VYPR

CVEs

113,483 total · page 1037 of 2,270

  • CVE-2024-24990HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC…

  • CVE-2024-24989HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC…

  • CVE-2024-24775HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

  • CVE-2024-23982HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This issue affects classification engines using signatures released between 09-08-2022 and 02-16-2023. See the…

  • CVE-2024-23979HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.00

    When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization. Note: Software versions which have reached End of…

  • CVE-2024-23805HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may occur when the HTTP Analytics profile with URLs enabled under Collected Entities is configured on a virtual server and the DB…

  • CVE-2024-23314HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

  • CVE-2024-23308HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause the BD process to terminate. The condition results from setting the Request Body Handling option in the Header-Based Content…

  • CVE-2024-23306HigFeb 14, 2024
    risk 0.46cvss 7.1epss 0.00

    A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

  • CVE-2024-22389HigFeb 14, 2024
    risk 0.47cvss 7.2epss 0.01

    When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

  • CVE-2024-22093HigFeb 14, 2024
    risk 0.57cvss 8.7epss 0.01

    When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached…

  • CVE-2024-21849HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) process to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are…

  • CVE-2024-21789HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

  • CVE-2024-21771HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    For unspecified traffic patterns, BIG-IP AFM IPS engine may spend an excessive amount of time matching the traffic against signatures, resulting in Traffic Management Microkernel (TMM) restarting and traffic disruption.  Note: Software versions which have reached End of…

  • CVE-2024-21763HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    When BIG-IP AFM Device DoS or DoS profile is configured with NXDOMAIN attack vector and bad actor detection, undisclosed queries can cause the Traffic Management Microkernel (TMM) to terminate.  NOTE: Software versions which have reached End of Technical Support (EoTS) are…

  • CVE-2024-0568HigFeb 14, 2024
    risk 0.57cvss 8.8epss 0.00

    CWE-287: Improper Authentication vulnerability exists that could cause unauthorized tampering of device configuration over NFC communication.

  • CVE-2023-6409HigFeb 14, 2024
    risk 0.50cvss 7.7epss 0.00

    CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with EcoStruxure Control Expert.

  • CVE-2023-6408HigFeb 14, 2024
    risk 0.53cvss 8.1epss 0.00

    CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle attack.

  • CVE-2023-27975HigFeb 14, 2024
    risk 0.46cvss 7.1epss 0.00

    CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering workstation.

  • CVE-2023-50868HigFeb 14, 2024
    risk 0.48cvss 7.5epss 0.82

    The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC…

  • CVE-2023-50387HigFeb 14, 2024
    risk 0.50cvss 7.5epss 1.00

    Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with…

  • CVE-2024-25213HigFeb 14, 2024
    risk 0.47cvss 7.2epss 0.01

    Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php.

  • CVE-2024-25212HigFeb 14, 2024
    risk 0.47cvss 7.2epss 0.01

    Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php.

  • CVE-2023-5123HigFeb 14, 2024
    risk 0.52cvss 8.0epss 0.01

    The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing JSON data from a remote endpoint (including a specific sub-path) configured by an…

  • CVE-2023-39941HigFeb 14, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper access control in some Intel(R) SUR software before version 2.4.10587 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

  • CVE-2023-39425HigFeb 14, 2024
    risk 0.57cvss 8.8epss 0.00

    Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-35121HigFeb 14, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-34351HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    Buffer underflow in some Intel(R) PCM software before version 202307 may allow an unauthenticated user to potentially enable denial of service via network access.

  • CVE-2023-33875HigFeb 14, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper access control for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via local access..

  • CVE-2023-25777HigFeb 14, 2024
    risk 0.51cvss 7.9epss 0.00

    Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-22342HigFeb 14, 2024
    risk 0.50cvss 7.7epss 0.00

    Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-22293HigFeb 14, 2024
    risk 0.53cvss 8.2epss 0.00

    Improper access control in the Intel(R) Thunderbolt(TM) DCH drivers for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2024-23789HigFeb 14, 2024
    risk 0.57cvss 8.8epss 0.01

    Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command on the affected product.

  • CVE-2024-23788HigFeb 14, 2024
    risk 0.53cvss 8.1epss 0.01

    Server-side request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to send an arbitrary HTTP request (GET) from the affected product.

  • CVE-2024-23783HigFeb 14, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper authentication vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to access the affected product without authentication.

  • CVE-2023-48987HigFeb 14, 2024
    risk 0.49cvss 7.5epss 0.01

    Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the pages.php component.

  • CVE-2023-44283HigFeb 14, 2024
    risk 0.51cvss 7.8epss 0.00

    In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concern has been identified, impacting locally authenticated users on their respective PCs. This issue may potentially enable privilege…

  • CVE-2023-25535HigFeb 14, 2024
    risk 0.47cvss 7.2epss 0.00

    Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has a high vulnerability that can result in local privilege escalation (LPE). This vulnerability only affects first-time installations done prior to 8th March 2023…

  • CVE-2024-24697HigFeb 14, 2024
    risk 0.47cvss 7.2epss 0.00

    Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access.

  • CVE-2024-1485HigFeb 14, 2024
    risk 0.45cvss 8.0epss 0.01

    A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup…

  • CVE-2024-25121HigFeb 13, 2024
    risk 0.39cvss 7.1epss 0.01

    TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File Abstraction Layer (FAL) could be persisted directly via `DataHandler`. This allowed attackers to reference files in the fallback storage…

  • CVE-2023-38960HigFeb 13, 2024
    risk 0.47cvss 7.3epss 0.00

    Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and execute arbitrary code via crafted executable running from the installation directory.

  • CVE-2023-20587HigFeb 13, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.

  • CVE-2021-46757HigFeb 13, 2024
    risk 0.51cvss 7.8epss 0.00

    Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space potentially leading to privilege escalation.

  • CVE-2024-25122HigFeb 13, 2024
    risk 0.39cvss 7.1epss 0.01

    sidekiq-unique-jobs is an open source project which prevents simultaneous Sidekiq jobs with the same unique arguments to run. Specially crafted GET request parameters handled by any of the following endpoints of sidekiq-unique-jobs' "admin" web UI, allow a super-user attacker,…

  • CVE-2024-24814HigFeb 13, 2024
    risk 0.00cvss 7.5epss 0.01

    mod_auth_openidc is an OpenID Certified™ authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. In affected versions missing input validation on mod_auth_openidc_session_chunks cookie value makes…

  • CVE-2024-1354HigFeb 13, 2024
    risk 0.52cvss 8.0epss 0.02

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the `syslog-ng` configuration file. Exploitation of this vulnerability required…

  • CVE-2024-21420HigFeb 13, 2024
    risk 0.57cvss 8.8epss 0.02

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2024-21412HigKEVFeb 13, 2024
    risk 0.78cvss 8.1epss 0.95

    Internet Shortcut Files Security Feature Bypass Vulnerability

  • CVE-2024-21406HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.01

    Windows Printing Service Spoofing Vulnerability