VYPR

CVEs

38,065 total · page 503 of 762

  • CVE-2021-40499CriOct 12, 2021
    risk 0.64cvss 9.8epss 0.01

    Client-side printing services SAP Cloud Print Manager and SAPSprint for SAP NetWeaver Application Server for ABAP - versions 7.70, 7.70 PI, 7.70 BYD, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the…

  • CVE-2021-38180CriOct 12, 2021
    risk 0.64cvss 9.8epss 0.02

    SAP Business One - version 10.0, allows an attacker to inject formulas when exporting data to Excel (CSV injection) due to improper sanitation during the data export. An attacker could thereby execute arbitrary commands on the victim's computer but only if the victim allows to…

  • CVE-2021-37726CriOct 12, 2021
    risk 0.64cvss 9.8epss 0.02

    A remote buffer overflow vulnerability was discovered in HPE Aruba Instant (IAP) version(s): Aruba Instant 8.7.x.x: 8.7.0.0 through 8.7.1.2. Aruba has released patches for Aruba Instant (IAP) that address this security vulnerability.

  • CVE-2021-38458CriOct 12, 2021
    risk 0.64cvss 9.8epss 0.02

    A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

  • CVE-2021-38456CriOct 12, 2021
    risk 0.64cvss 9.8epss 0.01

    A use of hard-coded password vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to gain access through accounts using default passwords

  • CVE-2021-38454CriOct 12, 2021
    risk 0.66cvss 10.0epss 0.16

    A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.

  • CVE-2021-21941CriOct 12, 2021
    risk 0.59cvss 9.0epss 0.02

    A use-after-free vulnerability exists in the pushMuxer CreatePushThread functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to remote code execution.

  • CVE-2021-21940CriOct 12, 2021
    risk 0.65cvss 10.0epss 0.01

    A heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted network packet can lead to a heap buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2021-33725CriOct 12, 2021
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delete arbitrary files or directories under a user controlled path and does not correctly check if the relative path is still within the intended target directory.

  • CVE-2021-33724CriOct 12, 2021
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system contains an Arbitrary File Deletion vulnerability that possibly allows to delete an arbitrary file or directory under a user controlled path.

  • CVE-2021-40617CriOct 11, 2021
    risk 0.67cvss 9.8epss 0.05

    An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.

  • CVE-2021-40239CriOct 11, 2021
    risk 0.64cvss 9.8epss 0.01

    A Buffer Overflow vulnerability exists in the latest version of Miniftpd in the do_retr function in ftpproto.c

  • CVE-2020-27372CriOct 11, 2021
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in Brandy Basic V Interpreter 1.21 in the run_interpreter function.

  • CVE-2021-26588CriOct 11, 2021
    risk 0.64cvss 9.8epss 0.02

    A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts…

  • CVE-2021-37123CriOct 11, 2021
    risk 0.64cvss 9.8epss 0.01

    There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200. The vulnerability is due to that when an user wants to do certain operation, the software does not insufficiently validate the user's identity. Successful exploit could allow the attacker to do…

  • CVE-2021-27664CriOct 11, 2021
    risk 0.64cvss 9.8epss 0.02

    Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.

  • CVE-2021-40543CriOct 11, 2021
    risk 0.64cvss 9.8epss 0.01

    Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at two parameters $_GET['usrid'] and $_GET['prof_id'] in the PasswordCheck.php file.

  • CVE-2021-40887CriOct 11, 2021
    risk 0.64cvss 9.8epss 0.02

    Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP files or any file on the system that has permissions to /upload/files/ folder.

  • CVE-2021-40889CriOct 11, 2021
    risk 0.64cvss 9.8epss 0.02

    CMSUno version 1.7.2 is affected by a PHP code execution vulnerability. sauvePass action in {webroot}/uno/central.php file calls to file_put_contents() function to write username in password.php file when a user successfully changed their password. The attacker can inject…

  • CVE-2021-42139CriOct 11, 2021
    risk 0.64cvss 9.8epss 0.02

    Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.

  • CVE-2021-37973CriKEVOct 8, 2021
    risk 0.75cvss 9.6epss 0.12

    Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-30633CriKEVOct 8, 2021
    risk 0.77cvss 9.6epss 0.33

    Use after free in Indexed DB API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-22617CriOct 8, 2021
    risk 0.64cvss 9.8epss 0.01

    Ardour v5.12 contains a use-after-free vulnerability in the component ardour/libs/pbd/xml++.cc when using xmlFreeDoc and xmlXPathFreeContext.

  • CVE-2021-42109CriOct 8, 2021
    risk 0.64cvss 9.8epss 0.02

    VITEC Exterity IPTV products through 2021-04-30 allow privilege escalation to root.

  • CVE-2021-41974CriOct 8, 2021
    risk 0.59cvss 9.1epss 0.01

    Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content of books without permission.

  • CVE-2021-41566CriOct 8, 2021
    risk 0.64cvss 9.8epss 0.02

    The file extension of the TadTools file upload function fails to filter, thus remote attackers can upload any types of files and execute arbitrary code without logging in.

  • CVE-2021-36767CriOct 8, 2021
    risk 0.64cvss 9.8epss 0.01

    In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the server password, making the protection ineffective. An attacker may send an unauthenticated request to the server. The server will reply with a weakly-hashed…

  • CVE-2021-35977CriOct 8, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Digi RealPort for Windows through 4.8.488.0. A buffer overflow exists in the handling of ADDP discovery response messages. This could result in arbitrary code execution.

  • CVE-2021-38298CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.03

    Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.

  • CVE-2020-21726CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.01

    OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the cid parameter.

  • CVE-2020-21725CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.01

    OpenSNS v6.1.0 contains a blind SQL injection vulnerability in /Controller/ChinaCityController.class.php via the pid parameter.

  • CVE-2021-42091CriOct 7, 2021
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.

  • CVE-2021-42090CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserialization is mishandled.

  • CVE-2020-21865CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.02

    ThinkPHP50-CMS v1.0 contains a remote code execution (RCE) vulnerability in the component /public/?s=captcha.

  • CVE-2021-42094CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.

  • CVE-2021-42071CriOct 7, 2021
    risk 0.72cvss 9.8epss 0.70

    In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.

  • CVE-2021-42013CriKEVOct 7, 2021
    risk 0.86cvss 9.8epss 1.00

    It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by…

  • CVE-2021-3833CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.01

    Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and the MD5 hash stored in the database. An attacker with a specific formatted password could exploit this vulnerability in order to login in the system with…

  • CVE-2021-37931CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37930CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37929CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37928CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37926CriOct 7, 2021
    risk 0.70cvss 9.8epss 0.74

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37924CriOct 7, 2021
    risk 0.65cvss 9.8epss 0.11

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37923CriOct 7, 2021
    risk 0.65cvss 9.8epss 0.11

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37921CriOct 7, 2021
    risk 0.65cvss 9.8epss 0.11

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37920CriOct 7, 2021
    risk 0.65cvss 9.8epss 0.11

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37919CriOct 7, 2021
    risk 0.65cvss 9.8epss 0.11

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37918CriOct 7, 2021
    risk 0.70cvss 9.8epss 0.74

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37762CriOct 7, 2021
    risk 0.64cvss 9.8epss 0.08

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.