VYPR

CVEs

1,665 total · page 7 of 34

  • CVE-2024-57727HigKEVJan 15, 2025
    risk 0.77cvss 7.5epss 0.95

    SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration…

  • CVE-2024-57726CriKEVJan 15, 2025
    risk 0.83cvss 9.9epss 0.09

    SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

  • CVE-2025-21335HigKEVJan 14, 2025
    risk 0.63cvss 7.8epss 0.01

    Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

  • CVE-2025-21334HigKEVJan 14, 2025
    risk 0.63cvss 7.8epss 0.02

    Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

  • CVE-2025-21333HigKEVJan 14, 2025
    risk 0.66cvss 7.8epss 0.10

    Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability

  • CVE-2024-13161CriKEVJan 14, 2025
    risk 0.83cvss 9.8epss 0.90

    Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

  • CVE-2024-13160CriKEVJan 14, 2025
    risk 0.83cvss 9.8epss 0.91

    Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

  • CVE-2024-13159CriKEVJan 14, 2025
    risk 0.84cvss 9.8epss 1.00

    Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

  • CVE-2024-55591CriKEVJan 14, 2025
    risk 0.90cvss 9.8epss 0.98

    An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests…

  • CVE-2024-53704CriKEVJan 9, 2025
    risk 0.89cvss 9.8epss 0.95

    An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

  • CVE-2025-0282CriKEVJan 8, 2025
    risk 0.87cvss 9.0epss 1.00

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

  • CVE-2024-50603CriKEVJan 8, 2025
    risk 0.85cvss 10.0epss 0.99

    An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in…

  • CVE-2024-12987HigKEVDec 27, 2024
    risk 0.67cvss 7.3epss 0.98

    A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads…

  • CVE-2024-53197HigKEVDec 27, 2024
    risk 0.56cvss 7.8epss 0.04

    In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices A bogus device can provide a bNumConfigurations value that exceeds the initial value used in usb_get_configuration for…

  • CVE-2024-3393HigKEVDec 27, 2024
    risk 0.63cvss 7.5epss 0.29

    A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet through the data plane of the firewall that reboots the firewall. Repeated attempts to trigger this condition will…

  • CVE-2024-53150HigKEVDec 24, 2024
    risk 0.51cvss 7.1epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver code doesn't check bLength of each descriptor at traversing for clock descriptors. That is, when a device…

  • CVE-2024-56145CriKEVDec 18, 2024
    risk 0.79cvss 9.8epss 0.97

    Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code…

  • CVE-2024-12686MedKEVDec 18, 2024
    risk 0.56cvss 6.6epss 0.14

    A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.

  • CVE-2024-12356CriKEVDec 17, 2024
    risk 0.86cvss 9.8epss 0.88

    A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.

  • CVE-2024-55956CriKEVDec 13, 2024
    risk 0.92cvss 9.8epss 0.94

    In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

  • CVE-2024-49138HigKEVDec 12, 2024
    risk 0.68cvss 7.8epss 0.25

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2024-55550LowKEVDec 10, 2024
    risk 0.39cvss 2.7epss 0.38

    Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to…

  • CVE-2024-53104HigKEVDec 2, 2024
    risk 0.56cvss 7.8epss 0.03

    In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the…

  • CVE-2024-11667HigKEVNov 27, 2024
    risk 0.67cvss 7.5epss 0.03

    A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series…

  • CVE-2024-49035HigKEVNov 26, 2024
    risk 0.69cvss 8.7epss 0.01

    An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

  • CVE-2024-11680CriKEVNov 26, 2024
    risk 0.86cvss 9.8epss 0.92

    ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration.…

  • CVE-2024-44309MedKEVNov 20, 2024
    risk 0.55cvss 6.3epss 0.23

    A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to a cross site…

  • CVE-2024-44308HigKEVNov 20, 2024
    risk 0.70cvss 8.8epss 0.09

    The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware…

  • CVE-2024-50302MedKEVNov 19, 2024
    risk 0.48cvss 5.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: HID: core: zero-initialize the report buffer Since the report buffer is used by all kinds of drivers in various ways, let's zero-initialize it during allocation to make sure that it can't be ever used to leak…

  • CVE-2024-21287HigKEVNov 18, 2024
    risk 0.61cvss 7.5epss 0.01

    Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

  • CVE-2024-9474HigKEVNov 18, 2024
    risk 0.75cvss 7.2epss 0.95

    A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access are not impacted by this vulnerability.

  • CVE-2024-0012CriKEVNov 18, 2024
    risk 0.93cvss 9.8epss 1.00

    An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other…

  • CVE-2024-11182MedKEVNov 15, 2024
    risk 0.53cvss 6.1epss 0.17

    An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window.

  • CVE-2024-11120CriKEVNov 15, 2024
    risk 0.78cvss 9.8epss 0.29

    Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we…

  • CVE-2024-43093HigKEVNov 13, 2024
    risk 0.60cvss 7.3epss 0.01

    In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode normalization. This could lead to local escalation of privilege with no additional execution…

  • CVE-2024-8069HigKEVNov 12, 2024
    risk 0.65cvss 8.0epss 0.15

    Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server

  • CVE-2024-8068HigKEVNov 12, 2024
    risk 0.64cvss 8.0epss 0.01

    Privilege escalation to NetworkService Account access in Citrix Session Recording when an attacker is an authenticated user in the same Windows Active Directory domain as the session recording server domain

  • CVE-2024-49039HigKEVNov 12, 2024
    risk 0.76cvss 8.8epss 0.14

    Windows Task Scheduler Elevation of Privilege Vulnerability

  • CVE-2024-43451MedKEVNov 12, 2024
    risk 0.61cvss 6.5epss 0.82

    NTLM Hash Disclosure Spoofing Vulnerability

  • CVE-2024-51567CriKEVOct 29, 2024
    risk 0.93cvss 10.0epss 0.87

    upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a POST request) and using shell…

  • CVE-2024-51378CriKEVOct 29, 2024
    risk 0.94cvss 10.0epss 0.95

    getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST…

  • CVE-2024-50623CriKEVOct 28, 2024
    risk 0.90cvss 9.8epss 0.99

    In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.

  • CVE-2024-20481MedKEVOct 23, 2024
    risk 0.51cvss 5.8epss 0.16

    A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service. This…

  • CVE-2024-47575CriKEVOct 23, 2024
    risk 0.86cvss 9.8epss 0.95

    A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1…

  • CVE-2024-41713CriKEVOct 21, 2024
    risk 0.85cvss 9.1epss 0.98

    A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized…

  • CVE-2024-9537CriKEVOct 18, 2024
    risk 0.76cvss 9.8epss 0.04

    ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component packaged with SL1. The vulnerability is addressed in SL1 versions 12.1.3+, 12.2.3+, and 12.3+. Remediations have been made available for all SL1 versions…

  • CVE-2024-9465CriKEVOct 9, 2024
    risk 0.79cvss 9.1epss 1.00

    An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary…

  • CVE-2024-9463HigKEVOct 9, 2024
    risk 0.69cvss 7.5epss 0.98

    An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

  • CVE-2024-9680CriKEVOct 9, 2024
    risk 0.84cvss 9.8epss 0.23

    An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR <…

  • CVE-2024-43573MedKEVOct 8, 2024
    risk 0.58cvss 6.5epss 0.44

    Windows MSHTML Platform Spoofing Vulnerability