VYPR

CVEs

113,472 total · page 1044 of 2,270

  • CVE-2024-24757HigFeb 2, 2024
    risk 0.49cvss 7.6epss 0.01

    open-irs is an issue response robot that reponds to issues in the installed repository. The `.env` file was accidentally uploaded when working with git actions. This problem is fixed in 1.0.1. Discontinuing all sensitive keys and turning into secrets.

  • CVE-2024-24470HigFeb 2, 2024
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php component.

  • CVE-2024-24161HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.

  • CVE-2024-23831HigFeb 2, 2024
    risk 0.00cvss 7.5epss 0.00

    LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker can trick the admin into clicking on a link which automatically submits a request to setup.pl without the admin's consent. This…

  • CVE-2024-22107HigFeb 2, 2024
    risk 0.47cvss 7.2epss 0.03

    An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An…

  • CVE-2023-6387HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service or remote code execution

  • CVE-2023-51838HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    Ylianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm.

  • CVE-2023-47568HigFeb 2, 2024
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QTS…

  • CVE-2023-47564HigFeb 2, 2024
    risk 0.52cvss 8.0epss 0.01

    An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the…

  • CVE-2023-47562HigFeb 2, 2024
    risk 0.48cvss 7.4epss 0.01

    An OS command injection vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15…

  • CVE-2023-39297HigFeb 2, 2024
    risk 0.57cvss 8.8epss 0.01

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS…

  • CVE-2020-29504HigFeb 2, 2024
    risk 0.48cvss 7.4epss 0.00

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Missing Required Cryptographic Step Vulnerability.

  • CVE-2023-38273HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 260733.

  • CVE-2023-47142HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.00

    IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate their privileges due to unauthorized API access. IBM X-Force ID: 270267.

  • CVE-2024-0269HigFeb 2, 2024
    risk 0.54cvss 8.3epss 0.05

    ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 7271.

  • CVE-2024-0253HigFeb 2, 2024
    risk 0.54cvss 8.3epss 0.05

    ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data.

  • CVE-2023-6676HigFeb 2, 2024
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in National Keep Cyber Security Services CyberMath allows Cross Site Request Forgery. This issue affects CyberMath: from v1.4 before v1.5.

  • CVE-2024-1201HigFeb 2, 2024
    risk 0.51cvss 7.8epss 0.00

    Search path or unquoted item vulnerability in HDD Health affecting versions 4.2.0.112 and earlier. This vulnerability could allow a local attacker to store a malicious executable file within the unquoted search path, resulting in privilege escalation.

  • CVE-2024-23895HigFeb 2, 2024
    risk 0.53cvss 8.2epss 0.01

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/locationcreate.php, in the locationid parameter.…

  • CVE-2024-0338HigFeb 2, 2024
    risk 0.47cvss 7.3epss 0.00

    A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute arbitrary code through a long file debug argument that controls the Structured Exception Handler (SEH).

  • CVE-2023-39611HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in Software FX Chart FX 7 version 7.0.4962.20829 allows attackers to enumerate and read files from the local filesystem by sending crafted web requests.

  • CVE-2024-22851HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the /static/ endpoint.

  • CVE-2023-48645HigFeb 2, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in the Archibus app 4.0.3 for iOS. It uses a local database that is synchronized with a Web central server instance every time the application is opened, or when the refresh button is used. There is a SQL injection in the search work request feature in…

  • CVE-2024-24524HigFeb 2, 2024
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the add_menu.php component.

  • CVE-2020-24682HigFeb 2, 2024
    risk 0.47cvss 7.2epss 0.00

    Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation Studio: from 4.0 through 4.6, from 4.7.0 before 4.7.7 SP, from 4.8.0…

  • CVE-2024-21860HigFeb 2, 2024
    risk 0.53cvss 8.2epss 0.00

    in OpenHarmony v4.0.0 and prior versions allow an adjacent attacker arbitrary code execution in any apps through use after free.

  • CVE-2024-21780HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    Stack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted command may result in a denial of service (DoS) condition. Note that the affected products are no longer supported.

  • CVE-2021-22282HigFeb 2, 2024
    risk 0.54cvss 8.3epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from 4.0 through 4.12.

  • CVE-2020-24681HigFeb 2, 2024
    risk 0.53cvss 8.2epss 0.00

    Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from 4.7.0 before 4.7.7 SP, from 4.8.0 before 4.8.6 SP, from 4.9.0…

  • CVE-2023-46045HigFeb 2, 2024
    risk 0.51cvss 7.8epss 0.01

    Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically owned by root.

  • CVE-2023-38019HigFeb 2, 2024
    risk 0.53cvss 8.1epss 0.01

    IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 260575.

  • CVE-2024-22319HigFeb 2, 2024
    risk 0.59cvss 8.1epss 0.76

    IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 279145.

  • CVE-2024-22903HigFeb 2, 2024
    risk 0.57cvss 8.8epss 0.02

    Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.

  • CVE-2024-22900HigFeb 2, 2024
    risk 0.57cvss 8.8epss 0.02

    Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.

  • CVE-2024-22899HigFeb 2, 2024
    risk 0.57cvss 8.8epss 0.02

    Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.

  • CVE-2024-22779HigFeb 2, 2024
    risk 0.00cvss 8.8epss 0.02

    Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerPack in ServerResourcePackProviderMixin.java.

  • CVE-2024-21399HigFeb 2, 2024
    risk 0.54cvss 8.3epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2023-50326HigFeb 2, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 275107.

  • CVE-2024-22016HigFeb 2, 2024
    risk 0.51cvss 7.8epss 0.00

    In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada directory. This may allow privilege escalation.

  • CVE-2024-24756HigFeb 1, 2024
    risk 0.00cvss 7.5epss 0.01

    Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the `lib/public/` directory can be requested from the server. Instances running behind Cloudflare (including crafatar.com) are not affected. Instances using the Docker…

  • CVE-2024-21852HigFeb 1, 2024
    risk 0.57cvss 8.8epss 0.01

    In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration file by utilizing a Zip Slip vulnerability in the unpacking routine to achieve remote code execution.

  • CVE-2023-6221HigFeb 1, 2024
    risk 0.50cvss 7.7epss 0.01

    The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the programmable logic controller (PLC), PumpSense, PowerAnalyzer, FeverWarn, and others is insufficiently protected against unauthorized access. An attacker with…

  • CVE-2023-49610HigFeb 1, 2024
    risk 0.53cvss 8.1epss 0.00

    MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could overflow the stack.

  • CVE-2023-49115HigFeb 1, 2024
    risk 0.49cvss 7.5epss 0.01

    MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users.

  • CVE-2023-47867HigFeb 1, 2024
    risk 0.57cvss 8.8epss 0.00

    MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and compromise the device.

  • CVE-2023-36496HigFeb 1, 2024
    risk 0.50cvss 7.7epss 0.01

    Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.

  • CVE-2023-47257HigFeb 1, 2024
    risk 0.53cvss 8.1epss 0.01

    ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.

  • CVE-2024-24570HigFeb 1, 2024
    risk 0.46cvss 8.2epss 0.01

    Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing for XSS. This affects the front-end forms with asset fields without any mime type validation, asset fields in the control panel, and asset browser in the…

  • CVE-2023-6078HigFeb 1, 2024
    risk 0.57cvss 8.8epss 0.02

    An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution.

  • CVE-2023-51509HigFeb 1, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login allows Reflected XSS.This issue affects RegistrationMagic – Custom…