VYPR

CVEs

113,602 total · page 1000 of 2,273

  • CVE-2023-52549HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52546HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of package name verification being bypassed in the Calendar app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52545HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52541HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Authentication vulnerability in the API for app pre-loading. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52540HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of improper authentication in the Iaware module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52539HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52537HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52388HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Permission control vulnerability in the clock module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52359HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of permission verification in some APIs in the ActivityTaskManagerService module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52351HigApr 8, 2024
    risk 0.51cvss 7.8epss 0.00

    In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed

  • CVE-2023-52342HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

  • CVE-2023-52341HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    In Plaintext COUNTER CHECK message accepted before AS security activation, there is a possible missing permission check. This could lead to remote information disclosure no additional execution privileges needed

  • CVE-2024-28744HigApr 8, 2024
    risk 0.57cvss 8.8epss 0.00

    The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmware v02.04 and earlier. An unauthenticated attacker may log in to the product with no password, and obtain and/or alter information such as network…

  • CVE-2024-3437HigApr 8, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /Admin/add-admin.php of the component Avatar Handler. The manipulation of the argument avatar leads to unrestricted…

  • CVE-2020-36829HigApr 8, 2024
    risk 0.42cvss 7.5epss 0.01

    The Mojolicious module before 8.65 for Perl is vulnerable to secure_compare timing attacks that allow an attacker to guess the length of a secret string. Only versions after 1.74 are affected.

  • CVE-2024-31292HigApr 7, 2024
    risk 0.47cvss 7.2epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Moove Agency Import XML and RSS Feeds.This issue affects Import XML and RSS Feeds: from n/a through 2.1.5.

  • CVE-2024-31288HigApr 7, 2024
    risk 0.47cvss 7.2epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in RapidLoad RapidLoad Power-Up for Autoptimize.This issue affects RapidLoad Power-Up for Autoptimize: from n/a through 2.2.11.

  • CVE-2024-31277HigApr 7, 2024
    risk 0.57cvss 8.7epss 0.00

    Deserialization of Untrusted Data vulnerability in PickPlugins Product Designer.This issue affects Product Designer: from n/a through 1.0.32.

  • CVE-2024-31260HigApr 7, 2024
    risk 0.49cvss 7.6epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WisdmLabs Edwiser Bridge.This issue affects Edwiser Bridge: from n/a through 3.0.2.

  • CVE-2024-31256HigApr 7, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebinarPress allows Reflected XSS.This issue affects WebinarPress: from n/a through 1.33.10.

  • CVE-2024-31255HigApr 7, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ELEXtensions ELEX WooCommerce Dynamic Pricing and Discounts allows Reflected XSS.This issue affects ELEX WooCommerce Dynamic Pricing and Discounts: from n/a through 2.1.2.

  • CVE-2024-31241HigApr 7, 2024
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress LearnPress Export Import.This issue affects LearnPress Export Import: from n/a through 4.0.3.

  • CVE-2024-31234HigApr 7, 2024
    risk 0.55cvss 8.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sizam REHub Framework.This issue affects REHub Framework: from n/a before 19.6.2.

  • CVE-2024-31233HigApr 7, 2024
    risk 0.55cvss 8.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sizam Rehub.This issue affects Rehub: from n/a through 19.6.1.

  • CVE-2024-30418HigApr 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of insufficient permission verification in the app management module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-30417HigApr 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Path traversal vulnerability in the Bluetooth-based sharing module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-30416HigApr 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Use After Free (UAF) vulnerability in the underlying driver module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52716HigApr 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of starting activities in the background in the ActivityManagerService (AMS) module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52715HigApr 7, 2024
    risk 0.49cvss 7.5epss 0.00

    The SystemUI module has a vulnerability in permission management. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-52714HigApr 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of defects introduced in the design process in the hwnff module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52713HigApr 7, 2024
    risk 0.50cvss 7.7epss 0.00

    Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.

  • CVE-2024-30414HigApr 7, 2024
    risk 0.49cvss 7.5epss 0.01

    Command injection vulnerability in the AccountManager module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2024-30413HigApr 7, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-3413HigApr 6, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in SourceCodester Human Resource Information System 1.0 and classified as critical. This vulnerability affects unknown code of the file initialize/login_process.php. The manipulation of the argument hr_email/hr_password leads to sql injection. The…

  • CVE-2024-28741HigApr 6, 2024
    risk 0.66cvss 8.8epss 0.78

    Cross Site Scripting vulnerability in EginDemirbilek NorthStar C2 v1 allows a remote attacker to execute arbitrary code via the login.php component.

  • CVE-2024-27620HigApr 6, 2024
    risk 0.52cvss 7.5epss 0.02

    An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request to the API.

  • CVE-2024-3159HigApr 6, 2024
    risk 0.57cvss 8.8epss 0.02

    Out of bounds memory access in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-3158HigApr 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in Bookmarks in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-3156HigApr 6, 2024
    risk 0.57cvss 8.8epss 0.13

    Inappropriate implementation in V8 in Google Chrome prior to 123.0.6312.105 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-3376HigApr 6, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part of the file config.php. The manipulation of the argument url leads to execution after redirect. It is possible to initiate the attack…

  • CVE-2024-24746HigApr 6, 2024
    risk 0.00cvss 7.5epss 0.01

    Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE.  Specially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device. This issue affects Apache NimBLE: through 1.6.0. Users…

  • CVE-2024-22328HigApr 6, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 279950.

  • CVE-2024-3363HigApr 6, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Online Library System 1.0. It has been classified as critical. This affects an unknown part of the file admin/borrowed/index.php. The manipulation of the argument BookPublisher/BookTitle leads to sql injection. It is possible to…

  • CVE-2024-3362HigApr 6, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Online Library System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/books/controller.php. The manipulation of the argument IBSN leads to sql injection. The attack may be launched…

  • CVE-2024-3361HigApr 6, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in SourceCodester Online Library System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin/books/deweydecimal.php. The manipulation of the argument category leads to sql injection. The…

  • CVE-2024-3360HigApr 6, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Online Library System 1.0. Affected is an unknown function of the file admin/books/index.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely.…

  • CVE-2024-3359HigApr 6, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Online Library System 1.0. This issue affects some unknown processing of the file admin/login.php. The manipulation of the argument user_email leads to sql injection. The attack may be initiated…

  • CVE-2024-1385HigApr 6, 2024
    risk 0.46cvss 7.1epss 0.00

    The WP-Stateless – Google Cloud Storage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the dismiss_notices() function in all versions up to, and including, 3.4.0. This makes it possible for authenticated attackers, with…

  • CVE-2024-3356HigApr 5, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file admin/mod_settings/controller.php?action=add. The manipulation of the argument type…

  • CVE-2024-3355HigApr 5, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file admin/mod_users/controller.php?action=add. The manipulation of the argument…