VYPR

CVEs

113,590 total · page 1011 of 2,272

  • CVE-2024-24335HigMar 27, 2024
    risk 0.00cvss 8.4epss 0.00

    A heap buffer overflow occurs in the dfs_v2 romfs filesystem RT-Thread through 5.0.2.

  • CVE-2024-24334HigMar 27, 2024
    risk 0.00cvss 8.4epss 0.00

    A heap buffer overflow occurs in dfs_v2 dfs_file in RT-Thread through 5.0.2.

  • CVE-2024-0400HigMar 27, 2024
    risk 0.49cvss 7.5epss 0.01

    SCM Software is a client and server application. An Authenticated System manager client can execute LINQ query in the SCM server, for customized filtering. An Authenticated malicious client can send a specially crafted code to skip the validation and execute arbitrary code (RCE)…

  • CVE-2024-1531HigMar 27, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could print random memory content in the RTU500 system log, if an authorized user uploads a specially crafted stb-language file.

  • CVE-2024-2930HigMar 27, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file classes/Master.php?f=save_music. The manipulation leads to unrestricted upload. The attack can be launched…

  • CVE-2024-2927HigMar 26, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in code-projects Mobile Shop 1.0. It has been classified as critical. Affected is an unknown function of the file Details.php of the component Login Page. The manipulation of the argument id leads to sql injection. It is possible to launch the attack…

  • CVE-2024-2916HigMar 26, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Campcodes House Rental Management System 1.0. It has been classified as critical. Affected is an unknown function of the file ajax.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely.…

  • CVE-2024-26577HigMar 26, 2024
    risk 0.49cvss 7.5epss 0.01

    VSeeFace through 1.13.38.c2 allows attackers to cause a denial of service (application hang) via a spoofed UDP packet containing at least 10 digits in JSON data.

  • CVE-2024-25136HigMar 26, 2024
    risk 0.49cvss 7.5epss 0.01

    There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL without proper sanitizing of the content.

  • CVE-2023-50702HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.01

    Sikka SSCWindowsService 5 2023-09-14 executes a program as LocalSystem but allows full control by low-privileged users (and low-privileged users have write access to %PROGRAMDATA%\SSCService). Consequently, low-privileged users can execute arbitrary code as LocalSystem.

  • CVE-2023-51147HigMar 26, 2024
    risk 0.52cvss 8.0epss 0.01

    Buffer Overflow vulnerability in TRENDnet Trendnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_mod_pwd action.

  • CVE-2023-51146HigMar 26, 2024
    risk 0.52cvss 8.0epss 0.01

    Buffer Overflow vulnerability in TRENDnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_add_user action.

  • CVE-2024-2909HigMar 26, 2024
    risk 0.58cvss 8.8epss 0.04

    A vulnerability classified as critical was found in Ruijie RG-EG350 up to 20240318. Affected by this vulnerability is the function setAction of the file /itbox_pi/networksafe.php?a=set of the component HTTP POST Request Handler. The manipulation of the argument bandwidth leads…

  • CVE-2024-2903HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument mac leads to stack-based buffer overflow. It is possible to launch the…

  • CVE-2024-2887HigMar 26, 2024
    risk 0.52cvss 7.7epss 0.20

    Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-2886HigMar 26, 2024
    risk 0.49cvss 7.5epss 0.02

    Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-2885HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-2883HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.03

    Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2024-28551HigMar 26, 2024
    risk 0.49cvss 7.5epss 0.01

    Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the ssid parameter of form_fast_setting_wifi_set function.

  • CVE-2024-27521HigMar 26, 2024
    risk 0.52cvss 8.0epss 0.01

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parameters in the "setOpModeCfg" function. This security issue allows an attacker to take complete control of the device. In detail,…

  • CVE-2024-25420HigMar 26, 2024
    risk 0.40cvss 7.2epss 0.01

    An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.

  • CVE-2023-51148HigMar 26, 2024
    risk 0.52cvss 8.0epss 0.01

    An issue in TRENDnet Trendnet AC1200 Dual Band PoE Indoor Wireless Access Point TEW-821DAP v.3.00b06 allows an attacker to execute arbitrary code via the 'mycli' command-line interface component.

  • CVE-2023-48275HigMar 26, 2024
    risk 0.52cvss 8.0epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Trustindex.Io Widgets for Google Reviews.This issue affects Widgets for Google Reviews: from n/a through 11.0.2.

  • CVE-2023-39307HigMar 26, 2024
    risk 0.55cvss 8.5epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

  • CVE-2023-28687HigMar 26, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in perfectwpthemes Glaze Blog Lite, themebeez Fascinate, themebeez Cream Blog, themebeez Cream Magazine allows Reflected XSS.This issue affects Glaze Blog Lite: from n/a through <=…

  • CVE-2024-2955HigMar 26, 2024
    risk 0.44cvss 7.8epss 0.01

    T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file

  • CVE-2024-2902HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. This issue affects the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. The manipulation of the argument shareSpeed leads to stack-based buffer overflow. The attack may be initiated…

  • CVE-2024-2901HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. This vulnerability affects the function setSchedWifi of the file /goform/openSchedWifi. The manipulation of the argument schedEndTime leads to stack-based buffer overflow. The attack can be…

  • CVE-2024-2900HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability, which was classified as critical, was found in Tenda AC7 15.03.06.44. This affects the function saveParentControlInfo of the file /goform/saveParentControlInfo. The manipulation of the argument deviceId/time/urls leads to stack-based buffer overflow. It is…

  • CVE-2024-28442HigMar 26, 2024
    risk 0.49cvss 7.5epss 0.01

    Directory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via terms of use function in the company portal component.

  • CVE-2023-6091HigMar 26, 2024
    risk 0.47cvss 7.2epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in mndpsingh287 Theme Editor.This issue affects Theme Editor: from n/a through 2.7.1.

  • CVE-2023-27459HigMar 26, 2024
    risk 0.48cvss 7.4epss 0.01

    Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n/a through 2.3.2.1.

  • CVE-2023-27440HigMar 26, 2024
    risk 0.47cvss 7.2epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in OnTheGoSystems Types.This issue affects Types: from n/a through 3.4.17.

  • CVE-2024-2899HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability, which was classified as critical, has been found in Tenda AC7 15.03.06.44. Affected by this issue is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. The…

  • CVE-2024-2898HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability classified as critical was found in Tenda AC7 15.03.06.44. Affected by this vulnerability is the function fromSetRouteStatic of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack can be…

  • CVE-2024-2896HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. This issue affects the function formWifiWpsStart of the file /goform/WifiWpsStart. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be initiated…

  • CVE-2024-2895HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was found in Tenda AC7 15.03.06.44. It has been declared as critical. This vulnerability affects the function formWifiWpsOOB of the file /goform/WifiWpsOOB. The manipulation of the argument index leads to stack-based buffer overflow. The attack can be initiated…

  • CVE-2024-26646HigMar 26, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: thermal: intel: hfi: Add syscore callbacks for system-wide PM The kernel allocates a memory buffer and provides its location to the hardware, which uses it to update the HFI table. This allocation occurs…

  • CVE-2023-52626HigMar 26, 2024
    risk 0.46cvss 7.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix operation precedence bug in port timestamping napi_poll context Indirection (*) is of lower precedence than postfix increment (++). Logic in napi_poll context would cause an out-of-bound read by…

  • CVE-2023-52624HigMar 26, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before executing GPINT commands [Why] DMCUB can be in idle when we attempt to interface with the HW through the GPINT mailbox resulting in a system hang. [How] Add…

  • CVE-2023-52623HigMar 26, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix a suspicious RCU usage warning I received the following warning while running cthon against an ontap server running pNFS: [ 57.202521] ============================= [ 57.202522] WARNING:…

  • CVE-2023-52621HigMar 26, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: bpf: Check rcu_read_lock_trace_held() before calling bpf map helpers These three bpf_map_{lookup,update,delete}_elem() helpers are also available for sleepable bpf program, so add the corresponding lock…

  • CVE-2023-44989HigMar 26, 2024
    risk 0.49cvss 7.5epss 0.01

    Insertion of Sensitive Information into Log File vulnerability in GSheetConnector CF7 Google Sheets Connector.This issue affects CF7 Google Sheets Connector: from n/a through 5.0.5.

  • CVE-2024-2894HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. This affects the function formSetQosBand of the file /goform/SetNetControlList. The manipulation of the argument list leads to stack-based buffer overflow. It is possible to initiate the…

  • CVE-2024-2893HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. Affected by this issue is the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the argument devName leads to stack-based buffer overflow. The attack may be launched…

  • CVE-2024-2929HigMar 26, 2024
    risk 0.51cvss 7.8epss 0.00

    A memory corruption vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by corrupting the memory triggering an access violation. Once inside, the threat actor can run harmful code…

  • CVE-2024-2915HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to elevate themselves to unauthorized groups via a specially crafted request.

  • CVE-2024-2892HigMar 26, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack can be launched…

  • CVE-2024-2452HigMar 26, 2024
    risk 0.46cvss 7.0epss 0.01

    In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cause an integer wrap-around and an allocation smaller than expected. This could cause subsequent heap buffer overflows.

  • CVE-2024-2214HigMar 26, 2024
    risk 0.46cvss 7.0epss 0.00

    In Eclipse ThreadX before version 6.4.0, the _Mtxinit() function in the Xtensa port was missing an array size check causing a memory overwrite. The affected file was ports/xtensa/xcc/src/tx_clib_lock.c