VYPR

CVEs

38,063 total · page 505 of 762

  • CVE-2020-12030CriSep 29, 2021
    risk 0.65cvss 10.0epss 0.01

    There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports used by the gateway.

  • CVE-2021-36745CriSep 29, 2021
    risk 0.64cvss 9.8epss 0.09

    A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Network Appliance Filers 5.8, and ServerProtect for Microsoft Windows / Novell Netware 5.8 could allow a remote attacker to bypass authentication on affected…

  • CVE-2021-33924CriSep 29, 2021
    risk 0.64cvss 9.8epss 0.02

    Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its auxiliary component that allows remote attackers to access sensitive information.

  • CVE-2020-20122CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.01

    Wuzhi CMS v4.1 contains a SQL injection vulnerability in the checktitle() function in /coreframe/app/content/admin/content.php.

  • CVE-2020-20120CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.02

    ThinkPHP v3.2.3 and below contains a SQL injection vulnerability which is triggered when the array is not passed to the "where" and "query" methods.

  • CVE-2021-38303CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Sureline SUREedge Migrator 7.0.7.29360.

  • CVE-2021-36366CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.04

    Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards.

  • CVE-2021-36365CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.04

    Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

  • CVE-2021-36364CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.04

    Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards.

  • CVE-2021-36363CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.04

    Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.

  • CVE-2021-38124CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.02

    Remote Code Execution vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, affecting versions 7.0.2 through 7.5. The vulnerability could be exploited resulting in remote code execution.

  • CVE-2021-37270CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.01

    There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulnerability to directly access the specified background path without logging in to the background to obtain the background administrator authority.

  • CVE-2021-41097CriSep 27, 2021
    risk 0.53cvss 9.1epss 0.05

    aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vulnerability exposes Aurelia application that uses `aurelia-path` package to parse a string. The…

  • CVE-2021-20034CriSep 27, 2021
    risk 0.69cvss 9.1epss 0.81

    An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.

  • CVE-2021-41558CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.01

    The set_user extension module before 3.0.0 for PostgreSQL allows ProcessUtility_hook bypass via set_config.

  • CVE-2021-40329CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.01

    The Authentication API in Ping Identity PingFederate before 10.3 mishandles certain aspects of external password management.

  • CVE-2021-37761CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.

  • CVE-2021-36879CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.02

    Unauthenticated Privilege Escalation vulnerability in WordPress uListing plugin (versions <= 2.0.5). Possible if WordPress configuration allows user registration.

  • CVE-2021-24666CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.09

    The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P[\d]+), takes an 'id' and 'category' parameters as arguments. Both parameters can be used for…

  • CVE-2021-37539CriSep 27, 2021
    risk 0.71cvss 9.8epss 0.93

    Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.

  • CVE-2021-36219CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in SKALE sgxwallet 1.58.3. The provided input for ECALL 14 triggers a branch in trustedEcdsaSign that frees a non-initialized pointer from the stack. An attacker can chain multiple enclave calls to prepare a stack that contains a valid address. This…

  • CVE-2021-34416CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.02

    The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Meeting Connector MMR before version 4.6.360.20210325, Zoom on-premise Recording Connector before version 3.8.44.20210326, Zoom…

  • CVE-2021-33907CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.03

    The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated privileged context.

  • CVE-2021-40098CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regular expression.

  • CVE-2021-38299CriSep 27, 2021
    risk 0.57cvss 9.8epss 0.02

    Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to login to a vulnerable service using an attached FIDO2 authenticator without passing a check of the user presence.

  • CVE-2021-34351CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.01

    A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and…

  • CVE-2021-34348CriSep 27, 2021
    risk 0.64cvss 9.8epss 0.01

    A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.5 build 20210803 and…

  • CVE-2021-22869CriSep 24, 2021
    risk 0.64cvss 9.8epss 0.01

    An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects customers using self-hosted runner groups for access control. A repository with access to one…

  • CVE-2021-40102CriSep 24, 2021
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_dir (PHP Object Injection associated with the __wakeup magic method).

  • CVE-2021-26794CriSep 23, 2021
    risk 0.64cvss 9.8epss 0.02

    Privilege escalation in 'upload.php' in FrogCMS SentCMS v0.9.5 allows attacker to execute arbitrary code via crafted php file.

  • CVE-2020-4690CriSep 23, 2021
    risk 0.64cvss 9.8epss 0.01

    IBM Security Guardium 11.3 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 186697.

  • CVE-2021-21913CriSep 23, 2021
    risk 0.64cvss 9.8epss 0.02

    An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specially-crafted network request can lead to command execution. An attacker can connect to the MQTT service to trigger this vulnerability.

  • CVE-2021-22945CriSep 23, 2021
    risk 0.60cvss 9.1epss 0.07

    When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also free it *again*.

  • CVE-2021-22941CriKEVSep 23, 2021
    risk 0.86cvss 9.8epss 0.54

    Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.

  • CVE-2021-22005CriKEVSep 23, 2021
    risk 0.93cvss 9.8epss 1.00

    The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.

  • CVE-2021-34770CriSep 23, 2021
    risk 0.65cvss 10.0epss 0.03

    A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9000 Family Wireless Controllers could allow an unauthenticated, remote attacker to execute arbitrary code with administrative…

  • CVE-2021-34727CriSep 23, 2021
    risk 0.64cvss 9.8epss 0.03

    A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an affected device processes traffic. An…

  • CVE-2021-1619CriSep 23, 2021
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the…

  • CVE-2021-40684CriSep 22, 2021
    risk 0.59cvss 9.1epss 0.01

    Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container…

  • CVE-2019-6288CriSep 22, 2021
    risk 0.64cvss 9.8epss 0.03

    Edgecore ECS2020 Firmware 1.0.0.0 devices allow Unauthenticated Command Injection via the command1 HTTP header to the /EXCU_SHELL URI.

  • CVE-2021-37927CriSep 22, 2021
    risk 0.64cvss 9.8epss 0.02

    Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.

  • CVE-2021-37925CriSep 22, 2021
    risk 0.65cvss 9.8epss 0.10

    Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.

  • CVE-2021-36260CriKEVSep 22, 2021
    risk 0.87cvss 9.8epss 1.00

    A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious commands.

  • CVE-2021-31819CriSep 22, 2021
    risk 0.64cvss 9.8epss 0.02

    In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each other based on certificate verification.

  • CVE-2021-37424CriSep 21, 2021
    risk 0.64cvss 9.8epss 0.05

    ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.

  • CVE-2021-28960CriSep 21, 2021
    risk 0.64cvss 9.8epss 0.02

    Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations.

  • CVE-2021-0869CriSep 21, 2021
    risk 0.64cvss 9.8epss 0.01

    In GetTimeStampAndPkt of DumpstateDevice.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android…

  • CVE-2021-31917CriSep 21, 2021
    risk 0.64cvss 9.8epss 0.01

    A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authentication on all REST endpoints when DIGEST is used as the authentication method. The highest threat from this vulnerability is to data…

  • CVE-2021-40674CriSep 20, 2021
    risk 0.64cvss 9.8epss 0.01

    An SQL injection vulnerability exists in Wuzhi CMS v4.1.0 via the KeyValue parameter in coreframe/app/order/admin/index.php.

  • CVE-2021-24741CriSep 20, 2021
    risk 0.64cvss 9.8epss 0.06

    The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable…