VYPR

CVEs

38,065 total · page 495 of 762

  • CVE-2021-43703CriDec 9, 2021
    risk 0.64cvss 9.8epss 0.02

    An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling JavaScript, you can directly access the administrator console.

  • CVE-2021-41695CriDec 9, 2021
    risk 0.64cvss 9.8epss 0.01

    An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in connect.php. .

  • CVE-2021-41694CriDec 9, 2021
    risk 0.64cvss 9.8epss 0.01

    An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in requests\user.php.

  • CVE-2021-21954CriDec 9, 2021
    risk 0.65cvss 9.9epss 0.03

    A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to arbitrary command execution.

  • CVE-2021-20146CriDec 9, 2021
    risk 0.64cvss 9.8epss 0.02

    An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery, the ssh key could be used to login to the development server hosted in Amazon…

  • CVE-2021-3817CriDec 9, 2021
    risk 0.70cvss 9.8epss 0.38

    wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

  • CVE-2021-4048CriDec 8, 2021
    risk 0.59cvss 9.1epss 0.03

    An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or…

  • CVE-2021-44529CriKEVDec 8, 2021
    risk 0.93cvss 9.8epss 0.99

    A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

  • CVE-2021-43527CriDec 8, 2021
    risk 0.65cvss 9.8epss 0.18

    NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be…

  • CVE-2021-38503CriDec 8, 2021
    risk 0.65cvss 10.0epss 0.04

    The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

  • CVE-2021-23859CriDec 8, 2021
    risk 0.59cvss 9.1epss 0.01

    An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standalone VRM or BVMS with VRM installation this crash also opens the possibility to send further unauthenticated commands to the service. On some products the…

  • CVE-2021-21951CriDec 8, 2021
    risk 0.65cvss 10.0epss 0.02

    An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function read_udp_push_config_file. A specially-crafted network packet can lead to code execution.

  • CVE-2021-21950CriDec 8, 2021
    risk 0.65cvss 10.0epss 0.02

    An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function recv_server_device_response_msg_process. A specially-crafted network packet can lead to code execution.

  • CVE-2020-27416CriDec 8, 2021
    risk 0.64cvss 9.8epss 0.02

    Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to control a users account.

  • CVE-2021-41063CriDec 8, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability was discovered in Aanderaa GeoView Webservice prior to version 2.1.3 that could allow an unauthenticated attackers to execute arbitrary commands.

  • CVE-2021-3815CriDec 8, 2021
    risk 0.57cvss 9.8epss 0.01

    utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CVE-2021-27860CriKEVDec 8, 2021
    risk 0.79cvss 9.8epss 0.40

    A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this…

  • CVE-2021-37051CriDec 8, 2021
    risk 0.59cvss 9.1epss 0.01

    There is an Out-of-bounds read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds memory access.

  • CVE-2021-37049CriDec 8, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a Heap-based buffer overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may rewrite the memory of adjacent objects.

  • CVE-2021-37045CriDec 8, 2021
    risk 0.64cvss 9.8epss 0.01

    There is an UAF vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart unexpectedly and the kernel-mode code to be executed.

  • CVE-2021-37040CriDec 8, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a Parameter injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause privilege escalation of files after CIFS share mounting.

  • CVE-2021-44557CriDec 8, 2021
    risk 0.59cvss 9.1epss 0.01

    National Library of the Netherlands multiNER <= c0440948057afc6e3d6b4903a7c05e666b94a3bc is affected by an XML External Entity (XXE) vulnerability in multiNER/ner.py. Since XML parsing resolves external entities, a malicious XML stream could leak internal files and/or cause a…

  • CVE-2021-44556CriDec 8, 2021
    risk 0.59cvss 9.1epss 0.01

    National Library of the Netherlands digger < 6697d1269d981e35e11f240725b16401b5ce3db5 is affected by a XML External Entity (XXE) vulnerability. Since XML parsing resolves external entities, a malicious XML stream could leak internal files and/or cause a DoS.

  • CVE-2021-20045CriDec 8, 2021
    risk 0.66cvss 9.8epss 0.25

    A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execute code as the 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

  • CVE-2021-20042CriDec 8, 2021
    risk 0.64cvss 9.8epss 0.04

    An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

  • CVE-2021-20038CriKEVDec 8, 2021
    risk 0.90cvss 9.8epss 1.00

    A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v…

  • CVE-2021-38759CriDec 7, 2021
    risk 0.68cvss 9.8epss 0.16

    Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain administrator privileges.

  • CVE-2021-41716CriDec 7, 2021
    risk 0.64cvss 9.8epss 0.01

    Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function

  • CVE-2021-40859CriDec 7, 2021
    risk 0.72cvss 9.8epss 0.72

    Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management application full administrative access to the device.

  • CVE-2021-24041CriDec 7, 2021
    risk 0.64cvss 9.8epss 0.01

    A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowed an out-of-bounds write if a user sent a malicious image.

  • CVE-2021-37099CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete any file.

  • CVE-2021-37095CriDec 7, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to remote denial of service and potential remote code execution.

  • CVE-2021-37088CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can write any content to any file.

  • CVE-2021-37087CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Path Traversal vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers can create arbitrary file.

  • CVE-2021-37084CriDec 7, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to malicious invoking other functions of the Smart Assistant through text messages.

  • CVE-2021-37079CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete arbitrary file by system_app permission.

  • CVE-2021-37065CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Integer Overflow or Wraparound vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Confidentiality or Availability impacted.

  • CVE-2021-37064CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Improper Limitation of a Pathname to a Restricted Directory vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to arbitrary file created.

  • CVE-2021-37063CriDec 7, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a Cryptographic Issues vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to read and delete images of Harmony devices.

  • CVE-2021-37062CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Improper Validation of Array Index vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to memory overflow and information leakage.

  • CVE-2021-37059CriDec 7, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a Weaknesses Introduced During Design

  • CVE-2021-37021CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Out-of-bounds read.

  • CVE-2021-37020CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Out-of-bounds read.

  • CVE-2021-37011CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Stack-based Buffer Overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to Out-of-bounds read.

  • CVE-2021-37042CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds read.

  • CVE-2021-37041CriDec 7, 2021
    risk 0.59cvss 9.1epss 0.01

    There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds read.

  • CVE-2021-42128CriDec 7, 2021
    risk 0.64cvss 9.8epss 0.05

    An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service.

  • CVE-2021-42127CriDec 7, 2021
    risk 0.69cvss 9.8epss 0.66

    A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.

  • CVE-2021-29114CriDec 7, 2021
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in feature services provided by Esri ArcGIS Server 10.9 and below allows a remote, unauthenticated attacker to impact the confidentiality, integrity and availability of targeted services via specifically crafted queries.

  • CVE-2021-44685CriDec 7, 2021
    risk 0.64cvss 9.8epss 0.03

    Git-it through 4.4.0 allows OS command injection at the Branches Aren't Just For Birds challenge step. During the verification process, it attempts to run the reflog command followed by the current branch name (which is not sanitized for execution).