VYPR

CVEs

113,476 total · page 1041 of 2,270

  • CVE-2023-47131HigFeb 8, 2024
    risk 0.49cvss 7.5epss 0.01

    The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.

  • CVE-2023-40263HigFeb 8, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp.

  • CVE-2023-40265HigFeb 8, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.

  • CVE-2023-27001HigFeb 8, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue discovered in Egerie Risk Manager v4.0.5 allows attackers to bypass the signature mechanism and tamper with the values inside the JWT payload resulting in privilege escalation.

  • CVE-2023-25365HigFeb 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3

  • CVE-2024-23756HigFeb 8, 2024
    risk 0.49cvss 7.5epss 0.01

    The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as uploading files to the server or deleting them.

  • CVE-2024-23660HigFeb 8, 2024
    risk 0.49cvss 7.5epss 0.01

    The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the device time is the only entropy source, leading to economic losses, as exploited in…

  • CVE-2024-1329HigFeb 8, 2024
    risk 0.43cvss 7.7epss 0.01

    HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. This vulnerability, CVE-2024-1329, is fixed in Nomad 1.7.4, 1.6.7, and 1.5.14.

  • CVE-2024-0242HigFeb 8, 2024
    risk 0.47cvss 7.3epss 0.01

    Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.

  • CVE-2024-22795HigFeb 8, 2024
    risk 0.46cvss 7.0epss 0.00

    Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Compliance Status component.

  • CVE-2024-1314higFeb 8, 2024
    risk 0.39cvss epss 0.01

    ### Impact The attachment file of an existing record can be replaced if the user has `"read"` permission on one of the parent (collection or bucket). And if the `"read"` permission is given to `"system.Everyone"` on one of the parent, then the attachment can be replaced on a…

  • CVE-2023-47020HigFeb 8, 2024
    risk 0.57cvss 8.8epss 0.00

    Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user account creation and adding the user to an administrator group. This is exploited by an undisclosed…

  • CVE-2024-24878HigFeb 8, 2024
    risk 0.39cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Almeida | Webdados Portugal CTT Tracking for WooCommerce portugal-ctt-tracking-woocommerce.This issue affects Portugal CTT Tracking for WooCommerce: from n/a through <=…

  • CVE-2024-24877HigFeb 8, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magic Hills Pty Ltd Wonder Slider Lite allows Reflected XSS.This issue affects Wonder Slider Lite: from n/a through 13.9.

  • CVE-2024-24113HigFeb 8, 2024
    risk 0.57cvss 8.8epss 0.01

    xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE.

  • CVE-2024-1150HigFeb 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1.

  • CVE-2024-1149HigFeb 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent:…

  • CVE-2024-0985HigFeb 8, 2024
    risk 0.52cvss 8.0epss 0.02

    Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, enabling safe refresh of untrusted…

  • CVE-2024-24881HigFeb 8, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc allows Reflected XSS.This issue affects WP SMS – Messaging & SMS Notification…

  • CVE-2024-24879HigFeb 8, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a through 7.5.13.

  • CVE-2023-6519HigFeb 8, 2024
    risk 0.49cvss 7.5epss 0.01

    Exposure of Data Element to Wrong Session vulnerability in Mia Technology Inc. MİA-MED allows Read Sensitive Strings Within an Executable. This issue affects MİA-MED: before 1.0.7.

  • CVE-2023-6518HigFeb 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Plaintext Storage of a Password vulnerability in Mia Technology Inc. MİA-MED allows Read Sensitive Strings Within an Executable. This issue affects MİA-MED: before 1.0.7.

  • CVE-2023-6517HigFeb 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Exposure of Sensitive Information Due to Incompatible Policies vulnerability in Mia Technology Inc. MİA-MED allows Collect Data as Provided by Users. This issue affects MİA-MED: before 1.0.7.

  • CVE-2023-6515HigFeb 8, 2024
    risk 0.57cvss 8.8epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in Mia Technology Inc. MİA-MED allows Authentication Abuse. This issue affects MİA-MED: before 1.0.7.

  • CVE-2024-23452HigFeb 8, 2024
    risk 0.00cvss 7.5epss 0.02

    Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle request. Vulnerability Cause Description: The http_parser does not comply with the RFC-7230 HTTP 1.1 specification. Attack scenario: If a message is…

  • CVE-2024-24350HigFeb 8, 2024
    risk 0.57cvss 8.8epss 0.01

    File Upload vulnerability in Software Publico e-Sic Livre v.2.0 and before allows a remote attacker to execute arbitrary code via the extension filtering component.

  • CVE-2024-24806HigFeb 7, 2024
    risk 0.00cvss 7.3epss 0.02

    libuv is a multi-platform support library with a focus on asynchronous I/O. The `uv_getaddrinfo` function in `src/unix/getaddrinfo.c` (and its windows counterpart `src/win/getaddrinfo.c`), truncates hostnames to 256 characters before calling `getaddrinfo`. This behavior can be…

  • CVE-2024-23769HigFeb 7, 2024
    risk 0.47cvss 7.3epss 0.00

    Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacker to read privileged data.

  • CVE-2024-24824HigFeb 7, 2024
    risk 0.53cvss 8.8epss 0.34

    Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the `/api/system/cluster_config/` endpoint. Graylog's cluster config system uses…

  • CVE-2024-20290HigFeb 7, 2024
    risk 0.51cvss 7.5epss 0.34

    A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may…

  • CVE-2024-20255HigFeb 7, 2024
    risk 0.53cvss 8.2epss 0.01

    A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient…

  • CVE-2023-43017HigFeb 7, 2024
    risk 0.53cvss 8.2epss 0.01

    IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: 266155.

  • CVE-2023-32330HigFeb 7, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. IBM X-Force ID: 254977.

  • CVE-2023-32328HigFeb 7, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of the server. IBM X-Force Id: 254957.

  • CVE-2024-22012HigFeb 7, 2024
    risk 0.51cvss 7.8epss 0.00

    there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-24771HigFeb 7, 2024
    risk 0.50cvss 7.7epss 0.01

    Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authentication weakness. Superusers who have their credentials (username + password) compromised could potentially have the…

  • CVE-2024-25201HigFeb 7, 2024
    risk 0.49cvss 7.5epss 0.01

    Espruino 2v20 (commit fcc9ba4) was discovered to contain an Out-of-bounds Read via jsvStringIteratorPrintfCallback at src/jsvar.c.

  • CVE-2024-25200HigFeb 7, 2024
    risk 0.49cvss 7.5epss 0.01

    Espruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse.c.

  • CVE-2024-1118HigFeb 7, 2024
    risk 0.50cvss 8.8epss 0.01

    The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute of the podlove-subscribe-button shortcode in all versions up to, and including, 1.3.10 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2023-51437HigFeb 7, 2024
    risk 0.41cvss 7.4epss 0.01

    Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge a SASL Role Token that will pass signature verification. Users are recommended to upgrade to version 2.11.3, 3.0.2, or 3.1.1 which fixes the issue. Users…

  • CVE-2024-24311HigFeb 7, 2024
    risk 0.49cvss 7.5epss 0.01

    Path Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for PrestaShop before version 1.6.6, a guest can download personal information without restriction.

  • CVE-2024-24304HigFeb 7, 2024
    risk 0.49cvss 7.5epss 0.01

    In the module "Mailjet" (mailjet) from Mailjet for PrestaShop before versions 3.5.1, a guest can download technical information without restriction.

  • CVE-2024-24810HigFeb 7, 2024
    risk 0.46cvss 8.2epss 0.00

    WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges. This impacts any installer built with the WiX installer framework.…

  • CVE-2024-22022HigFeb 7, 2024
    risk 0.57cvss 8.8epss 0.01

    Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service account used by the Veeam Orchestrator Server Service.

  • CVE-2024-24680HigFeb 6, 2024
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a potential denial-of-service attack when used with very long strings.

  • CVE-2024-24577HigFeb 6, 2024
    risk 0.56cvss 8.6epss 0.02

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_index_add` can cause heap corruption that could be leveraged for arbitrary…

  • CVE-2024-24575HigFeb 6, 2024
    risk 0.00cvss 7.5epss 0.01

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Using well-crafted inputs to `git_revparse_single` can cause the function to enter an infinite loop,…

  • CVE-2024-22520HigFeb 6, 2024
    risk 0.53cvss 8.2epss 0.01

    An issue discovered in Dronetag Drone Scanner 1.5.2 allows attackers to impersonate other drones via transmission of crafted data packets.

  • CVE-2024-22519HigFeb 6, 2024
    risk 0.53cvss 8.2epss 0.01

    An issue discovered in OpenDroneID OSM 3.5.1 allows attackers to impersonate other drones via transmission of crafted data packets.

  • CVE-2023-45735HigFeb 6, 2024
    risk 0.52cvss 8.0epss 0.01

    A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the device.