VYPR

CVEs

113,587 total · page 1014 of 2,272

  • CVE-2024-2807HigMar 22, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.20_multi. This vulnerability affects the function formExpandDlnaFile of the file /goform/expandDlnaFile. The manipulation of the argument filePath leads to stack-based buffer overflow. The attack…

  • CVE-2024-2806HigMar 22, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical has been found in Tenda AC15 15.03.05.18/15.03.20_multi. This affects the function addWifiMacFilter of the file /goform/addWifiMacFilter. The manipulation of the argument deviceId/deviceMac leads to stack-based buffer overflow. It is…

  • CVE-2024-25808HigMar 22, 2024
    risk 0.54cvss 8.3epss 0.00

    Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album function.

  • CVE-2024-2805HigMar 22, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been rated as critical. Affected by this issue is the function formSetSpeedWan of the file /goform/SetSpeedWan. The manipulation of the argument speed_dir leads to stack-based buffer overflow. The attack…

  • CVE-2024-29031HigMar 21, 2024
    risk 0.42cvss 7.5epss 0.01

    Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery prior to version 0.7.17 allows a remote attacker to obtain sensitive information via the `order`…

  • CVE-2024-28171HigMar 21, 2024
    risk 0.53cvss 8.1epss 0.01

    It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.

  • CVE-2024-28040HigMar 21, 2024
    risk 0.58cvss 8.8epss 0.08

    SQL injection vulnerability exists in GetDIAE_astListParameters.

  • CVE-2024-25567HigMar 21, 2024
    risk 0.53cvss 8.1epss 0.01

    Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file system, then the original file will be overwritten.

  • CVE-2024-23975HigMar 21, 2024
    risk 0.58cvss 8.8epss 0.08

    SQL injection vulnerability exists in GetDIAE_slogListParameters.

  • CVE-2024-23494HigMar 21, 2024
    risk 0.58cvss 8.8epss 0.08

    SQL injection vulnerability exists in GetDIAE_unListParameters.

  • CVE-2024-28891HigMar 21, 2024
    risk 0.58cvss 8.8epss 0.08

    SQL injection vulnerability exists in the script Handler_CFG.ashx.

  • CVE-2024-28521HigMar 21, 2024
    risk 0.51cvss 7.8epss 0.00

    SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute arbitrary code and obtain sensitive information via a crafted script to the loginid parameter of the /singlelogin.php component.

  • CVE-2024-28119HigMar 21, 2024
    risk 0.50cvss 8.8epss 0.02

    Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from grav context, an attacker can redefine the escape function and execute arbitrary commands. Twig processing of static pages can be…

  • CVE-2024-28118HigMar 21, 2024
    risk 0.50cvss 8.8epss 0.01

    Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Grav context, an attacker can redefine config variable. As a result, attacker can bypass a previous SSTI mitigation. Twig processing…

  • CVE-2024-28117HigMar 21, 2024
    risk 0.50cvss 8.8epss 0.01

    Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDangerousFunction function, but does not impose restrictions on twig functions like twig_array_map, allowing attackers to bypass the…

  • CVE-2024-28116HigMar 21, 2024
    risk 0.51cvss 8.8epss 0.06

    Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI), which allows any authenticated user (editor permissions are sufficient) to execute arbitrary code on the remote server…

  • CVE-2024-28029HigMar 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.

  • CVE-2024-27921HigMar 21, 2024
    risk 0.55cvss 8.8epss 0.61

    Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior to version 1.7.45, enabling attackers to replace or create files with extensions like .json, .zip, .css, .gif, etc. This critical…

  • CVE-2024-25937HigMar 21, 2024
    risk 0.58cvss 8.8epss 0.08

    SQL injection vulnerability exists in the script DIAE_tagHandler.ashx.

  • CVE-2024-24272HigMar 21, 2024
    risk 0.46cvss 7.1epss 0.00

    An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentials as plaintext in a log file that can be accessed by the local user without knowledge of the master secret.

  • CVE-2024-2764HigMar 21, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48. This affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of the argument endIP leads to stack-based buffer overflow. It is possible to initiate the…

  • CVE-2024-2763HigMar 21, 2024
    risk 0.57cvss 8.8epss 0.02

    A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48. Affected by this issue is the function formSetCfm of the file goform/setcfm. The manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be launched…

  • CVE-2024-29180HigMar 21, 2024
    risk 0.41cvss 7.4epss 0.01

    Prior to versions 7.1.0, 6.1.2, and 5.3.4, the webpack-dev-middleware development middleware for devpack does not validate the supplied URL address sufficiently before returning the local file. It is possible to access any file on the developer's machine. The middleware can…

  • CVE-2024-27968HigMar 21, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue affects Super Page Cache for Cloudflare: from n/a through 4.7.5.

  • CVE-2024-27964HigMar 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.9.

  • CVE-2024-27962HigMar 21, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Florian 'fkrauthan' Krauthan allows Reflected XSS.This issue affects wp-mpdf: from n/a through 3.7.1.

  • CVE-2024-2465HigMar 21, 2024
    risk 0.46cvss 7.1epss 0.01

    Open redirection vulnerability in CDeX application allows to redirect users to arbitrary websites via a specially crafted URL.This issue affects CDeX application versions through 5.7.1.

  • CVE-2024-2463HigMar 21, 2024
    risk 0.52cvss 8.0epss 0.01

    Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX application versions through 5.7.1.

  • CVE-2024-27994HigMar 21, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Product Add-Ons yith-woocommerce-product-add-ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through <= 4.5.0.

  • CVE-2024-27993HigMar 21, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through <= 3.0.2.

  • CVE-2024-29879HigMar 21, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal…

  • CVE-2024-29878HigMar 21, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/sitepreference/add, 'description' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and steal their session data.

  • CVE-2024-29877HigMar 21, 2024
    risk 0.46cvss 7.1epss 0.01

    Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through  /sentrifugo/index.php/expenses/expensecategories/edit, 'expense_category_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially crafted URL to the victim and…

  • CVE-2024-1394HigMar 21, 2024
    risk 0.42cvss 7.5epss 0.02

    A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are…

  • CVE-2024-26643HigMar 21, 2024
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout While the rhashtable set gc runs asynchronously, a race allows it to collect elements from anonymous sets with timeouts while it…

  • CVE-2024-26642HigMar 21, 2024
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: disallow anonymous set with timeout flag Anonymous sets are never used with timeout from userspace, reject this. Exception to this rule is NFT_SET_EVAL to ensure legacy meters still work.

  • CVE-2023-52620HigMar 21, 2024
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: disallow timeout for anonymous sets Never used from userspace, disallow these parameters.

  • CVE-2024-29131HigMar 21, 2024
    risk 0.41cvss 7.3epss 0.02

    Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.

  • CVE-2024-2162HigMar 21, 2024
    risk 0.57cvss 8.8epss 0.02

    An OS Command Injection vulnerability in Kiloview NDI allows a low-privileged user to execute arbitrary code remotely on the device with high privileges. This issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .

  • CVE-2024-29862HigMar 21, 2024
    risk 0.00cvss 7.5epss 0.01

    The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4.2.1 and chirpstack-gateway-bridge before 4.0.11 wrongly accepts certain TCP packets when a connection is not in the ESTABLISHED state.

  • CVE-2024-1538HigMar 21, 2024
    risk 0.51cvss 8.8epss 0.11

    The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation on the wp_file_manager page that includes files through the 'lang' parameter. This makes it…

  • CVE-2024-2053HigMar 21, 2024
    risk 0.52cvss 7.5epss 0.45

    The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user. This issue was demonstrated on version 4.50 of the The Artica-Proxy administrative web…

  • CVE-2024-2014HigMar 21, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in Panabit Panalog 202103080942. This vulnerability affects unknown code of the file /Maintain/sprog_upstatus.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has…

  • CVE-2024-28286HigMar 21, 2024
    risk 0.49cvss 7.5epss 0.01

    In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c function of src/mms/iso_mms/server/mms_file_service.c. The vulnerability manifests as SEGV and causes the application to crash

  • CVE-2024-28123HigMar 21, 2024
    risk 0.41cvss 7.3epss 0.01

    Wasmi is an efficient and lightweight WebAssembly interpreter with a focus on constrained and embedded systems. In the WASMI Interpreter, an Out-of-bounds Buffer Write will arise if the host calls or resumes a Wasm function with more parameters than the default limit (128), as…

  • CVE-2024-28101HigMar 21, 2024
    risk 0.42cvss 7.5epss 0.01

    The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo Federation. Versions 0.9.5 until 1.40.2 are subject to a Denial-of-Service (DoS) type vulnerability. When receiving compressed HTTP payloads, affected versions of the Router…

  • CVE-2024-27936HigMar 21, 2024
    risk 0.50cvss 8.8epss 0.01

    Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Starting in version 1.32.1 and prior to version 1.41.0 of the deno library, maliciously crafted permission request can show the spoofed permission prompt by inserting a broken ANSI escape sequence…

  • CVE-2024-27935HigMar 21, 2024
    risk 0.40cvss 7.2epss 0.01

    Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.35.1 and prior to version 1.36.3, a vulnerability in Deno's Node.js compatibility runtime allows for cross-session data contamination during simultaneous asynchronous reads from Node.js streams…

  • CVE-2024-27934HigMar 21, 2024
    risk 0.55cvss 8.4epss 0.00

    Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.36.2 and prior to version 1.40.3, use of inherently unsafe `*const c_void` and `ExternalPointer` leads to use-after-free access of the underlying structure, resulting in arbitrary code execution.…

  • CVE-2024-27933HigMar 21, 2024
    risk 0.46cvss 8.2epss 0.02

    Deno is a JavaScript, TypeScript, and WebAssembly runtime. In version 1.39.0, use of raw file descriptors in `op_node_ipc_pipe()` leads to premature close of arbitrary file descriptors, allowing standard input to be re-opened as a different resource resulting in permission…