VYPR

CVEs

38,061 total · page 516 of 762

  • CVE-2021-34552CriJul 13, 2021
    risk 0.57cvss 9.8epss 0.03

    Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.

  • CVE-2020-22884CriJul 13, 2021
    risk 0.64cvss 9.8epss 0.03

    Buffer overflow vulnerability in function jsvGetStringChars in Espruino before RELEASE_2V09, allows remote attackers to execute arbitrary code.

  • CVE-2020-22875CriJul 13, 2021
    risk 0.64cvss 9.8epss 0.03

    Integer overflow vulnerability in function Jsi_ObjSetLength in jsish before 3.0.6, allows remote attackers to execute arbitrary code.

  • CVE-2020-22874CriJul 13, 2021
    risk 0.64cvss 9.8epss 0.03

    Integer overflow vulnerability in function Jsi_ObjArraySizer in jsish before 3.0.8, allows remote attackers to execute arbitrary code.

  • CVE-2020-22873CriJul 13, 2021
    risk 0.64cvss 9.8epss 0.02

    Buffer overflow vulnerability in function NumberToPrecisionCmd in jsish before 3.0.7, allows remote attackers to execute arbitrary code.

  • CVE-2021-36124CriJul 13, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability for unauthenticated users to access pages that are vulnerable to attacks such as SQL injection.

  • CVE-2021-33578CriJul 13, 2021
    risk 0.64cvss 9.8epss 0.01

    Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticated and unauthenticated users, leading to the ability to bypass authentication, exfiltrate Structured Query Language (SQL) records, and manipulate data.

  • CVE-2021-1965CriJul 13, 2021
    risk 0.64cvss 9.8epss 0.03

    Possible buffer overflow due to lack of parameter length check during MBSSID scan IE parse in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

  • CVE-2020-11307CriJul 13, 2021
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in modem due to improper array index check before copying into it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

  • CVE-2021-24442CriJul 12, 2021
    risk 0.67cvss 9.8epss 0.46

    The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks

  • CVE-2021-24385CriJul 12, 2021
    risk 0.64cvss 9.8epss 0.03

    The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerability as the user input is not escaped and passed directly to the get_col function and it allows SQL…

  • CVE-2020-18544CriJul 12, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection in WMS v1.0 allows remote attackers to execute arbitrary code via the "username" parameter in the component "chkuser.php".

  • CVE-2020-19038CriJul 12, 2021
    risk 0.59cvss 9.1epss 0.01

    File Deletion vulnerability in Halo 0.4.3 via delBackup.

  • CVE-2021-23390CriJul 12, 2021
    risk 0.57cvss 9.8epss 0.03

    The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

  • CVE-2021-23389CriJul 12, 2021
    risk 0.57cvss 9.8epss 0.04

    The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

  • CVE-2020-18980CriJul 12, 2021
    risk 0.64cvss 9.8epss 0.01

    Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters.

  • CVE-2020-21133CriJul 12, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Metinfo 7.0.0 beta in member/getpassword.php?lang=cn&a=dovalid.

  • CVE-2020-21132CriJul 12, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Metinfo 7.0.0beta in index.php.

  • CVE-2021-35064CriJul 12, 2021
    risk 0.72cvss 9.8epss 0.71

    KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits running of multiple dangerous commands, including unzip, systemctl and dpkg.

  • CVE-2021-29102CriJul 11, 2021
    risk 0.59cvss 9.1epss 0.02

    A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthenticated attacker to forge GET requests to arbitrary URLs from the system, potentially leading to network enumeration or facilitating other attacks.

  • CVE-2021-24007CriJul 9, 2021
    risk 0.64cvss 9.8epss 0.01

    Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

  • CVE-2021-30120CriJul 9, 2021
    risk 0.65cvss 9.9epss 0.06

    Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforce client-side instead of server-side and can be bypassed using a local proxy. Thus rendering 2FA useless. Detailed description --- During the login process,…

  • CVE-2021-30118CriJul 9, 2021
    risk 0.69cvss 9.8epss 0.60

    An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and subsequently use these files to execute asp commands The api /SystemTab/uploader.aspx is vulnerable to an unauthenticated…

  • CVE-2021-30117CriJul 9, 2021
    risk 0.69cvss 9.8epss 0.72

    The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the parameter fldrId. Detailed description --- Given the following request: ``` GET /InstallTab/exportFldr.asp?fldrId=1’ HTTP/1.1 Host: 192.168.1.194 User-Agent:…

  • CVE-2021-30116CriKEVJul 9, 2021
    risk 0.90cvss 10.0epss 0.86

    Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker…

  • CVE-2012-2666CriJul 9, 2021
    risk 0.57cvss 9.8epss 0.02

    golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporary file with predicable name and executes it as shell script.

  • CVE-2020-23580CriJul 8, 2021
    risk 0.64cvss 9.8epss 0.02

    Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.

  • CVE-2021-25437CriJul 8, 2021
    risk 0.64cvss 9.8epss 0.02

    Improper access control vulnerability in Tizen FOTA service prior to Firmware update JUL-2021 Release allows attackers to arbitrary code execution by replacing FOTA update file.

  • CVE-2021-25436CriJul 8, 2021
    risk 0.64cvss 9.8epss 0.02

    Improper input validation vulnerability in Tizen FOTA service prior to Firmware update JUL-2021 Release allows arbitrary code execution via Samsung Accessory Protocol.

  • CVE-2021-25435CriJul 8, 2021
    risk 0.64cvss 9.8epss 0.02

    Improper input validation vulnerability in Tizen bootloader prior to Firmware update JUL-2021 Release allows arbitrary code execution using recovery partition in wireless firmware download mode.

  • CVE-2021-25434CriJul 8, 2021
    risk 0.64cvss 9.8epss 0.02

    Improper input validation vulnerability in Tizen bootloader prior to Firmware update JUL-2021 Release allows arbitrary code execution using param partition in wireless firmware download mode.

  • CVE-2021-21821CriJul 8, 2021
    risk 0.64cvss 9.8epss 0.02

    A stack-based buffer overflow vulnerability exists in the PDF process_fontname functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-28809CriJul 8, 2021
    risk 0.65cvss 9.8epss 0.16

    An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security of the operating system.QNAP have already fixed this vulnerability in the following versions of HBS…

  • CVE-2021-21807CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.01

    An integer overflow vulnerability exists in the DICOM parse_dicom_meta_info functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to a stack-based buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-33221CriJul 7, 2021
    risk 0.68cvss 9.8epss 0.56

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Unauthenticated API Endpoints.

  • CVE-2021-33219CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the admin and nplus1user accounts.

  • CVE-2021-33218CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded System Passwords that provide shell access.

  • CVE-2021-33216CriJul 7, 2021
    risk 0.68cvss 9.8epss 0.14

    An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account.

  • CVE-2021-32538CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    ARTWARE CMS parameter of image upload function does not filter the type of upload files which allows remote attackers can upload arbitrary files without logging in, and further execute code unrestrictedly.

  • CVE-2021-32535CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.01

    The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administrator’s permission and execute arbitrary functions. The referred vulnerability has been solved with the updated version of QSAN SANOS v2.1.0.

  • CVE-2021-32534CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version of QSAN SANOS v2.1.0.

  • CVE-2021-32533CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version of QSAN SANOS v2.1.0.

  • CVE-2021-32531CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version of QSAN XEVO v2.1.0.

  • CVE-2021-32530CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arbitrary commands via status parameter. The referred vulnerability has been solved with the updated version of QSAN XEVO v2.1.0.

  • CVE-2021-32529CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.02

    Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

  • CVE-2021-32525CriJul 7, 2021
    risk 0.59cvss 9.1epss 0.02

    The same hard-coded password in QSAN Storage Manager's in the firmware allows remote attackers to access the control interface with the administrator’s credential, entering the hard-coded password of the debug mode to execute the restricted system instructions. The referred…

  • CVE-2021-32524CriJul 7, 2021
    risk 0.59cvss 9.1epss 0.02

    Command injection vulnerability in QSAN Storage Manager allows remote privileged users to execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

  • CVE-2021-32523CriJul 7, 2021
    risk 0.59cvss 9.1epss 0.01

    Improper authorization vulnerability in QSAN Storage Manager allows remote privileged users to bypass the access control and execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.

  • CVE-2021-32522CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.01

    Improper restriction of excessive authentication attempts vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to discover users’ credentials and obtain access via a brute force attack. Suggest contacting with QSAN and refer to recommendations in QSAN…

  • CVE-2021-32520CriJul 7, 2021
    risk 0.64cvss 9.8epss 0.01

    Use of hard-coded cryptographic key vulnerability in QSAN Storage Manager allows attackers to obtain users’ credentials and related permissions. Suggest contacting with QSAN and refer to recommendations in QSAN Document.