VYPR

CVEs

113,472 total · page 1042 of 2,270

  • CVE-2023-40545HigFeb 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.

  • CVE-2023-47618HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.02

    A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an…

  • CVE-2023-47617HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an…

  • CVE-2023-47209HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an…

  • CVE-2023-47167HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated…

  • CVE-2023-46683HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection . An attacker can…

  • CVE-2023-43482HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to…

  • CVE-2023-42664HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an…

  • CVE-2023-36498HigFeb 6, 2024
    risk 0.47cvss 7.2epss 0.03

    A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an…

  • CVE-2023-50395HigFeb 6, 2024
    risk 0.52cvss 8.0epss 0.02

    SQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited

  • CVE-2023-35188HigFeb 6, 2024
    risk 0.52cvss 8.0epss 0.02

    SQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited.

  • CVE-2024-24591HigFeb 6, 2024
    risk 0.52cvss 8.0epss 0.01

    A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a maliciously uploaded dataset to write local or remote files to an arbitrary location on an end user’s system when interacted with.

  • CVE-2024-24590HigFeb 6, 2024
    risk 0.52cvss 8.0epss 0.02

    Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously uploaded artifact to run arbitrary code on an end user’s system when interacted with.

  • CVE-2024-23673HigFeb 6, 2024
    risk 0.48cvss 8.5epss 0.01

    Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affects all version of Apache Sling Servlets Resolver before 2.11.0. However, whether a system is vulnerable to this attack depends on the exact configuration of…

  • CVE-2023-32451HigFeb 6, 2024
    risk 0.47cvss 7.3epss 0.00

    Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during installation and uninstallation

  • CVE-2024-22433HigFeb 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info in DP Search. A remote unauthorized unauthenticated attacker could potentially exploit this vulnerability leading to a loss of…

  • CVE-2023-25543HigFeb 6, 2024
    risk 0.51cvss 7.8epss 0.00

    Dell Power Manager, versions prior to 3.14, contain an Improper Authorization vulnerability in DPM service. A low privileged malicious user could potentially exploit this vulnerability in order to elevate privileges on the system.

  • CVE-2023-43536HigFeb 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while parse fils IE with length equal to 1.

  • CVE-2023-43535HigFeb 6, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption when negative display IDs are sent as input while processing DISPLAYESCAPE event trigger.

  • CVE-2023-43534HigFeb 6, 2024
    risk 0.56cvss 8.6epss 0.00

    Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.

  • CVE-2023-43533HigFeb 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.

  • CVE-2023-43532HigFeb 6, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption while reading ACPI config through the user mode app.

  • CVE-2023-43523HigFeb 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while processing 11AZ RTT management action frame received through OTA.

  • CVE-2023-43522HigFeb 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.

  • CVE-2023-43520HigFeb 6, 2024
    risk 0.56cvss 8.6epss 0.00

    Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE.

  • CVE-2023-43519HigFeb 6, 2024
    risk 0.47cvss 7.3epss 0.00

    Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size.

  • CVE-2023-43518HigFeb 6, 2024
    risk 0.47cvss 7.3epss 0.00

    Memory corruption in video while parsing invalid mp2 clip.

  • CVE-2023-43517HigFeb 6, 2024
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Automotive Multimedia due to improper access control in HAB.

  • CVE-2023-43516HigFeb 6, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when malformed message payload is received from firmware.

  • CVE-2023-43513HigFeb 6, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.

  • CVE-2023-33060HigFeb 6, 2024
    risk 0.46cvss 7.1epss 0.00

    Transient DOS in Core when DDR memory check is called while DDR is not initialized.

  • CVE-2023-33058HigFeb 6, 2024
    risk 0.53cvss 8.2epss 0.00

    Information disclosure in Modem while processing SIB5.

  • CVE-2023-33057HigFeb 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in Multi-Mode Call Processor while processing UE policy container.

  • CVE-2023-33049HigFeb 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.

  • CVE-2023-33046HigFeb 6, 2024
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.

  • CVE-2024-23304HigFeb 6, 2024
    risk 0.49cvss 7.5epss 0.01

    Cybozu KUNAI for Android 3.0.20 to 3.0.21 allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by performing certain operations.

  • CVE-2024-20816HigFeb 6, 2024
    risk 0.52cvss 8.0epss 0.00

    Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

  • CVE-2024-20815HigFeb 6, 2024
    risk 0.52cvss 8.0epss 0.00

    Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

  • CVE-2024-20813HigFeb 6, 2024
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2024-20812HigFeb 6, 2024
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2024-22773HigFeb 6, 2024
    risk 0.53cvss 8.1epss 0.01

    Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in Login Bypass.

  • CVE-2023-47889HigFeb 6, 2024
    risk 0.51cvss 7.8epss 0.00

    The Android application BINHDRM26 com.bdrm.superreboot 1.0.3, exposes several critical actions through its exported broadcast receivers. These exposed actions can allow any app on the device to send unauthorized broadcasts, leading to unintended consequences. The vulnerability…

  • CVE-2023-47353HigFeb 6, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue in the com.oneed.dvr.service.DownloadFirmwareService component of IMOU GO v1.0.11 allows attackers to force the download of arbitrary files.

  • CVE-2023-46360HigFeb 6, 2024
    risk 0.57cvss 8.8epss 0.03

    Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier is vulnerable to Execution with Unnecessary Privileges.

  • CVE-2023-47354HigFeb 6, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue in the PowerOffWidgetReceiver function of Super Reboot (Root) Recovery v1.0.3 allows attackers to arbitrarily reset or power off the device via a crafted intent

  • CVE-2024-1072HigFeb 5, 2024
    risk 0.46cvss 8.2epss 0.01

    The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the seedprod_lite_new_lpage function in all versions up to,…

  • CVE-2024-0869HigFeb 5, 2024
    risk 0.50cvss 8.8epss 0.01

    The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulnerable to unauthorized arbitrary options update due to an insufficient check that neglects to verify whether the updated option belongs to the plugin on the…

  • CVE-2024-0761HigFeb 5, 2024
    risk 0.46cvss 8.1epss 0.01

    The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filenames, which use a timestamp plus 4 random digits. This makes it possible for unauthenticated…

  • CVE-2024-0428HigFeb 5, 2024
    risk 0.39cvss 7.1epss 0.00

    The Index Now plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.3. This is due to missing or incorrect nonce validation on the 'reset_form' function. This makes it possible for unauthenticated attackers to delete arbitrary…

  • CVE-2024-0324HigFeb 5, 2024
    risk 0.53cvss 8.2epss 0.02

    The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wppb_two_factor_authentication_settings_update' function in all…