VYPR

CVEs

113,576 total · page 1022 of 2,272

  • CVE-2024-21427HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.02

    Windows Kerberos Security Feature Bypass Vulnerability

  • CVE-2024-21426HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.04

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2024-21421HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.02

    Azure SDK Spoofing Vulnerability

  • CVE-2024-21419HigMar 12, 2024
    risk 0.49cvss 7.6epss 0.01

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

  • CVE-2024-21418HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Software for Open Networking in the Cloud (SONiC) Elevation of Privilege Vulnerability

  • CVE-2024-21411HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.03

    Skype for Consumer Remote Code Execution Vulnerability

  • CVE-2024-21407HigMar 12, 2024
    risk 0.54cvss 8.1epss 0.16

    Windows Hyper-V Remote Code Execution Vulnerability

  • CVE-2024-21392HigMar 12, 2024
    risk 0.42cvss 7.5epss 0.03

    .NET and Visual Studio Denial of Service Vulnerability

  • CVE-2024-21390HigMar 12, 2024
    risk 0.46cvss 7.1epss 0.01

    Microsoft Authenticator Elevation of Privilege Vulnerability

  • CVE-2024-21330HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability

  • CVE-2024-27758HigMar 12, 2024
    risk 0.48cvss 8.4epss 0.01

    In RPyC before 6.0.0, when a server exposes a method that calls the attribute named __array__ for a client-provided netref (e.g., np.array(client_netref)), a remote attacker can craft a class that results in remote code execution.

  • CVE-2024-1529HigMar 12, 2024
    risk 0.48cvss 7.4epss 0.00

    Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/adduser.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially…

  • CVE-2024-1528HigMar 12, 2024
    risk 0.48cvss 7.4epss 0.00

    CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /admin/moduleinterface.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted…

  • CVE-2024-1302HigMar 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker could change the application's file parameter to a log file obtaining all sensitive information such as database credentials.

  • CVE-2024-23112HigMar 12, 2024
    risk 0.52cvss 8.0epss 0.01

    An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.1 through 7.0.13, 6.4.7 through 6.4.14, and FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 SSL-VPN may…

  • CVE-2024-1618HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.00

    A search path or unquoted item vulnerability in Faronics Deep Freeze Server Standard, which affects versions 8.30.020.4627 and earlier. This vulnerability affects the DFServ.exe file. An attacker with local user privileges could exploit this vulnerability to replace the…

  • CVE-2024-1226HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.00

    The software does not neutralize or incorrectly neutralizes certain characters before the data is included in outgoing HTTP headers. The inclusion of invalidated data in an HTTP header allows an attacker to specify the full HTTP response represented by the browser. An attacker…

  • CVE-2023-46717HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when configured with FortiAuthenticator in HA may allow a readonly user to gain read-write access via successive login attempts.

  • CVE-2023-42790HigMar 12, 2024
    risk 0.53cvss 8.1epss 0.01

    A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through…

  • CVE-2023-36554HigMar 12, 2024
    risk 0.53cvss 8.1epss 0.01

    A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specially crafted HTTP requests.

  • CVE-2024-27907HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted Catia MODEL file. This could allow an attacker to execute code in…

  • CVE-2024-22045HigMar 12, 2024
    risk 0.49cvss 7.6epss 0.00

    A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1). The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information. This…

  • CVE-2024-22044HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in SENTRON 3KC ATC6 Expansion Module Ethernet (3KC9000-8TL75) (All versions). Affected devices expose an unused, unstable http service at port 80/tcp on the Modbus-TCP Ethernet. This could allow an attacker on the same Modbus network to create…

  • CVE-2024-22041HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200…

  • CVE-2024-22040HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions), Cerberus PRO EN Fire Panel FC72x IP6 (All versions), Cerberus PRO EN Fire Panel FC72x IP7 (All versions), Cerberus PRO EN Fire Panel FC72x IP8 (All versions < IP8 SR4), Cerberus PRO EN X200…

  • CVE-2024-26288HigMar 12, 2024
    risk 0.57cvss 8.7epss 0.00

    An unauthenticated remote attacker can influence the communication due to the lack of encryption of sensitive data via a MITM. Charging is not affected.

  • CVE-2024-26004HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can DoS a control agent due to access of a uninitialized pointer which may prevent or disrupt the charging functionality.

  • CVE-2024-26003HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can DoS the control agent due to a out-of-bounds read which may prevent or disrupt the charging functionality. 

  • CVE-2024-26002HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.00

    An improper input validation in the Qualcom plctool allows a local attacker with low privileges to gain root access by changing the ownership of specific files.

  • CVE-2024-26001HigMar 12, 2024
    risk 0.48cvss 7.4epss 0.01

    An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not always successful because of memory randomization.

  • CVE-2024-25999HigMar 12, 2024
    risk 0.55cvss 8.4epss 0.00

    An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service. 

  • CVE-2024-25998HigMar 12, 2024
    risk 0.48cvss 7.3epss 0.01

    An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.

  • CVE-2024-27121HigMar 12, 2024
    risk 0.47cvss 7.2epss 0.01

    Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote…

  • CVE-2024-25325HigMar 12, 2024
    risk 0.46cvss 7.1epss 0.00

    SQL injection vulnerability in Employee Management System v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to the txtemail parameter in the login.php.

  • CVE-2024-21805HigMar 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary file may be placed in the specific folder by a user who can log in to the PC where the product's…

  • CVE-2024-28199HigMar 11, 2024
    risk 0.39cvss 7.1epss 0.01

    phlex is an open source framework for building object-oriented views in Ruby. There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. This was due to improper case-sensitivity in the code that was meant to prevent…

  • CVE-2022-46070HigMar 11, 2024
    risk 0.49cvss 7.5epss 0.00

    GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path.

  • CVE-2024-28197HigMar 11, 2024
    risk 0.42cvss 7.5epss 0.00

    Zitadel is an open source identity management system. Zitadel uses a cookie to identify the user agent (browser) and its user sessions. Although the cookie was handled according to best practices, it was accessible on subdomains of the ZITADEL instance. An attacker could take…

  • CVE-2024-28187HigMar 11, 2024
    risk 0.00cvss 7.2epss 0.02

    SOY CMS is an open source CMS (content management system) that allows you to build blogs and online shops. SOY CMS versions prior to 3.14.2 are vulnerable to an OS Command Injection vulnerability within the file upload feature when accessed by an administrator. The vulnerability…

  • CVE-2024-27236HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    In aoc_unlocked_ioctl of aoc.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27233HigMar 11, 2024
    risk 0.51cvss 7.8epss 0.00

    In ppcfw_init_secpolicy of ppcfw.c, there is a possible permission bypass due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27229HigMar 11, 2024
    risk 0.49cvss 7.5epss 0.00

    In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27226HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    In tmu_config_gov_params of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27224HigMar 11, 2024
    risk 0.51cvss 7.8epss 0.00

    In strncpy of strncpy.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27222HigMar 11, 2024
    risk 0.51cvss 7.8epss 0.00

    In onSkipButtonClick of FaceEnrollFoldPage.java, there is a possible way to access the file the app cannot access due to Intent Redirect GRANT_URI_PERMISSIONS Attack. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2024-27221HigMar 11, 2024
    risk 0.51cvss 7.8epss 0.00

    In update_policy_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27220HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    In lpm_req_handler of , there is a possible out of bounds memory access due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27219HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    In tmu_set_pi of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27213HigMar 11, 2024
    risk 0.55cvss 8.4epss 0.00

    In BroadcastSystemMessage of servicemgr.cpp, there is a possible Remote Code Execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27212HigMar 11, 2024
    risk 0.51cvss 7.8epss 0.00

    In init_data of , there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.