VYPR

CVEs

113,477 total · page 1040 of 2,270

  • CVE-2024-24796HigFeb 12, 2024
    risk 0.53cvss 8.2epss 0.01

    Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin.This issue affects Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin: from n/a…

  • CVE-2024-23513HigFeb 12, 2024
    risk 0.57cvss 8.7epss 0.01

    Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5.

  • CVE-2024-24933HigFeb 12, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prasidhda Malla Honeypot for WP Comment allows Reflected XSS.This issue affects Honeypot for WP Comment: from n/a through 2.2.3.

  • CVE-2024-24932HigFeb 12, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Djo VK Poster Group allows Reflected XSS.This issue affects VK Poster Group: from n/a through 2.0.3.

  • CVE-2024-24927HigFeb 12, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme allows Reflected XSS.This issue affects Brooklyn | Creative Multi-Purpose Responsive WordPress Theme:…

  • CVE-2024-25744HigFeb 12, 2024
    risk 0.00cvss 8.8epss 0.00

    In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tdx/tdx.c and arch/x86/mm/mem_encrypt_amd.c.

  • CVE-2024-25728HigFeb 11, 2024
    risk 0.49cvss 7.5epss 0.01

    ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configuration (e.g., sends them to DNS servers operated by the user's ISP instead of to the ExpressVPN DNS servers), which may allow remote attackers to obtain…

  • CVE-2024-25419HigFeb 11, 2024
    risk 0.57cvss 8.8epss 0.00

    flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_menu.php.

  • CVE-2024-25418HigFeb 11, 2024
    risk 0.57cvss 8.8epss 0.00

    flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_menu.php.

  • CVE-2024-25417HigFeb 11, 2024
    risk 0.57cvss 8.8epss 0.00

    flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_translation.php.

  • CVE-2023-52428HigFeb 11, 2024
    risk 0.49cvss 7.5epss 0.01

    In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration count) for the PasswordBasedDecrypter (PBKDF2) component.

  • CVE-2023-52427HigFeb 11, 2024
    risk 0.49cvss 7.5epss 0.01

    In OpenDDS through 3.27, there is a segmentation fault for a DataWriter with a large value of resource_limits.max_samples. NOTE: the vendor's position is that the product is not designed to handle a max_samples value that is too large for the amount of memory on the system.

  • CVE-2023-50957HigFeb 10, 2024
    risk 0.52cvss 8.0epss 0.00

    IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtaining encrypted data from clear text key storage. IBM X-Force ID: 275783.

  • CVE-2023-51488HigFeb 10, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more allows Reflected XSS.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11.

  • CVE-2024-0594HigFeb 10, 2024
    risk 0.57cvss 8.8epss 0.01

    The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due to insufficient escaping on the user supplied parameter…

  • CVE-2024-21490HigFeb 10, 2024
    risk 0.49cvss 7.5epss 0.02

    This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can…

  • CVE-2024-23327HigFeb 9, 2024
    risk 0.00cvss 7.5epss 0.01

    Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, the Envoy instance will segfault when attempting to craft the upstream PPv2 header. This occurs when the downstream request has a command type of LOCAL and does…

  • CVE-2024-23325HigFeb 9, 2024
    risk 0.00cvss 7.5epss 0.01

    Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible to crashing on a host with IPv6 disabled and a listener config with proxy protocol enabled when it receives a…

  • CVE-2024-23324HigFeb 9, 2024
    risk 0.00cvss 8.6epss 0.01

    Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can force invalid gRPC requests to be sent to ext_authz, circumventing ext_authz checks when failure_mode_allow is set to true. This issue…

  • CVE-2024-23322HigFeb 9, 2024
    risk 0.00cvss 7.5epss 0.01

    Envoy is a high-performance edge/middle/service proxy. Envoy will crash when certain timeouts happen within the same interval. The crash occurs when the following are true: 1. hedge_on_per_try_timeout is enabled, 2. per_try_idle_timeout is enabled (it can only be done in…

  • CVE-2023-50386HigFeb 9, 2024
    risk 0.60cvss 8.8epss 0.84

    Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. In…

  • CVE-2023-50298HigFeb 9, 2024
    risk 0.42cvss 7.5epss 0.02

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. Solr Streaming Expressions allows users to extract data from other Solr Clouds, using a "zkHost"…

  • CVE-2023-50292HigFeb 9, 2024
    risk 0.42cvss 7.5epss 0.03

    Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This issue affects Apache Solr: from 8.10.0 through 8.11.2, from 9.0.0 before 9.3.0. The Schema Designer was introduced to allow users to…

  • CVE-2023-50291HigFeb 9, 2024
    risk 0.42cvss 7.5epss 0.03

    Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.0. One of the two endpoints that publishes the Solr process' Java system properties, /admin/info/properties, was only setup to…

  • CVE-2024-25450HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts().

  • CVE-2024-25448HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.

  • CVE-2024-25447HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.

  • CVE-2024-25446HigFeb 9, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.

  • CVE-2024-25445HigFeb 9, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure.

  • CVE-2024-25443HigFeb 9, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue in the HuginBase::ImageVariable::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-use-after-free via parsing a crafted image.

  • CVE-2024-25442HigFeb 9, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.

  • CVE-2024-25318HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'pid' parameter in Hotel/admin/print.php?pid=2.

  • CVE-2024-25310HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5."

  • CVE-2024-25313HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/teacher_login.php.

  • CVE-2024-25312HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?id=5."

  • CVE-2024-25309HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.php.

  • CVE-2024-25308HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php.

  • CVE-2024-25306HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php".

  • CVE-2024-25305HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/index.php.

  • CVE-2024-25304HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php."

  • CVE-2023-6724HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in Software Engineering Consultancy Machine Equipment Limited Company Hearing Tracking System allows Authentication Abuse. This issue affects Hearing Tracking System: before for IOS 7.0, for Android Latest release…

  • CVE-2024-25677HigFeb 9, 2024
    risk 0.57cvss 8.8epss 0.01

    In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resources. For example, a local file may request other local files through an XML document.

  • CVE-2024-23749HigFeb 9, 2024
    risk 0.54cvss 7.8epss 0.05

    KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and validation, failure to escape special characters, and insecure system calls (at lines 2369-2390). This allows an attacker to add…

  • CVE-2024-25004HigFeb 9, 2024
    risk 0.54cvss 7.8epss 0.02

    KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds checking and input sanitization (at line 2600). This allows an attacker to overwrite adjacent memory, which leads to arbitrary code execution.

  • CVE-2024-25003HigFeb 9, 2024
    risk 0.54cvss 7.8epss 0.02

    KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insufficient bounds checking and input sanitization. This allows an attacker to overwrite adjacent memory, which leads to arbitrary code execution.

  • CVE-2024-0229HigFeb 9, 2024
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash, local privilege escalation (if the server runs with…

  • CVE-2024-0842HigFeb 9, 2024
    risk 0.42cvss 7.5epss 0.01

    The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.6. This is due to direct access of the backuply/restore_ins.php file and. This makes it possible for unauthenticated attackers to…

  • CVE-2023-51761HigFeb 9, 2024
    risk 0.54cvss 8.3epss 0.01

    In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities.

  • CVE-2023-45191HigFeb 9, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 268755.

  • CVE-2024-24821HigFeb 9, 2024
    risk 0.50cvss 8.8epss 0.00

    Composer is a dependency Manager for the PHP language. In affected versions several files within the local working directory are included during the invocation of Composer and in the context of the executing user. As such, under certain conditions arbitrary code execution may…