VYPR

CVEs

38,073 total · page 485 of 762

  • CVE-2021-36152CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.01

    Apache Gobblin trusts all certificates used for LDAP connections in Gobblin-as-a-Service. This affects versions <= 0.15.0. Users should update to version 0.16.0 which addresses this issue.

  • CVE-2021-21965CriFeb 4, 2022
    risk 0.61cvss 9.3epss 0.01

    A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2021-21961CriFeb 4, 2022
    risk 0.65cvss 10.0epss 0.03

    A stack-based buffer overflow vulnerability exists in the NBNS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2021-21960CriFeb 4, 2022
    risk 0.65cvss 10.0epss 0.03

    A stack-based buffer overflow vulnerability exists in both the LLMNR functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2022-23329CriFeb 4, 2022
    risk 0.65cvss 9.8epss 0.14

    A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files.

  • CVE-2021-29396CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.02

    Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication.

  • CVE-2021-29393CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "commandvalues" parameters.

  • CVE-2022-24260CriFeb 4, 2022
    risk 0.68cvss 9.8epss 0.50

    A SQL injection vulnerability in Voipmonitor GUI before v24.96 allows attackers to escalate privileges to the Administrator level.

  • CVE-2022-24259CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.02

    An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows unauthenticated attackers to escalate privileges via a crafted request.

  • CVE-2021-44978CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.02

    iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.

  • CVE-2022-24171CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetPppoeServer. This vulnerability allows attackers to execute arbitrary commands via the pppoeServerIP, pppoeServerStartIP, and pppoeServerEndIP…

  • CVE-2022-24170CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpSecTunnel. This vulnerability allows attackers to execute arbitrary commands via the IPsecLocalNet and IPsecRemoteNet parameters.

  • CVE-2022-24168CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetIpGroup. This vulnerability allows attackers to execute arbitrary commands via the IPGroupStartIP and IPGroupEndIP parameters.

  • CVE-2022-24167CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetDMZ. This vulnerability allows attackers to execute arbitrary commands via the dmzHost1 parameter.

  • CVE-2022-24165CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetQvlanList. This vulnerability allows attackers to execute arbitrary commands via the qvlanIP parameter.

  • CVE-2022-24150CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function formSetSafeWanWebMan. This vulnerability allows attackers to execute arbitrary commands via the remoteIp parameter.

  • CVE-2022-24148CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.03

    Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function mDMZSetCfg. This vulnerability allows attackers to execute arbitrary commands via the dmzIp parameter.

  • CVE-2022-24144CriFeb 4, 2022
    risk 0.65cvss 9.8epss 0.19

    Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function WanParameterSetting. This vulnerability allows attackers to execute arbitrary commands via the gateway, dns1, and dns2 parameters.

  • CVE-2021-46457CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function ChgSambaUserSettings. This vulnerability allows attackers to execute arbitrary commands via the samba_name parameter.

  • CVE-2021-46456CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetWLanACLSettings. This vulnerability allows attackers to execute arbitrary commands via the wl(0).(0)_maclist parameter.

  • CVE-2021-46455CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStationSettings. This vulnerability allows attackers to execute arbitrary commands via the station_access_enable parameter.

  • CVE-2021-46454CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetWLanApcliSettings. This vulnerability allows attackers to execute arbitrary commands via the ApCliKeyStr parameter.

  • CVE-2021-46453CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStaticRouteSettings. This vulnerability allows attackers to execute arbitrary commands via the staticroute_list parameter.

  • CVE-2021-46452CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via the tomography_ping_address, tomography_ping_number,…

  • CVE-2021-46233CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function msp_info.htm. This vulnerability allows attackers to execute arbitrary commands via the cmd parameter.

  • CVE-2021-46232CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function version_upgrade.asp. This vulnerability allows attackers to execute arbitrary commands via the path parameter.

  • CVE-2021-46231CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlrd_opt.asp. This vulnerability allows attackers to execute arbitrary commands via the url_en parameter.

  • CVE-2021-46230CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function upgrade_filter. This vulnerability allows attackers to execute arbitrary commands via the path and time parameters.

  • CVE-2021-46229CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function usb_paswd.asp. This vulnerability allows attackers to execute arbitrary commands via the name parameter.

  • CVE-2021-46228CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp. This vulnerability allows attackers to execute arbitrary commands via the time parameter.

  • CVE-2021-46227CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.05

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function proxy_client.asp. This vulnerability allows attackers to execute arbitrary commands via the proxy_srv, proxy_srvport, proxy_lanip, proxy_lanport parameters.

  • CVE-2021-46226CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function wget_test.asp. This vulnerability allows attackers to execute arbitrary commands via the url parameter.

  • CVE-2021-45998CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

  • CVE-2021-45990CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function uploadPicture. This vulnerability allows attackers to execute arbitrary commands via the pic_name parameter.

  • CVE-2021-45987CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This vulnerability allows attackers to execute arbitrary commands via the hostName parameter.

  • CVE-2021-45986CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.02

    Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetUSBShareInfo. This vulnerability allows attackers to execute arbitrary commands via the usbOrdinaryUserName parameter.

  • CVE-2021-45742CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.03

    TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

  • CVE-2021-45740CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the setWiFiWpsStart function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the pin parameter.

  • CVE-2021-45738CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function UploadFirmwareFile. This vulnerability allows attackers to execute arbitrary commands via the parameter FileName.

  • CVE-2021-45733CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host_time.

  • CVE-2021-44882CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.05

    D-Link device DIR_878_FW1.30B08_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

  • CVE-2021-44881CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.05

    D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the twsystem function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

  • CVE-2021-44880CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.04

    D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

  • CVE-2021-44247CriFeb 4, 2022
    risk 0.64cvss 9.8epss 0.03

    Totolink devices A3100R v4.1.2cu.5050_B20200504, A830R v5.9c.4729_B20191112, and A720R v4.1.5cu.470_B20200911 were discovered to contain command injection vulnerability in the function setNoticeCfg. This vulnerability allows attackers to execute arbitrary commands via the IpFrom…

  • CVE-2022-24307CriFeb 3, 2022
    risk 0.64cvss 9.8epss 0.01

    Mastodon before 3.3.2 and 3.4.x before 3.4.6 has incorrect access control because it does not compact incoming signed JSON-LD activities. (JSON-LD signing has been supported since version 1.6.0.)

  • CVE-2022-23357CriFeb 3, 2022
    risk 0.61cvss 9.1epss 0.20

    mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir.

  • CVE-2021-42640CriFeb 2, 2022
    risk 0.59cvss 9.1epss 0.02

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.

  • CVE-2021-42637CriFeb 2, 2022
    risk 0.64cvss 9.8epss 0.02

    PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.

  • CVE-2022-21817CriFeb 2, 2022
    risk 0.61cvss 9.3epss 0.02

    NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resources in other security domains, which may…

  • CVE-2021-39070CriFeb 2, 2022
    risk 0.64cvss 9.8epss 0.02

    IBM Security Verify Access 10.0.0.0, 10.0.1.0 and 10.0.2.0 with the advanced access control authentication service enabled could allow an attacker to authenticate as any user on the system. IBM X-Force ID: 215353.