

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20710CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.02

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20709CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.04

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20708CriKEVFeb 10, 2022
    risk 0.78cvss 10.0epss 0.15

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20707CriFeb 10, 2022
    risk 0.74cvss 10.0epss 0.75

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20706CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.06

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20705CriFeb 10, 2022
    risk 0.74cvss 10.0epss 0.80

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20704CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.02

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20703CriKEVFeb 10, 2022
    risk 0.78cvss 10.0epss 0.09

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20702CriFeb 10, 2022
    risk 0.65cvss 10.0epss 0.05

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20701CriKEVFeb 10, 2022
    risk 0.78cvss 10.0epss 0.10

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20700CriKEVFeb 10, 2022
    risk 0.77cvss 10.0epss 0.06

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2022-20699CriKEVFeb 10, 2022
    risk 0.86cvss 10.0epss 0.72

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and…

  • CVE-2021-25992CriFeb 10, 2022
    risk 0.64cvss 9.8epss 0.02

    In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetical attacks.

  • CVE-2022-24313CriFeb 9, 2022
    risk 0.67cvss 9.8epss 0.45

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data…

  • CVE-2022-24312CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.03

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by adding at end of file or create a new file in the context of the Data Server potentially leading to remote code execution when an…

  • CVE-2022-24311CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.04

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by inserting at beginning of file or create a new file in the context of the Data Server potentially leading to remote code execution when…

  • CVE-2022-24310CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.02

    A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Product: Interactive Graphical…

  • CVE-2022-22813CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.01

    A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the Courier tunneling communication network, they could potentially observe and manipulate traffic associated with product…

  • CVE-2022-22810CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.01

    A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials. Affected Product: spaceLYnk (V2.6.2 and prior), Wiser for KNX (formerly homeLYnk)…

  • CVE-2022-22544CriFeb 9, 2022
    risk 0.59cvss 9.1epss 0.01

    Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents and browse files on their systems. An attacker could thereby control the managed systems. It is considered that this is a missing…

  • CVE-2022-22536CriKEVFeb 9, 2022
    risk 0.88cvss 10.0epss 0.98

    SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary…

  • CVE-2022-22532CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.02

    In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, KERNEL 7.22, 7.49, 7.53, an unauthenticated attacker could submit a crafted HTTP server request which triggers improper shared memory buffer handling. This…

  • CVE-2021-39997CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a vulnerability of unstrict input parameter verification in the audio assembly.Successful exploitation of this vulnerability may cause out-of-bounds access.

  • CVE-2021-39994CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.01

    There is an arbitrary address access vulnerability with the product line test code.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

  • CVE-2022-23631CriFeb 9, 2022
    risk 0.59cvss 9.0epss 0.02

    superjson is a program to allow JavaScript expressions to be serialized to a superset of JSON. In versions prior to 1.8.1 superjson allows input to run arbitrary code on any server using superjson input without prior authentication or knowledge. The only requirement is that the…

  • CVE-2021-36302CriFeb 9, 2022
    risk 0.64cvss 9.9epss 0.01

    All Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability. A remote malicious user with standard level JEA credentials may potentially exploit this vulnerability to elevate privileges and take over the system.

  • CVE-2021-45331CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.01

    An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.

  • CVE-2021-45330CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.

  • CVE-2022-0525CriFeb 9, 2022
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in Homebrew mruby prior to 3.2.

  • CVE-2022-24677CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.02

    Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php.

  • CVE-2022-0139CriFeb 8, 2022
    risk 0.00cvss 9.8epss 0.01

    Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.

  • CVE-2021-45327CriFeb 8, 2022
    risk 0.57cvss 9.8epss 0.02

    Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.

  • CVE-2022-23340CriFeb 8, 2022
    risk 0.57cvss 9.8epss 0.02

    Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results.

  • CVE-2022-21241CriFeb 8, 2022
    risk 0.63cvss 9.6epss 0.03

    Cross-site scripting vulnerability in CSV+ prior to 0.8.1 allows a remote unauthenticated attacker to inject an arbitrary script or an arbitrary OS command via a specially crafted CSV file that contains HTML a tag.

  • CVE-2021-42833CriFeb 7, 2022
    risk 0.60cvss 9.3epss 0.00

    A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manipulate users and system settings.

  • CVE-2021-25114CriFeb 7, 2022
    risk 0.63cvss 9.8epss 0.82

    The Paid Memberships Pro WordPress plugin before 2.6.7 does not escape the discount_code in one of its REST route (available to unauthenticated users) before using it in a SQL statement, leading to a SQL injection

  • CVE-2021-43928CriFeb 7, 2022
    risk 0.64cvss 9.9epss 0.02

    Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in mail sending and receiving component in Synology Mail Station before 20211105-10315 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

  • CVE-2022-24552CriFeb 6, 2022
    risk 0.64cvss 9.8epss 0.01

    A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input parameters. Some of them go directly to bash as part of a script. An attacker with non-root user access can inject arbitrary data into the command that will…

  • CVE-2022-22832CriFeb 6, 2022
    risk 0.68cvss 9.8epss 0.14

    An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/users/ request.

  • CVE-2022-22831CriFeb 6, 2022
    risk 0.68cvss 9.8epss 0.11

    An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Authorization HTTP header.

  • CVE-2021-41816CriFeb 6, 2022
    risk 0.57cvss 9.8epss 0.05

    CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem before 0.3.1 for Ruby.

  • CVE-2013-20004CriFeb 6, 2022
    risk 0.64cvss 9.8epss 0.01

    A flaw was found in StarWind iSCSI target. StarWind service does not limit client connections and allocates memory on each connection attempt. An attacker could create a denial of service state by trying to connect a non-existent target multiple times. This affects iSCSI SAN…

  • CVE-2021-38172CriFeb 5, 2022
    risk 0.64cvss 9.8epss 0.02

    perM 0.4.0 has a Buffer Overflow related to strncpy. (Debian initially fixed this in 0.4.0-7.)

  • CVE-2022-23379CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid().

  • CVE-2022-22987CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.01

    The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server login and perform further actions.

  • CVE-2022-0365CriFeb 4, 2022
    risk 0.59cvss 9.1epss 0.02

    The affected product is vulnerable to an authenticated OS command injection, which may allow an attacker to inject and execute arbitrary shell commands as the Admin (root) user.