VYPR

CVEs

38,063 total · page 507 of 762

  • CVE-2021-38833CriSep 13, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in PHPGurukul Apartment Visitors Management System (AVMS) v. 1.0 allows attackers to execute arbitrary SQL statements and to gain RCE.

  • CVE-2021-3666CriSep 13, 2021
    risk 0.57cvss 9.8epss 0.01

    body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CVE-2021-33543CriSep 13, 2021
    risk 0.73cvss 9.8epss 0.81

    Multiple camera devices by UDP Technology, Geutebrück and other vendors allow unauthenticated remote access to sensitive files due to default user authentication settings. This can lead to manipulation of the device and denial of service.

  • CVE-2021-24493CriSep 13, 2021
    risk 0.64cvss 9.8epss 0.02

    The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authenticated user does not have any security measure in place to prevent upload of malicious files, such as PHP, allowing unauthenticated users to upload arbitrary…

  • CVE-2021-40870CriKEVSep 13, 2021
    risk 0.83cvss 9.8epss 0.93

    An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

  • CVE-2021-40866CriSep 13, 2021
    risk 0.64cvss 9.8epss 0.02

    Certain NETGEAR smart switches are affected by a remote admin password change by an unauthenticated attacker via the (disabled by default) /sqfs/bin/sccd daemon, which fails to check authentication when the authentication TLV is missing from a received NSDP packet. This affects…

  • CVE-2021-40146CriSep 11, 2021
    risk 0.64cvss 9.8epss 0.06

    A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5. RCE vulnerabilities allow a malicious actor to execute any code of their choice on a remote machine over LAN, WAN, or internet. RCE…

  • CVE-2021-38555CriSep 11, 2021
    risk 0.59cvss 9.1epss 0.03

    An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an…

  • CVE-2021-24040CriSep 10, 2021
    risk 0.61cvss 9.8epss 0.17

    Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files could provide malicious input, resulting in remote code execution or similar risks. This issue affects ParlAI prior to v1.1.0.

  • CVE-2021-40864CriSep 10, 2021
    risk 0.64cvss 9.8epss 0.02

    The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.data and text fields.

  • CVE-2021-37422CriSep 10, 2021
    risk 0.64cvss 9.8epss 0.03

    Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.

  • CVE-2021-37423CriSep 10, 2021
    risk 0.64cvss 9.8epss 0.03

    Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover.

  • CVE-2021-40373CriSep 10, 2021
    risk 0.64cvss 9.8epss 0.05

    playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that code via the index.php?app=main&inc=core_welcome URI.

  • CVE-2021-3645CriSep 10, 2021
    risk 0.57cvss 9.8epss 0.01

    merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

  • CVE-2021-34346CriSep 10, 2021
    risk 0.64cvss 9.8epss 0.02

    A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of NVR Storage Expansion:…

  • CVE-2021-34345CriSep 10, 2021
    risk 0.64cvss 9.8epss 0.02

    A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of NVR Storage Expansion:…

  • CVE-2021-34344CriSep 10, 2021
    risk 0.64cvss 9.8epss 0.02

    A stack buffer overflow vulnerability has been reported to affect QNAP device running QUSBCam2. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this vulnerability in the following versions of QUSBCam2: QTS 4.5.4: QUSBCam2 1.1.4…

  • CVE-2021-28813CriSep 10, 2021
    risk 0.62cvss 9.6epss 0.01

    A vulnerability involving insecure storage of sensitive information has been reported to affect QSW-M2116P-2T2S and QNAP switches running QuNetSwitch. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage…

  • CVE-2021-32724CriSep 9, 2021
    risk 0.58cvss 9.9epss 0.02

    check-spelling is a github action which provides CI spell checking. In affected versions and for a repository with the [check-spelling action](https://github.com/marketplace/actions/check-spelling) enabled that triggers on `pull_request_target` (or `schedule`), an attacker can…

  • CVE-2021-39296CriSep 9, 2021
    risk 0.65cvss 10.0epss 0.03

    In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.

  • CVE-2021-28913CriSep 9, 2021
    risk 0.64cvss 9.8epss 0.02

    BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /webif/SecurityModule to validate the so called and hard coded unique 'eibPort String' which acts as the root SSH key passphrase. This is usable and part of an attack chain to gain SSH…

  • CVE-2021-28911CriSep 9, 2021
    risk 0.64cvss 9.8epss 0.02

    BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains some sensitive data (e.g. device serial number). Having those info, a possible loginId can be self-calculated in a brute force attack against BMX interface.…

  • CVE-2021-28909CriSep 9, 2021
    risk 0.64cvss 9.8epss 0.01

    BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers to access uncontrolled the login service at /webif/SecurityModule in a brute force attack. The password could be weak and default username is known as 'admin'. This is usable and part of an…

  • CVE-2020-19267CriSep 9, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue in index.php/Dswjcms/Basis/resources of Dswjcms 1.6.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2021-38727CriSep 9, 2021
    risk 0.64cvss 9.8epss 0.02

    FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items

  • CVE-2021-38540CriSep 9, 2021
    risk 0.63cvss 9.8epss 0.81

    The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variables used in DAGs, potentially resulting in a denial of service, information disclosure or remote code…

  • CVE-2021-28494CriSep 9, 2021
    risk 0.62cvss 9.6epss 0.01

    In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, authentication is bypassed by unprivileged users who are accessing the Web UI. This issue affects: Arista Metamako Operating System MOS-0.34.0 and prior…

  • CVE-2021-38408CriSep 9, 2021
    risk 0.65cvss 9.8epss 0.12

    A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of user-supplied data may allow remote code execution.

  • CVE-2021-37579CriSep 9, 2021
    risk 0.64cvss 9.8epss 0.07

    The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server. But there's an exception that the attacker can use to skip the security check (when enabled) and reaching a deserialization…

  • CVE-2021-36161CriSep 9, 2021
    risk 0.64cvss 9.8epss 0.02

    Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean with special toString method. In the latest version, we fix the toString call in timeout, cache and some other places. Fixed in…

  • CVE-2021-1946CriSep 9, 2021
    risk 0.64cvss 9.8epss 0.01

    Null Pointer Dereference may occur due to improper validation while processing crafted SDP body in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

  • CVE-2021-1933CriSep 9, 2021
    risk 0.64cvss 9.8epss 0.01

    UE assertion is possible due to improper validation of invite message with SDP body in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

  • CVE-2021-32835CriSep 9, 2021
    risk 0.65cvss 9.9epss 0.05

    Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a sandbox escape vulnerability may lead to post-authentication Remote Code execution. This vulnerability is known to exist in the latest commit at the time of…

  • CVE-2021-40818CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.01

    scheme/webauthn.c in Glewlwyd SSO server through 2.5.3 has a buffer overflow during FIDO2 signature validation in webauthn registration.

  • CVE-2021-40814CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.01

    The Customer Photo Gallery addon before 2.9.4 for PrestaShop is vulnerable to SQL injection.

  • CVE-2021-36440CriSep 8, 2021
    risk 0.57cvss 9.8epss 0.05

    Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' parameter in the component AdminUpdateController.class.php'.

  • CVE-2020-26772CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.04

    Command Injection in PPGo_Jobs v2.8.0 allows remote attackers to execute arbitrary code via the 'AjaxRun()' function.

  • CVE-2020-19138CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.06

    Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the component "/src/main/java/com/dotmarketing/filters/CMSFilter.java".

  • CVE-2020-24672CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer running the affected product. This issue affects: .

  • CVE-2021-30690CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.01

    Multiple issues in apache were addressed by updating apache to version 2.4.46. This issue is fixed in Security Update 2021-004 Mojave. Multiple issues in apache.

  • CVE-2021-30678CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.03

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.

  • CVE-2021-30655CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.02

    An application may be able to execute arbitrary code with system privileges. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. The issue was addressed with improved permissions logic.

  • CVE-2021-1882CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.02

    A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. An application may be able to gain elevated privileges.

  • CVE-2021-1864CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.02

    A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. An attacker with JavaScript execution may be able to execute arbitrary code.

  • CVE-2021-1834CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.03

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. A malicious application may be able to execute arbitrary code with kernel privileges.

  • CVE-2021-1829CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.02

    A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.3. An application may be able to execute arbitrary code with kernel privileges.

  • CVE-2021-1770CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.03

    A buffer overflow may result in arbitrary code execution. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A logic issue was addressed with improved state management.

  • CVE-2021-30805CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.03

    A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. An application may be able to execute arbitrary code with kernel privileges.

  • CVE-2021-30793CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.03

    A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.5, Security Update 2021-004 Catalina, Security Update 2021-005 Mojave. An application may be able to execute arbitrary code with kernel privileges.

  • CVE-2021-1972CriSep 8, 2021
    risk 0.64cvss 9.8epss 0.01

    Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables,…