VYPR

CVEs

38,065 total · page 501 of 762

  • CVE-2020-25912CriOct 31, 2021
    risk 0.59cvss 9.1epss 0.01

    A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).

  • CVE-2020-25911CriOct 31, 2021
    risk 0.59cvss 9.1epss 0.02

    A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).

  • CVE-2021-41646CriOct 29, 2021
    risk 0.64cvss 9.8epss 0.07

    Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..

  • CVE-2021-41644CriOct 29, 2021
    risk 0.64cvss 9.8epss 0.03

    Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.

  • CVE-2021-41643CriOct 29, 2021
    risk 0.64cvss 9.8epss 0.05

    Remote Code Execution (RCE) vulnerability exists in Sourcecodester Church Management System 1.0 via the image upload field.

  • CVE-2021-41676CriOct 29, 2021
    risk 0.64cvss 9.8epss 0.01

    An SQL Injection vulnerabilty exists in the oretnom23 Pharmacy Point of Sale System 1.0 in the login function in actions.php.

  • CVE-2021-41674CriOct 29, 2021
    risk 0.64cvss 9.8epss 0.02

    An SQL Injection vulnerability exists in Sourcecodester E-Negosyo System 1.0 via the user_email parameter in /admin/login.php.

  • CVE-2021-3756CriOct 29, 2021
    risk 0.64cvss 9.8epss 0.01

    libmysofa is vulnerable to Heap-based Buffer Overflow

  • CVE-2020-22079CriOct 29, 2021
    risk 0.64cvss 9.8epss 0.04

    Stack-based buffer overflow in Tenda AC-10U AC1200 Router US_AC10UV1.0RTL_V15.03.06.48_multi_TDE01 allows remote attackers to execute arbitrary code via the timeZone parameter to goform/SetSysTimeCfg.

  • CVE-2021-41194CriOct 28, 2021
    risk 0.52cvss 9.1epss 0.01

    FirstUseAuthenticator is a JupyterHub authenticator that helps new users set their password on their first login to JupyterHub. When JupyterHub is used with FirstUseAuthenticator, a vulnerability in versions prior to 1.0.0 allows unauthorized access to any user's account if…

  • CVE-2021-36548CriOct 28, 2021
    risk 0.64cvss 9.8epss 0.03

    A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary commands via a crafted PHP file.

  • CVE-2021-36547CriOct 28, 2021
    risk 0.64cvss 9.8epss 0.03

    A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary commands via a crafted PHP file.

  • CVE-2021-37002CriOct 28, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a Memory out-of-bounds access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause malicious code to be executed.

  • CVE-2021-36990CriOct 28, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.

  • CVE-2021-36989CriOct 28, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a Kernel crash vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.

  • CVE-2021-36986CriOct 28, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.

  • CVE-2021-22474CriOct 28, 2021
    risk 0.64cvss 9.8epss 0.01

    There is an Out-of-bounds memory access in Huawei Smartphone.Successful exploitation of this vulnerability may cause process exceptions.

  • CVE-2021-22436CriOct 28, 2021
    risk 0.59cvss 9.1epss 0.01

    There is a Logic Bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service integrity and availability.

  • CVE-2021-22403CriOct 28, 2021
    risk 0.64cvss 9.8epss 0.01

    There is a vulnerability of hijacking unverified providers in Huawei Smartphone.Successful exploitation of this vulnerability may allow attackers to hijack the device and forge UIs to induce users to execute malicious commands.

  • CVE-2019-19810CriOct 28, 2021
    risk 0.65cvss 10.0epss 0.05

    Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A remote unauthenticated attacker can exploit this vulnerability by sending crafted RMI requests to execute arbitrary code on the target host.

  • CVE-2020-21250CriOct 27, 2021
    risk 0.64cvss 9.8epss 0.01

    CSZ CMS v1.2.4 was discovered to contain an arbitrary file upload vulnerability in the component /core/MY_Security.php.

  • CVE-2021-41589CriOct 27, 2021
    risk 0.64cvss 9.8epss 0.02

    In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and remote code execution when running the build cache node with its default configuration. This configuration allows anonymous access to the configuration user…

  • CVE-2020-24932CriOct 27, 2021
    risk 0.64cvss 9.8epss 0.02

    An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php.

  • CVE-2021-38450CriOct 27, 2021
    risk 0.64cvss 9.9epss 0.01

    The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.

  • CVE-2011-4574CriOct 27, 2021
    risk 0.64cvss 9.8epss 0.01

    PolarSSL versions prior to v1.1 use the HAVEGE random number generation algorithm. At its heart, this uses timing information based on the processor's high resolution timer (the RDTSC instruction). This instruction can be virtualized, and some virtual machine hosts have chosen…

  • CVE-2011-4125CriOct 27, 2021
    risk 0.64cvss 9.8epss 0.02

    A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute any program as root.

  • CVE-2011-4124CriOct 27, 2021
    risk 0.64cvss 9.8epss 0.02

    Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to argument injection and elevation of privileges.

  • CVE-2021-37371CriOct 26, 2021
    risk 0.64cvss 9.8epss 0.02

    Online Student Admission System 1.0 is affected by an unauthenticated SQL injection bypass vulnerability in /admin/login.php.

  • CVE-2011-4119CriOct 26, 2021
    risk 0.64cvss 9.8epss 0.02

    caml-light <= 0.75 uses mktemp() insecurely, and also does unsafe things in /tmp during make install.

  • CVE-2011-2195CriOct 26, 2021
    risk 0.64cvss 9.8epss 0.03

    A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.

  • CVE-2021-41873CriOct 26, 2021
    risk 0.65cvss 10.0epss 0.01

    Penguin Aurora TV Box 41502 is a high-end network HD set-top box produced by Tencent Video and Skyworth Digital. An unauthorized access vulnerability exists in the Penguin Aurora Box. An attacker can use the vulnerability to gain unauthorized access to a specific link to…

  • CVE-2021-42343CriOct 26, 2021
    risk 0.57cvss 9.8epss 0.03

    An issue was discovered in the Dask distributed package before 2021.10.0 for Python. Single machine Dask clusters started with dask.distributed.LocalCluster or dask.distributed.Client (which defaults to using LocalCluster) would mistakenly configure their respective Dask workers…

  • CVE-2021-34584CriOct 26, 2021
    risk 0.59cvss 9.1epss 0.01

    Crafted web server requests can be utilised to read partial stack or heap memory or may trigger a denial-of- service condition due to a crash in the CODESYS V2 web server prior to V1.1.9.22.

  • CVE-2021-20837CriOct 26, 2021
    risk 0.74cvss 9.8epss 0.88

    Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced 7 Series), Movable Type Advanced 6.8.2 and earlier (Movable Type Advanced 6 Series), Movable Type…

  • CVE-2021-41035CriOct 25, 2021
    risk 0.64cvss 9.8epss 0.02

    In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.

  • CVE-2021-24884CriOct 25, 2021
    risk 0.63cvss 9.6epss 0.03

    The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like ,,, and.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick…

  • CVE-2021-40865CriOct 25, 2021
    risk 0.62cvss 9.8epss 0.64

    An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre-auth Remote Code Execution (RCE). Apache Storm 2.2.x users should upgrade to version 2.2.1 or 2.3.0. Apache Storm 2.1.x users should upgrade to version 2.1.1.…

  • CVE-2021-38294CriOct 25, 2021
    risk 0.66cvss 9.8epss 0.84

    A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Apache Storm 1.x prior to 1.2.4. A specially crafted thrift request to the Nimbus server allows Remote Code Execution (RCE) prior to authentication.

  • CVE-2021-40371CriOct 25, 2021
    risk 0.64cvss 9.8epss 0.07

    Gridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, as demonstrated by ..\\ in a scriptName JSON value to ServiceManagerTenant/GetVisibilityMap.

  • CVE-2021-42258CriKEVOct 22, 2021
    risk 0.91cvss 9.8epss 0.74

    BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful…

  • CVE-2020-28960CriOct 22, 2021
    risk 0.64cvss 9.8epss 0.02

    Chichen Tech CMS v1.0 was discovered to contain multiple SQL injection vulnerabilities in the file product_list.php via the id and cid parameters.

  • CVE-2020-23037CriOct 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.

  • CVE-2021-42169CriOct 22, 2021
    risk 0.64cvss 9.8epss 0.03

    The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no…

  • CVE-2021-41745CriOct 22, 2021
    risk 0.57cvss 9.8epss 0.01

    ShowDoc 2.8.3 ihas a file upload vulnerability, where attackers can use the vulnerability to obtain server permissions.

  • CVE-2021-41744CriOct 22, 2021
    risk 0.64cvss 9.8epss 0.02

    All versions of yongyou PLM are affected by a command injection issue. UFIDA PLM (Product Life Cycle Management) is a strategic management method. It applies a series of enterprise application systems to support the entire process from conceptual design to the end of product…

  • CVE-2021-38477CriOct 22, 2021
    risk 0.64cvss 9.8epss 0.01

    There are multiple API function codes that permit reading and writing data to or from files and directories, which could lead to the manipulation and/or the deletion of files.

  • CVE-2021-38471CriOct 22, 2021
    risk 0.59cvss 9.1epss 0.01

    There are multiple API function codes that permit data writing to any file, which may allow an attacker to modify existing files or create new files.

  • CVE-2021-38469CriOct 22, 2021
    risk 0.59cvss 9.1epss 0.01

    Many of the services used by the affected product do not specify full paths for the DLLs they are loading. An attacker can exploit the uncontrolled search path by implanting their own DLL near the affected product’s binaries, thus hijacking the loaded DLL.

  • CVE-2021-38457CriOct 22, 2021
    risk 0.64cvss 9.8epss 0.01

    The server permits communication without any authentication procedure, allowing the attacker to initiate a session with the server without providing any form of authentication.

  • CVE-2021-38453CriOct 22, 2021
    risk 0.59cvss 9.1epss 0.01

    Some API functions allow interaction with the registry, which includes reading values as well as data modification.