VYPR

CVEs

113,580 total · page 1021 of 2,272

  • CVE-2024-26529HigMar 13, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in mz-automation libiec61850 v.1.5.3 and before, allows a remote attacker to cause a denial of service (DoS) via the mmsServer_handleDeleteNamedVariableListRequest function of src/mms/iso_mms/server/mms_named_variable_list_service.c.

  • CVE-2024-2400HigMar 13, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-7072HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.01

    The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.68 via the 'get_posts' REST API Endpoint. This makes it possible for unauthenticated attackers to extract sensitive data…

  • CVE-2024-2395HigMar 12, 2024
    risk 0.47cvss 7.3epss 0.00

    The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.14. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to…

  • CVE-2024-0386HigMar 12, 2024
    risk 0.47cvss 7.2epss 0.01

    The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versions up to, and including, 1.6.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

  • CVE-2024-28236HigMar 12, 2024
    risk 0.43cvss 7.7epss 0.01

    Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Vela pipelines can use variable substitution combined with insensitive fields like `parameters`, `image` and `entrypoint` to inject secrets into a plugin/image and — by using…

  • CVE-2024-24092HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.00

    SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php.

  • CVE-2024-23300HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.00

    A use-after-free issue was addressed with improved memory management. This issue is fixed in GarageBand 10.4.11. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.

  • CVE-2024-28186HigMar 12, 2024
    risk 0.00cvss 7.1epss 0.01

    FreeScout is an open source help desk and shared inbox built with PHP. A vulnerability has been identified in the Free Scout Application, which exposes SMTP server credentials used by an organization in the application to users of the application. This issue arises from the…

  • CVE-2024-28121HigMar 12, 2024
    risk 0.50cvss 8.8epss 0.02

    stimulus_reflex is a system to extend the capabilities of both Rails and Stimulus by intercepting user interactions and passing them to Rails over real-time websockets. In affected versions more methods than expected can be called on reflex instances. Being able to call some of…

  • CVE-2024-28114HigMar 12, 2024
    risk 0.00cvss 8.1epss 0.01

    Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to Remote Code Execution in Peering Manager <=1.8.2. As a result arbitrary commands can be executed on the operating system that is running Peering Manager. This…

  • CVE-2023-5410HigMar 12, 2024
    risk 0.53cvss 8.2epss 0.00

    A potential security vulnerability has been reported in the system BIOS of certain HP PC products, which might allow memory tampering. HP is releasing mitigation for the potential vulnerability.

  • CVE-2024-27894HigMar 12, 2024
    risk 0.55cvss 8.5epss 0.02

    The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the function's implementation is referenced by a URL. The supported URL schemes include "file", "http", and "https". When a function is created using this method, the…

  • CVE-2024-27317HigMar 12, 2024
    risk 0.59cvss 8.4epss 0.57

    In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Functions Worker. However, if a malicious file is uploaded, it could exploit a directory traversal vulnerability. This occurs when…

  • CVE-2024-27135HigMar 12, 2024
    risk 0.56cvss 8.5epss 0.06

    Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java code on the Pulsar Function worker, outside of the sandboxes designated for running user-provided functions. This vulnerability also applies to the Pulsar…

  • CVE-2022-34321HigMar 12, 2024
    risk 0.53cvss 8.2epss 0.02

    Improper Authentication vulnerability in Apache Pulsar Proxy allows an attacker to connect to the /proxy-stats endpoint without authentication. The vulnerable endpoint exposes detailed statistics about live connections, along with the capability to modify the logging level of…

  • CVE-2024-1138HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.00

    The FTL Server component of TIBCO Software Inc.'s TIBCO FTL - Enterprise Edition contains a vulnerability that allows a low privileged attacker with network access to execute a privilege escalation on the affected ftlserver. Affected releases are TIBCO Software Inc.'s TIBCO FTL…

  • CVE-2024-28340HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An information leak in the currentsetting.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 2.5.0.28 allows attackers to obtain sensitive information without any authentication required.

  • CVE-2024-28338HigMar 12, 2024
    risk 0.52cvss 8.0epss 0.01

    A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie.

  • CVE-2024-26204HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.02

    Outlook for Android Information Disclosure Vulnerability

  • CVE-2024-26203HigMar 12, 2024
    risk 0.48cvss 7.3epss 0.01

    Azure Data Studio Elevation of Privilege Vulnerability

  • CVE-2024-26199HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Office Elevation of Privilege Vulnerability

  • CVE-2024-26198HigMar 12, 2024
    risk 0.58cvss 8.8epss 0.07

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2024-26190HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.03

    Microsoft QUIC Denial of Service Vulnerability

  • CVE-2024-26182HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.06

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2024-26178HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2024-26176HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2024-26173HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2024-26170HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.07

    Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability

  • CVE-2024-26169HigKEVMar 12, 2024
    risk 0.69cvss 7.8epss 0.04

    Windows Error Reporting Service Elevation of Privilege Vulnerability

  • CVE-2024-26166HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-26165HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Visual Studio Code Elevation of Privilege Vulnerability

  • CVE-2024-26164HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft Django Backend for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-26162HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft ODBC Driver Remote Code Execution Vulnerability

  • CVE-2024-26161HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-26159HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft ODBC Driver Remote Code Execution Vulnerability

  • CVE-2024-21451HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft ODBC Driver Remote Code Execution Vulnerability

  • CVE-2024-21450HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-21446HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.01

    NTFS Elevation of Privilege Vulnerability

  • CVE-2024-21445HigMar 12, 2024
    risk 0.46cvss 7.0epss 0.01

    Windows USB Print Driver Elevation of Privilege Vulnerability

  • CVE-2024-21444HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-21443HigMar 12, 2024
    risk 0.48cvss 7.3epss 0.01

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2024-21442HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows USB Print Driver Elevation of Privilege Vulnerability

  • CVE-2024-21441HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-21440HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft ODBC Driver Remote Code Execution Vulnerability

  • CVE-2024-21439HigMar 12, 2024
    risk 0.46cvss 7.0epss 0.01

    Windows Telephony Server Elevation of Privilege Vulnerability

  • CVE-2024-21438HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.03

    Microsoft AllJoyn API Denial of Service Vulnerability

  • CVE-2024-21437HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.08

    Windows Graphics Component Elevation of Privilege Vulnerability

  • CVE-2024-21436HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Installer Elevation of Privilege Vulnerability

  • CVE-2024-21435HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows OLE Remote Code Execution Vulnerability