VYPR

CVEs

113,508 total · page 1028 of 2,271

  • CVE-2023-52478HigFeb 29, 2024
    risk 0.57cvss 8.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Fix kernel crash on receiver USB disconnect hidpp_connect_event() has *four* time-of-check vs time-of-use (TOCTOU) races when it races with itself. hidpp_connect_event() primarily runs…

  • CVE-2023-52475HigFeb 29, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: Input: powermate - fix use-after-free in powermate_config_complete syzbot has found a use-after-free bug [1] in the powermate driver. This happens when the device is disconnected, which leads to a memory free…

  • CVE-2023-50905HigFeb 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows Stored XSS.This issue affects WP Activity Log: from n/a through 4.6.1.

  • CVE-2023-1841HigFeb 29, 2024
    risk 0.53cvss 8.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Honeywell MPA2 Access Panel (Web server modules) allows XSS Using Invalid Characters.This issue affects MPA2 Access Panel all version prior to R1.00.08.05.  Honeywell released…

  • CVE-2024-1468HigFeb 29, 2024
    risk 0.57cvss 8.8epss 0.01

    The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_import_options() function in all versions up to, and including, 7.11.4. This makes it possible for authenticated…

  • CVE-2024-22871HigFeb 29, 2024
    risk 0.42cvss 7.5epss 0.02

    An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function.

  • CVE-2024-27284HigFeb 29, 2024
    risk 0.42cvss 7.5epss 0.01

    cassandra-rs is a Cassandra (CQL) driver for Rust. Code that attempts to use an item (e.g., a row) returned by an iterator after the iterator has advanced to the next item will be accessing freed memory and experience undefined behaviour. The problem has been fixed in version…

  • CVE-2024-26470HigFeb 29, 2024
    risk 0.53cvss 8.1epss 0.01

    A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request.

  • CVE-2024-26461HigFeb 29, 2024
    risk 0.49cvss 7.5epss 0.01

    Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.

  • CVE-2024-26131HigFeb 29, 2024
    risk 0.00cvss 8.4epss 0.00

    Element Android is an Android Matrix Client. Element Android version 1.4.3 through 1.6.10 is vulnerable to intent redirection, allowing a third-party malicious application to start any internal activity by passing some extra parameters. Possible impact includes making Element…

  • CVE-2024-25832HigFeb 29, 2024
    risk 0.61cvss 8.8epss 0.13

    F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.

  • CVE-2024-25713HigFeb 29, 2024
    risk 0.49cvss 8.6epss 0.02

    yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.)

  • CVE-2024-25262HigFeb 29, 2024
    risk 0.53cvss 8.1epss 0.01

    texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted TTF file.

  • CVE-2024-25006HigFeb 29, 2024
    risk 0.53cvss 8.1epss 0.01

    XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.

  • CVE-2024-23302HigFeb 29, 2024
    risk 0.49cvss 7.5epss 0.01

    Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.

  • CVE-2024-22939HigFeb 29, 2024
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.

  • CVE-2024-20321HigFeb 29, 2024
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because eBGP traffic is mapped…

  • CVE-2024-20267HigFeb 29, 2024
    risk 0.56cvss 8.6epss 0.01

    A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the netstack process to unexpectedly restart, which could cause the device to stop processing network traffic or to reload. This vulnerability…

  • CVE-2024-1971HigFeb 29, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in Surya2Developer Online Shopping System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file login.php of the component POST Parameter Handler. The manipulation of the argument password with the…

  • CVE-2024-1939HigFeb 29, 2024
    risk 0.57cvss 8.8epss 0.03

    Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-1938HigFeb 29, 2024
    risk 0.57cvss 8.8epss 0.01

    Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-1470HigFeb 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows allows Privilege Escalation, Code Injection.This issue only affects NetIQ Client Login Extension: 4.6.

  • CVE-2024-1317HigFeb 29, 2024
    risk 0.50cvss 8.8epss 0.01

    The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to SQL Injection via the ‘search_key’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping on the user supplied…

  • CVE-2024-1217HigFeb 29, 2024
    risk 0.42cvss 7.6epss 0.00

    The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the await_plugin_deactivation function in all versions up to, and including, 2.3.41. This makes it…

  • CVE-2024-1206HigFeb 29, 2024
    risk 0.50cvss 8.8epss 0.01

    The WP Recipe Maker plugin for WordPress is vulnerable to SQL Injection via the 'recipes' parameter in all versions up to, and including, 9.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

  • CVE-2024-0702HigFeb 29, 2024
    risk 0.47cvss 7.3epss 0.01

    The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions hooked via AJAX in the includes/class-pos-bridge-install.php file in all versions up to, and including, 2.4.2.1…

  • CVE-2023-7110HigFeb 29, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in code-projects Library Management System 2.0. This issue affects some unknown processing of the file login.php. The manipulation of the argument student leads to sql injection. The attack may be initiated…

  • CVE-2023-7109HigFeb 29, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in code-projects Library Management System 2.0. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The…

  • CVE-2023-7107HigFeb 29, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in code-projects E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file user_signup.php. The manipulation of the argument firstname/middlename/email/address/contact/username leads to sql…

  • CVE-2023-6881HigFeb 29, 2024
    risk 0.47cvss 7.3epss 0.00

    Possible buffer overflow in is_mount_point

  • CVE-2023-51779HigFeb 29, 2024
    risk 0.39cvss 7.0epss 0.00

    bt_sock_recvmsg in net/bluetooth/af_bluetooth.c in the Linux kernel through 6.6.8 has a use-after-free because of a bt_sock_ioctl race condition.

  • CVE-2023-51774HigFeb 29, 2024
    risk 0.48cvss 8.4epss 0.00

    The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be used to bypass JSON::JWT.decode.

  • CVE-2023-50658HigFeb 29, 2024
    risk 0.42cvss 7.5epss 0.01

    The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

  • CVE-2023-50437HigFeb 29, 2024
    risk 0.56cvss 8.6epss 0.01

    An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageCluster2.

  • CVE-2023-34198HigFeb 29, 2024
    risk 0.47cvss 7.3epss 0.01

    In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, and 4.7.0 before 4.7.1, the usage of a Network object created from an inactive DHCP interface in…

  • CVE-2023-25921HigFeb 29, 2024
    risk 0.55cvss 8.5epss 0.01

    IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 247620.

  • CVE-2022-34269HigFeb 29, 2024
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the Apache Axis service running on the localhost interface, leading to command execution.

  • CVE-2024-23910HigFeb 28, 2024
    risk 0.57cvss 8.8epss 0.00

    Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attacker to hijack the authentication of administrators and to perform unintended operations to the affected product. Note that WMC-X1800GST-B…

  • CVE-2024-25869HigFeb 28, 2024
    risk 0.59cvss 8.8epss 0.19

    An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a crafted php file in the settings.php component.

  • CVE-2024-25866HigFeb 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the email parameter in the index.php component.

  • CVE-2024-22983HigFeb 28, 2024
    risk 0.53cvss 8.1epss 0.01

    SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate privileges via the name parameter in the myform.php endpoint.

  • CVE-2023-49338HigFeb 28, 2024
    risk 0.49cvss 7.5epss 0.01

    Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.

  • CVE-2023-45859HigFeb 28, 2024
    risk 0.42cvss 7.6epss 0.01

    In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.

  • CVE-2023-25925HigFeb 28, 2024
    risk 0.55cvss 8.5epss 0.01

    IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 247632.

  • CVE-2024-25859HigFeb 28, 2024
    risk 0.46cvss 7.1epss 0.00

    A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbitrary code.

  • CVE-2024-24148HigFeb 28, 2024
    risk 0.49cvss 7.5epss 0.01

    A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

  • CVE-2023-52047HigFeb 28, 2024
    risk 0.57cvss 8.8epss 0.00

    Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager.

  • CVE-2024-26342HigFeb 28, 2024
    risk 0.49cvss 7.5epss 0.01

    A Null pointer dereference in usr/sbin/httpd in ASUS AC68U 3.0.0.4.384.82230 allows remote attackers to trigger DoS via network packet.

  • CVE-2024-1847HigFeb 28, 2024
    risk 0.51cvss 7.8epss 0.00

    Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Type Confusion, Uninitialized Variable, Use-After-Free vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through…

  • CVE-2024-27515HigFeb 28, 2024
    risk 0.47cvss 7.2epss 0.01

    Osclass 5.1.2 is vulnerable to SQL Injection.