VYPR

CVEs

1,665 total · page 9 of 34

  • CVE-2024-20399MedKEVJul 1, 2024
    risk 0.51cvss 6.0epss 0.04

    A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient validation…

  • CVE-2024-36401CriKEVJul 1, 2024
    risk 0.80cvss 9.8epss 1.00

    GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a…

  • CVE-2024-4885CriKEVJun 25, 2024
    risk 0.84cvss 9.8epss 0.99

    In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.

  • CVE-2024-37085MedKEVJun 25, 2024
    risk 0.64cvss 6.8epss 0.26

    VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere/2012/09/joining-vs…

  • CVE-2024-37079CriKEVJun 18, 2024
    risk 0.77cvss 9.8epss 0.22

    vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.

  • CVE-2024-6047CriKEVJun 17, 2024
    risk 0.76cvss 9.8epss 0.10

    Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.

  • CVE-2024-32896HigKEVJun 13, 2024
    risk 0.63cvss 7.8epss 0.03

    there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-34102CriKEVJun 13, 2024
    risk 0.80cvss 9.8epss 1.00

    Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted…

  • CVE-2024-35250HigKEVJun 11, 2024
    risk 0.68cvss 7.8epss 0.25

    Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

  • CVE-2024-30088HigKEVJun 11, 2024
    risk 0.69cvss 7.0epss 0.68

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2024-36971HigKEVJun 10, 2024
    risk 0.56cvss 7.8epss 0.03

    In the Linux kernel, the following vulnerability has been resolved: net: fix __dst_negative_advice() race __dst_negative_advice() does not enforce proper RCU rules when sk->dst_cache must be cleared, leading to possible UAF. RCU rules are that we must first clear…

  • CVE-2024-4577CriKEVJun 9, 2024
    risk 0.29cvss 9.8epss 1.00

    In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions.…

  • CVE-2024-4610HigKEVJun 7, 2024
    risk 0.63cvss 7.8epss 0.01

    Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from…

  • CVE-2024-37383MedKEVJun 7, 2024
    risk 0.54cvss 6.1epss 0.73

    Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.

  • CVE-2024-28995HigKEVJun 6, 2024
    risk 0.79cvss 8.6epss 1.00

    SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

  • CVE-2024-29824HigKEVMay 31, 2024
    risk 0.80cvss 8.8epss 1.00

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

  • CVE-2024-23692CriKEVMay 31, 2024
    risk 0.86cvss 9.8epss 0.99

    Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. As of…

  • CVE-2024-4358CriKEVMay 29, 2024
    risk 0.86cvss 9.8epss 0.97

    In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability.

  • CVE-2024-24919HigKEVMay 28, 2024
    risk 0.85cvss 8.6epss 1.00

    Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

  • CVE-2024-5274CriKEVMay 28, 2024
    risk 0.75cvss 9.6epss 0.10

    Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-4978HigKEVMay 23, 2024
    risk 0.69cvss 8.4epss 0.27

    Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.

  • CVE-2024-4947CriKEVMay 15, 2024
    risk 0.76cvss 9.6epss 0.15

    Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-30051HigKEVMay 14, 2024
    risk 0.69cvss 7.8epss 0.06

    Windows DWM Core Library Elevation of Privilege Vulnerability

  • CVE-2024-30040HigKEVMay 14, 2024
    risk 0.70cvss 8.8epss 0.04

    Windows MSHTML Platform Security Feature Bypass Vulnerability

  • CVE-2024-4761HigKEVMay 14, 2024
    risk 0.70cvss 8.8epss 0.11

    Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-4671CriKEVMay 14, 2024
    risk 0.75cvss 9.6epss 0.08

    Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-32113CriKEVMay 8, 2024
    risk 0.80cvss 9.8epss 0.99

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.

  • CVE-2023-50224MedKEVMay 3, 2024
    risk 0.56cvss 6.5epss 0.17

    TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit…

  • CVE-2024-20359MedKEVApr 24, 2024
    risk 0.53cvss 6.0epss 0.19

    A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to…

  • CVE-2024-20353HigKEVApr 24, 2024
    risk 0.74cvss 8.6epss 0.71

    A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of…

  • CVE-2024-4040CriKEVApr 22, 2024
    risk 0.87cvss 9.8epss 1.00

    A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and…

  • CVE-2024-27348CriKEVApr 22, 2024
    risk 0.80cvss 9.8epss 0.99

    RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.

  • CVE-2024-3400CriKEVApr 12, 2024
    risk 0.94cvss 10.0epss 1.00

    A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root…

  • CVE-2024-29988HigKEVApr 9, 2024
    risk 0.73cvss 8.8epss 0.45

    SmartScreen Prompt Security Feature Bypass Vulnerability

  • CVE-2024-29748HigKEVApr 5, 2024
    risk 0.63cvss 7.8epss 0.01

    there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2024-29745MedKEVApr 5, 2024
    risk 0.48cvss 5.5epss 0.00

    there is a possible Information Disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-3273HigKEVApr 4, 2024
    risk 0.67cvss 7.3epss 1.00

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET Request Handler. The…

  • CVE-2024-3272CriKEVApr 4, 2024
    risk 0.84cvss 9.8epss 0.98

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET…

  • CVE-2024-29059HigKEVMar 23, 2024
    risk 0.69cvss 7.5epss 0.99

    .NET Framework Information Disclosure Vulnerability

  • CVE-2024-20767HigKEVMar 18, 2024
    risk 0.71cvss 7.4epss 0.99

    ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not…

  • CVE-2024-26169HigKEVMar 12, 2024
    risk 0.69cvss 7.8epss 0.04

    Windows Error Reporting Service Elevation of Privilege Vulnerability

  • CVE-2023-48788CriKEVMar 12, 2024
    risk 0.93cvss 9.8epss 0.98

    A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

  • CVE-2024-23296HigKEVMar 5, 2024
    risk 0.63cvss 7.8epss 0.01

    A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.7, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary…

  • CVE-2024-23225HigKEVMar 5, 2024
    risk 0.63cvss 7.8epss 0.01

    A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, visionOS 1.1, watchOS 10.4. An attacker with arbitrary…

  • CVE-2024-27199HigKEVMar 4, 2024
    risk 0.73cvss 7.3epss 1.00

    In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

  • CVE-2024-27198CriKEVMar 4, 2024
    risk 0.93cvss 9.8epss 1.00

    In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

  • CVE-2024-1212CriKEVFeb 21, 2024
    risk 0.88cvss 10.0epss 0.95

    Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

  • CVE-2024-1709CriKEVFeb 21, 2024
    risk 0.29cvss 10.0epss 1.00

    ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to confidential information or critical systems.

  • CVE-2024-1708HigKEVFeb 21, 2024
    risk 0.83cvss 8.4epss 0.88

    ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.

  • CVE-2024-20953HigKEVFeb 17, 2024
    risk 0.69cvss 8.8epss 0.03

    Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful…