VYPR

CVEs

8,988 total · page 102 of 180

  • CVE-2024-22590CriMay 28, 2024
    risk 0.59cvss 9.1epss 0.00

    The TLS engine in Kwik commit 745fd4e2 does not track the current state of the connection. This vulnerability can allow Client Hello messages to be overwritten at any time, including after a connection has been established.

  • CVE-2024-0851CriMay 27, 2024
    risk 0.65cvss epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Grup Arge Energy and Control Systems Smartpower allows SQL Injection. This issue affects Smartpower: through V24.05.27.

  • CVE-2024-35592CriMay 24, 2024
    risk 0.62cvss 9.6epss 0.00

    An arbitrary file upload vulnerability in the Upload function of Box-IM v2.0 allows attackers to execute arbitrary code via uploading a crafted PDF file.

  • CVE-2024-4544CriMay 24, 2024
    risk 0.64cvss 9.8epss 0.00

    The Pie Register - Social Sites Login (Add on) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.7. This is due to insufficient verification on the user being supplied during a social login through the plugin. This makes it…

  • CVE-2024-5084CriMay 23, 2024
    risk 0.67cvss 9.8epss 0.93

    The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to…

  • CVE-2024-5168CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerability could allow an unauthenticated user to bypass authentication entirely and execute arbitrary API requests against the web application.

  • CVE-2024-25738CriMay 22, 2024
    risk 0.52cvss 9.1epss 0.01

    A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0 through 9.1 before 9.1.1 allows a remote attacker to overwrite local configuration files to gain access to the administrator panel and achieve Remote Code…

  • CVE-2024-33226CriMay 22, 2024
    risk 0.64cvss 9.9epss 0.00

    An issue in the component Access64.sys of Wistron Corporation TBT Force Power Control v1.0.0.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

  • CVE-2024-3495CriMay 22, 2024
    risk 0.71cvss 9.8epss 0.93

    The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' parameters in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

  • CVE-2024-5147CriMay 22, 2024
    risk 0.57cvss 9.8epss 0.01

    The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.37 via the 'grid_style' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary…

  • CVE-2024-4443CriMay 22, 2024
    risk 0.64cvss 9.8epss 0.94

    The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter…

  • CVE-2023-3943CriMay 21, 2024
    risk 0.65cvss 10.0epss 0.01

    Stack-based Buffer Overflow vulnerability in ZkTeco-based OEM devices allows, in some cases, the execution of arbitrary code. Due to the lack of protection mechanisms such as stack canaries and PIE, it is possible to successfully execute code even under restrictive conditions. …

  • CVE-2024-35361CriMay 21, 2024
    risk 0.64cvss 9.8epss 0.00

    MTab Bookmark v1.9.5 has an SQL injection vulnerability in /LinkStore/getIcon. An attacker can execute arbitrary SQL statements through this vulnerability without requiring any user rights.

  • CVE-2023-3941CriMay 21, 2024
    risk 0.65cvss 10.0epss 0.01

    Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to write any file on the system with root privileges. This issue affects ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec ST-FR041ME and possibly others) with the…

  • CVE-2023-3939CriMay 21, 2024
    risk 0.65cvss 10.0epss 0.01

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in ZkTeco-based OEM devices allows OS Command Injection. Since all the found command implementations are executed from the superuser, their impact is the maximum…

  • CVE-2024-4442CriMay 21, 2024
    risk 0.54cvss 9.1epss 0.27

    The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 9.8. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated…

  • CVE-2024-34947CriMay 20, 2024
    risk 0.61cvss 9.4epss 0.00

    Quanxun Huiju Network Technology (Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 was discovered to be vulnerable to an ICMP redirect attack.

  • CVE-2024-24294CriMay 20, 2024
    risk 0.57cvss 9.8epss 0.00

    A Prototype Pollution issue in Blackprint @blackprint/engine v.0.9.0 allows an attacker to execute arbitrary code via the _utils.setDeepProperty function of engine.min.js.

  • CVE-2024-35960CriMay 20, 2024
    risk 0.59cvss 9.1epss 0.03

    In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Properly link new fs rules into the tree Previously, add_rule_fg would only add newly created rules from the handle into the tree when they had a refcount of 1. On the other hand, create_flow_handle…

  • CVE-2024-36081CriMay 19, 2024
    risk 0.64cvss 9.8epss 0.00

    Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.

  • CVE-2024-36080CriMay 19, 2024
    risk 0.64cvss 9.8epss 0.00

    Westermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be changed. NOTE: this is a serial-to-Ethernet converter that should not be placed at the edge of the network.

  • CVE-2024-36053CriMay 19, 2024
    risk 0.59cvss 9.0epss 0.01

    In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell metacharacters in check_connection, drop_data_received_cb, and Service.remove. A user can modify a service name in a ~/.linuxmint/mintUpload/services/service…

  • CVE-2024-28064CriMay 18, 2024
    risk 0.64cvss 9.8epss 0.01

    Kiteworks Totemomail 7.x and 8.x before 8.3.0 allows /responsiveUI/EnvelopeOpenServlet messageId directory traversal for unauthenticated file read and delete operations (with displayLoginChunkedImages) and write operations (with storeLoginChunkedImages).

  • CVE-2024-2771CriMay 18, 2024
    risk 0.58cvss 9.8epss 0.22

    The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the /wp-json/fluentform/v1/managers REST API endpoint in all versions up to, and including,…

  • CVE-2024-4264CriMay 18, 2024
    risk 0.64cvss 9.8epss 0.03

    A remote code execution (RCE) vulnerability exists in the berriai/litellm project due to improper control of the generation of code when using the `eval` function unsafely in the `litellm.get_secret()` method. Specifically, when the server utilizes Google KMS, untrusted data is…

  • CVE-2024-35845CriMay 17, 2024
    risk 0.59cvss 9.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dbg-tlv: ensure NUL termination The iwl_fw_ini_debug_info_tlv is used as a string, so we must ensure the string is terminated correctly before using it.

  • CVE-2024-34919CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.00

    An arbitrary file upload vulnerability in the component \modstudent\controller.php of Pisay Online E-Learning System using PHP/MySQL v1.0 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-32809CriMay 17, 2024
    risk 0.65cvss 10.0epss 0.02

    Unrestricted Upload of File with Dangerous Type vulnerability in JumpDEMAND Inc. ActiveDEMAND allows Using Malicious Files.This issue affects ActiveDEMAND: from n/a through 0.2.41.

  • CVE-2024-33644CriMay 17, 2024
    risk 0.66cvss 9.9epss 0.17

    Improper Control of Generation of Code ('Code Injection') vulnerability in WPCustomify Customify Site Library allows Code Injection.This issue affects Customify Site Library: from n/a through 0.0.9.

  • CVE-2024-33567CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Privilege Management vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager allows Privilege Escalation.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.

  • CVE-2024-32511CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Privilege Management vulnerability in Astoundify Simple Registration for WooCommerce allows Privilege Escalation.This issue affects Simple Registration for WooCommerce: from n/a through 1.5.6.

  • CVE-2024-31290CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Privilege Management vulnerability in CodeRevolution Demo My WordPress allows Privilege Escalation.This issue affects Demo My WordPress: from n/a through 1.0.9.1.

  • CVE-2024-31231CriMay 17, 2024
    risk 0.59cvss 9.0epss 0.02

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sizam Design Rehub allows PHP Local File Inclusion.This issue affects Rehub: from n/a through 19.6.1.

  • CVE-2024-27954CriMay 17, 2024
    risk 0.68cvss 9.3epss 0.93

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0.

  • CVE-2024-24882CriMay 17, 2024
    risk 0.68cvss 9.8epss 0.51

    Incorrect Privilege Assignment vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.7.2.

  • CVE-2024-22157CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Privilege Management vulnerability in WebWizards SalesKing allows Privilege Escalation.This issue affects SalesKing: from n/a through 1.6.15.

  • CVE-2023-51483CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Privilege Management vulnerability in Glowlogix WP Frontend Profile allows Privilege Escalation.This issue affects WP Frontend Profile: from n/a through 1.3.1.

  • CVE-2023-51481CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Privilege Management vulnerability in powerfulwp Local Delivery Drivers for WooCommerce allows Privilege Escalation.This issue affects Local Delivery Drivers for WooCommerce: from n/a through 1.9.0.

  • CVE-2023-51476CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Privilege Management vulnerability in IOSS WP MLM Unilevel allows Privilege Escalation.This issue affects WP MLM Unilevel: from n/a through 4.0.

  • CVE-2023-51424CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Privilege Management vulnerability in Saleswonder Team WebinarIgnition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through 3.05.0.

  • CVE-2023-32297CriMay 17, 2024
    risk 0.59cvss 9.0epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LWS LWS Affiliation allows PHP Local File Inclusion.This issue affects LWS Affiliation: from n/a through 2.2.6.

  • CVE-2023-32244CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Privilege Management vulnerability in xtemos Woodmart Core allows Privilege Escalation.This issue affects Woodmart Core: from n/a through 1.0.36.

  • CVE-2023-26540CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Privilege Management vulnerability in Favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 2.7.1.

  • CVE-2023-26009CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Privilege Management vulnerability in Favethemes Houzez Login Register allows Privilege Escalation.This issue affects Houzez Login Register: from n/a through 2.6.3.

  • CVE-2024-3551CriMay 17, 2024
    risk 0.64cvss 9.8epss 0.01

    The Penci Soledad Data Migrator plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.0 via the 'data' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing…

  • CVE-2024-22476CriMay 16, 2024
    risk 0.71cvss 10.0epss 0.75

    Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access.

  • CVE-2024-5023CriMay 16, 2024
    risk 0.54cvss epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe allows Command Injection.This issue affects ConsoleMe: before 1.4.0.

  • CVE-2024-35187CriMay 16, 2024
    risk 0.52cvss 9.1epss 0.00

    Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execution as the stalwart-mail user (including web interface admins) can gain complete root access to the system. Usually, system services are run as a separate user…

  • CVE-2023-48643CriMay 16, 2024
    risk 0.64cvss 9.8epss 0.07

    Shrubbery tac_plus 2.x, 3.x. and 4.x through F4.0.4.28 allows unauthenticated Remote Command Execution. The product allows users to configure authorization checks as shell commands through the tac_plus.cfg configuration file. These are executed when a client sends an…

  • CVE-2024-4999CriMay 16, 2024
    risk 0.61cvss epss 0.03

    A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through…