VYPR

CVEs

8,988 total · page 101 of 180

  • CVE-2024-2472CriJun 14, 2024
    risk 0.60cvss 9.1epss 0.05

    The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the 'start_or_use_session_for_customer' function in all versions up to and including 4.9.9. This makes it possible for…

  • CVE-2024-5577CriJun 14, 2024
    risk 0.64cvss 9.8epss 0.02

    The Where I Was, Where I Will Be plugin for WordPress is vulnerable to Remote File Inclusion in version <= 1.1.1 via the WIW_HEADER parameter of the /system/include/include_user.php file. This makes it possible for unauthenticated attackers to include and execute arbitrary files…

  • CVE-2024-4936CriJun 14, 2024
    risk 0.65cvss 9.8epss 0.12

    The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes it possible for unauthenticated attackers to include remote files on the server, resulting in code execution. This required…

  • CVE-2024-27174CriJun 14, 2024
    risk 0.64cvss 9.8epss 0.06

    Remote Command program allows an attacker to get Remote Code Execution. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base…

  • CVE-2024-27173CriJun 14, 2024
    risk 0.67cvss 9.8epss 0.45

    Remote Command program allows an attacker to get Remote Code Execution by overwriting existing Python files containing executable code. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this…

  • CVE-2024-27172CriJun 14, 2024
    risk 0.66cvss 9.8epss 0.31

    Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, see the reference URL.

  • CVE-2024-3080CriJun 14, 2024
    risk 0.68cvss 9.8epss 0.53

    Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.

  • CVE-2024-27145CriJun 14, 2024
    risk 0.64cvss 9.8epss 0.00

    The Toshiba printers provide several ways to upload files using the admin web interface. An attacker can remotely compromise any Toshiba printer. An attacker can overwrite any insecure files. This vulnerability can be executed in combination with other vulnerabilities and …

  • CVE-2024-27144CriJun 14, 2024
    risk 0.64cvss 9.8epss 0.02

    The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker can overwrite any insecure files. And the Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any…

  • CVE-2024-27143CriJun 14, 2024
    risk 0.64cvss 9.8epss 0.00

    Toshiba printers use SNMP for configuration. Using the private community, it is possible to remotely execute commands as root on the remote printer. Using this vulnerability will allow any attacker to get a root access on a remote Toshiba printer. This vulnerability can be…

  • CVE-2024-4371CriJun 13, 2024
    risk 0.59cvss 9.0epss 0.05

    The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.1 via deserialization of untrusted input from the recently_viewed_products…

  • CVE-2024-3922CriJun 13, 2024
    risk 0.65cvss 10.0epss 0.90

    The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

  • CVE-2024-36840CriJun 12, 2024
    risk 0.60cvss 9.1epss 0.12

    SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter to news_details.php and location_details.php; and the section parameter to services.php.

  • CVE-2024-4898CriJun 12, 2024
    risk 0.71cvss 9.8epss 0.90

    The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on the REST API calls in all versions up to, and including, 0.1.0.38. This makes it possible for unauthenticated attackers…

  • CVE-2024-4315CriJun 12, 2024
    risk 0.52cvss 9.1epss 0.01

    parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. The `sanitize_path_from_endpoint` function fails to properly sanitize Windows-style paths (backward slash `\`), allowing attackers to perform directory…

  • CVE-2024-34405CriJun 11, 2024
    risk 0.59cvss 9.1epss 0.00

    Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to launch an arbitrary URL within the app.

  • CVE-2024-3549CriJun 11, 2024
    risk 0.57cvss 9.9epss 0.01

    The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

  • CVE-2024-36360CriJun 11, 2024
    risk 0.64cvss 9.8epss 0.02

    OS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and earlier. If a remote unauthenticated attacker sends a specially crafted HTTP request, an arbitrary OS command may be executed with the privileges of the…

  • CVE-2024-34762CriJun 10, 2024
    risk 0.64cvss 9.9epss 0.01

    Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows PHP Local File Inclusion.This issue affects Advanced Custom Fields PRO:…

  • CVE-2024-3592CriJun 7, 2024
    risk 0.57cvss 9.9epss 0.01

    The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' parameter in all versions up to, and including, 9.0.1 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2024-32752CriJun 6, 2024
    risk 0.59cvss 9.1epss 0.00

    The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attacker to gain unauthorized access

  • CVE-2024-5153CriJun 6, 2024
    risk 0.60cvss 9.1epss 0.05

    The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.15 via the 'dropzone_hash' parameter. This makes it possible for unauthenticated attackers to copy the contents of arbitrary files on the server,…

  • CVE-2024-4295CriJun 5, 2024
    risk 0.64cvss 9.8epss 0.93

    The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

  • CVE-2024-35700CriJun 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect Privilege Assignment vulnerability in DeluxeThemes Userpro userpro.This issue affects Userpro: from n/a through <= 5.1.8.

  • CVE-2024-33560CriJun 4, 2024
    risk 0.59cvss 9.0epss 0.02

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore allows PHP Local File Inclusion.This issue affects XStore: from n/a through 9.3.8.

  • CVE-2024-25600CriJun 4, 2024
    risk 0.76cvss 10.0epss 0.94

    Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6.

  • CVE-2024-4552CriJun 4, 2024
    risk 0.64cvss 9.8epss 0.00

    The Social Login Lite For WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.6.0. This is due to insufficient verification on the user being supplied during the social login through the plugin. This makes it possible for…

  • CVE-2024-31682CriJun 3, 2024
    risk 0.64cvss 9.8epss 0.00

    Incorrect access control in the fingerprint authentication mechanism of Phone Cleaner: Boost & Clean v2.2.0 allows attackers to bypass fingerprint authentication due to the use of a deprecated API.

  • CVE-2023-51219CriJun 3, 2024
    risk 0.62cvss 9.6epss 0.01

    A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controlled JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header.…

  • CVE-2024-4332CriJun 3, 2024
    risk 0.61cvss epss 0.01

    An authentication bypass vulnerability has been identified in the REST and SOAP API components of Tripwire Enterprise (TE) 9.1.0 when TE is configured to use LDAP/Active Directory SAML authentication and its optional "Auto-synchronize LDAP Users, Roles, and Groups" feature is…

  • CVE-2024-37019CriJun 3, 2024
    risk 0.64cvss 9.8epss 0.01

    Northern.tech Mender Enterprise before 3.6.4 and 3.7.x before 3.7.4 has Weak Authentication.

  • CVE-2024-0336CriJun 3, 2024
    risk 0.61cvss epss 0.00

    Missing Authentication for Critical Function vulnerability in EMTA Grup PDKS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDKS: from V3.04 before 20240603. NOTE: The vendor was contacted early about this disclosure but did not…

  • CVE-2024-5404CriJun 3, 2024
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker can change the admin password in a moneo appliance due to weak password recovery mechanism.

  • CVE-2024-5311CriJun 3, 2024
    risk 0.64cvss 9.8epss 0.01

    DigiWin EasyFlow .NET lacks validation for certain input parameters. An unauthenticated remote attacker can inject arbitrary SQL commands to read, modify, and delete database records.

  • CVE-2024-3820CriJun 1, 2024
    risk 0.65cvss 10.0epss 0.02

    The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to SQL Injection via the 'id_key' parameter of the wdt_delete_table_row AJAX action in all versions up to, and including, 6.3.1 due to insufficient escaping on the…

  • CVE-2024-3200CriJun 1, 2024
    risk 0.64cvss 9.9epss 0.01

    The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode in all versions up to, and including, 2.3.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

  • CVE-2024-5176CriMay 31, 2024
    risk 0.61cvss epss 0.00

    Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services with Stolen Credentials.This issue affects Welch Allyn Configuration Tool: versions 1.9.4.1 and prior.

  • CVE-2024-1275CriMay 31, 2024
    risk 0.59cvss epss 0.00

    Use of Default Cryptographic Key vulnerability in Baxter Welch Allyn Connex Spot Monitor may allow Configuration/Environment Manipulation.This issue affects Welch Allyn Connex Spot Monitor in all versions prior to 1.52.

  • CVE-2024-36108CriMay 31, 2024
    risk 0.57cvss 9.8epss 0.00

    casgate is an Open Source Identity and Access Management system. In affected versions `casgate` allows remote unauthenticated attacker to obtain sensitive information via GET request to an API endpoint. This issue has been addressed in PR #201 which is pending merge. An attacker…

  • CVE-2024-36246CriMay 31, 2024
    risk 0.64cvss 9.8epss 0.00

    Missing authorization vulnerability exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be altered or deleted.

  • CVE-2024-32850CriMay 31, 2024
    risk 0.64cvss 9.8epss 0.02

    Improper neutralization of special elements used in a command ('Command Injection') exists in SkyBridge MB-A100/MB-A110 firmware Ver. 4.2.2 and earlier and SkyBridge BASIC MB-A130 firmware Ver. 1.5.5 and earlier. If the remote monitoring and control function is enabled on the…

  • CVE-2024-37018CriMay 31, 2024
    risk 0.59cvss 9.1epss 0.00

    The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the path that is taken by discovery packets.

  • CVE-2024-3300CriMay 30, 2024
    risk 0.61cvss 9.0epss 0.32

    An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to pre-authentication remote code execution.

  • CVE-2024-1100CriMay 30, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vadi Corporate Information Systems DIGIKENT GIS allows SQL Injection. This issue affects DIGIKENT GIS: through 2.23.5.

  • CVE-2024-5514CriMay 30, 2024
    risk 0.64cvss 9.8epss 0.00

    MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be removed or disabled from the management interface. Remote attackers who obtain this account can bypass IP access control restrictions and log in to the backend…

  • CVE-2024-3412CriMay 29, 2024
    risk 0.53cvss 9.1epss 0.09

    The WP STAGING WordPress Backup Plugin – Migration Backup Restore plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wpstg_processing AJAX action in all versions up to, and including, 3.4.3. This makes it possible for…

  • CVE-2024-5150CriMay 29, 2024
    risk 0.57cvss 9.8epss 0.01

    The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.26. This is due to the 'activation_code' default value is empty, and the not empty check is missing in the 'lwp_ajax_register' function. This makes it…

  • CVE-2024-35563CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.00

    CDG-Server-V5.6.2.126.139 and earlier was discovered to contain a SQL injection vulnerability via the permissionId parameter in CDGTempPermissions.

  • CVE-2024-35344CriMay 28, 2024
    risk 0.64cvss 9.9epss 0.00

    Certain Anpviz products contain a hardcoded cryptographic key stored in the firmware of the device. This affects IPC-D250, IPC-D260, IPC-B850, IPC-D850, IPC-D350, IPC-D3150, IPC-D4250, IPC-D380, IPC-D880, IPC-D280, IPC-D3180, MC800N, YM500L, YM800N_N2, YMF50B, YM800SV2, YM500L8,…

  • CVE-2024-35343CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.00

    Certain Anpviz products allow unauthenticated users to download arbitrary files from the device's filesystem via a HTTP GET request to the /playback/ URI. This affects IPC-D250, IPC-D260, IPC-B850, IPC-D850, IPC-D350, IPC-D3150, IPC-D4250, IPC-D380, IPC-D880, IPC-D280,…