VYPR

CVEs

38,065 total · page 490 of 762

  • CVE-2021-39979CriJan 3, 2022
    risk 0.64cvss 9.8epss 0.01

    HHEE system has a Code Injection vulnerability.Successful exploitation of this vulnerability may affect HHEE system integrity.

  • CVE-2021-37128CriJan 3, 2022
    risk 0.64cvss 9.8epss 0.01

    HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may write any file.

  • CVE-2021-37121CriJan 3, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a Configuration defects in Smartphone.Successful exploitation of this vulnerability may elevate the MEID (IMEI) permission.

  • CVE-2021-37120CriJan 3, 2022
    risk 0.64cvss 9.8epss 0.01

    There is a Double free vulnerability in Smartphone.Successful exploitation of this vulnerability may cause a kernel crash or privilege escalation.

  • CVE-2021-37116CriJan 3, 2022
    risk 0.59cvss 9.1epss 0.01

    PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cause that the PIN of the subscriber is changed.

  • CVE-2021-45428CriJan 3, 2022
    risk 0.71cvss 9.8epss 0.57

    TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats.

  • CVE-2021-30351CriJan 3, 2022
    risk 0.64cvss 9.8epss 0.04

    An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice &…

  • CVE-2021-30276CriJan 3, 2022
    risk 0.60cvss 9.3epss 0.00

    Improper access control while doing XPU re-configuration dynamically can lead to unauthorized access to a secure resource in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wired Infrastructure and Networking

  • CVE-2021-30275CriJan 3, 2022
    risk 0.60cvss 9.3epss 0.00

    Possible integer overflow in page alignment interface due to lack of address and size validation before alignment in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wired…

  • CVE-2021-25981CriJan 3, 2022
    risk 0.64cvss 9.8epss 0.02

    In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admin’s still-valid session token even when logged-out, to gain admin…

  • CVE-2022-0080CriJan 2, 2022
    risk 0.00cvss 9.8epss 0.01

    mruby is vulnerable to Heap-based Buffer Overflow

  • CVE-2021-45957CriJan 1, 2022
    risk 0.64cvss 9.8epss 0.02

    Dnsmasq 2.86 has a heap-based buffer overflow in answer_request (called from FuzzAnswerTheRequest and fuzz_rfc1035.c). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.

  • CVE-2021-45956CriJan 1, 2022
    risk 0.64cvss 9.8epss 0.03

    Dnsmasq 2.86 has a heap-based buffer overflow in print_mac (called from log_packet and dhcp_reply). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.

  • CVE-2021-45955CriJan 1, 2022
    risk 0.64cvss 9.8epss 0.03

    Dnsmasq 2.86 has a heap-based buffer overflow in resize_packet (called from FuzzResizePacket and fuzz_rfc1035.c) because of the lack of a proper bounds check upon pseudo header re-insertion. NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not…

  • CVE-2021-45954CriJan 1, 2022
    risk 0.64cvss 9.8epss 0.03

    Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from answer_auth and FuzzAuth). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.

  • CVE-2021-45953CriJan 1, 2022
    risk 0.64cvss 9.8epss 0.03

    Dnsmasq 2.86 has a heap-based buffer overflow in extract_name (called from hash_questions and fuzz_util.c). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.

  • CVE-2021-45952CriJan 1, 2022
    risk 0.64cvss 9.8epss 0.03

    Dnsmasq 2.86 has a heap-based buffer overflow in dhcp_reply (called from dhcp_packet and FuzzDhcp). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.

  • CVE-2021-45951CriJan 1, 2022
    risk 0.64cvss 9.8epss 0.03

    Dnsmasq 2.86 has a heap-based buffer overflow in check_bad_address (called from check_for_bogus_wildcard and FuzzCheckForBogusWildcard). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowledge.

  • CVE-2021-20158CriDec 30, 2021
    risk 0.65cvss 9.8epss 0.11

    Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to force the change of the admin password due to a hidden administrative command.

  • CVE-2021-20155CriDec 30, 2021
    risk 0.64cvss 9.8epss 0.02

    Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations via the management web interface. These devices are encrypted using a hardcoded password of "12345678".

  • CVE-2021-20151CriDec 30, 2021
    risk 0.65cvss 10.0epss 0.02

    Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device. The router's management software manages web sessions based on IP address rather than verifying client cookies/session tokens/etc. This allows an attacker (whether from a…

  • CVE-2021-20149CriDec 30, 2021
    risk 0.64cvss 9.8epss 0.01

    Trendnet AC2600 TEW-827DRU version 2.08B01 does not have sufficient access controls for the WAN interface. The default iptables ruleset for governing access to services on the device only apply to IPv4. All services running on the devices are accessible via the WAN interface via…

  • CVE-2021-45427CriDec 30, 2021
    risk 0.65cvss 9.8epss 0.19

    Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete files without any authentication due to incorrect access control and directory traversal.

  • CVE-2020-7883CriDec 28, 2021
    risk 0.64cvss 9.8epss 0.01

    Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.

  • CVE-2020-7878CriDec 28, 2021
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-7878). This issue is due to missing support for integrity check.

  • CVE-2020-22057CriDec 28, 2021
    risk 0.59cvss 9.1epss 0.01

    The WinRin0x64.sys and WinRing0.sys low-level drivers in EVGA Precision XOC version v6.2.7 were discovered to be configured with the default security descriptor which allows attackers to access sensitive components and data.

  • CVE-2021-45814CriDec 28, 2021
    risk 0.67cvss 9.8epss 0.06

    Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel with an administrative account.

  • CVE-2021-37401CriDec 28, 2021
    risk 0.64cvss 9.8epss 0.01

    An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/or downloaded.

  • CVE-2021-37400CriDec 28, 2021
    risk 0.64cvss 9.8epss 0.01

    An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded.

  • CVE-2019-20082CriDec 28, 2021
    risk 0.64cvss 9.8epss 0.02

    ASUS RT-N53 3.0.0.4.376.3754 devices have a buffer overflow via a long lan_dns1_x or lan_dns2_x parameter to Advanced_LAN_Content.asp.

  • CVE-2020-21238CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.

  • CVE-2020-21237CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue in the user login box of LJCMS v1.11 allows attackers to hijack user accounts via brute force attacks.

  • CVE-2020-20944CriDec 27, 2021
    risk 0.59cvss 9.1epss 0.02

    An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.

  • CVE-2021-45890CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.02

    basic/BasicAuthProvider.java in AuthGuard before 0.9.0 allows authentication via an inactive identifier.

  • CVE-2021-4161CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    The affected products contain vulnerable firmware, which could allow an attacker to sniff the traffic and decrypt login credential details. This could give an attacker admin rights through the HTTP web server.

  • CVE-2021-43857CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.55

    Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code execution, and this issue is patched in version 0.9.8.

  • CVE-2021-45232CriDec 27, 2021
    risk 0.71cvss 9.8epss 0.86

    In Apache APISIX Dashboard before 2.10.1, the Manager API uses two frameworks and introduces framework `droplet` on the basis of framework `gin`, all APIs and authentication middleware are developed based on framework `droplet`, but some API directly use the interface of…

  • CVE-2021-45709CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the crypto2 crate through 2021-10-08 for Rust. During Chacha20 encryption and decryption, an unaligned read of a u32 may occur.

  • CVE-2021-45707CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the nix crate 0.16.0 and later before 0.20.2, 0.21.x before 0.21.2, and 0.22.x before 0.22.2 for Rust. unistd::getgrouplist has an out-of-bounds write if a user is in more than 16 /etc/groups groups.

  • CVE-2021-45706CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the zeroize_derive crate before 1.1.1 for Rust. Dropped memory is not zeroed out for an enum.

  • CVE-2021-45705CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the nanorand crate before 0.6.1 for Rust. There can be multiple mutable references to the same object because the TlsWyRand Deref implementation dereferences a raw pointer.

  • CVE-2021-45703CriDec 27, 2021
    risk 0.57cvss 9.8epss 0.01

    An issue was discovered in the tectonic_xdv crate before 0.1.12 for Rust. XdvParser::::process may read from uninitialized memory locations.

  • CVE-2021-45701CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the tremor-script crate before 0.11.6 for Rust. A patch operation may result in a use-after-free.

  • CVE-2021-45698CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the ckb crate before 0.40.0 for Rust. A get_block_template RPC call may fail in situations where it is supposed to select a Nervos CKB blockchain transaction with a higher fee rate than another transaction.

  • CVE-2021-45697CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the molecule crate before 0.7.2 for Rust. A FixVec partial read has an incorrect result.

  • CVE-2021-45696CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the sha2 crate 0.9.7 before 0.9.8 for Rust. Hashes of long messages may be incorrect when the AVX2-accelerated backend is used.

  • CVE-2021-45695CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in the mopa crate through 2021-06-01 for Rust. It incorrectly relies on Trait memory layout, possibly leading to future occurrences of arbitrary code execution or ASLR bypass.

  • CVE-2021-45693CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string_primitive may read from uninitialized memory locations.

  • CVE-2021-45692CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_extension_others may read from uninitialized memory locations.

  • CVE-2021-45691CriDec 27, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the messagepack-rs crate through 2021-01-26 for Rust. deserialize_string may read from uninitialized memory locations.