VYPR

CVEs

113,325 total · page 1045 of 2,267

  • CVE-2024-23863HigJan 26, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/taxstructuredisplay.php, in the description parameter.…

  • CVE-2024-23862HigJan 26, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/grndisplay.php, in the grnno parameter. Exploitation of this…

  • CVE-2024-23861HigJan 26, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/unitofmeasurementcreate.php, in the unitofmeasurementid…

  • CVE-2024-23860HigJan 26, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/currencylist.php, in the description parameter. Exploitation…

  • CVE-2024-23859HigJan 26, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/taxstructurelinecreate.php, in the flatamount parameter.…

  • CVE-2024-23858HigJan 26, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/stockissuancelinecreate.php, in the batchno parameter.…

  • CVE-2024-23857HigJan 26, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/grnlinecreate.php, in the batchno parameter. Exploitation of…

  • CVE-2024-23856HigJan 26, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/itemlist.php, in the description parameter. Exploitation of…

  • CVE-2024-0920HigJan 26, 2024
    risk 0.47cvss 7.2epss 0.09

    A vulnerability was found in TRENDnet TEW-822DRE 1.03B02. It has been declared as critical. This vulnerability affects unknown code of the file /admin_ping.htm of the component POST Request Handler. The manipulation of the argument ipv4_ping/ipv6_ping leads to command injection.…

  • CVE-2024-0919HigJan 26, 2024
    risk 0.59cvss 8.8epss 0.23

    A vulnerability was found in TRENDnet TEW-815DAP 1.0.2.0. It has been classified as critical. This affects the function do_setNTP of the component POST Request Handler. The manipulation of the argument NtpDstStart/NtpDstEnd leads to command injection. It is possible to initiate…

  • CVE-2024-0918HigJan 26, 2024
    risk 0.49cvss 7.2epss 0.25

    A vulnerability was found in TRENDnet TEW-800MB 1.0.1.0 and classified as critical. Affected by this issue is some unknown functionality of the component POST Request Handler. The manipulation of the argument DeviceURL leads to os command injection. The attack may be launched…

  • CVE-2022-48622HigJan 26, 2024
    risk 0.51cvss 7.8epss 0.00

    In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk in io-ani.c) when parsing chunks in a crafted .ani file. A crafted file could allow an attacker to overwrite heap metadata, leading…

  • CVE-2024-22545HigJan 26, 2024
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary code via the system.ntp.server parameter in the sub_420AE0() function. The attack can be launched remotely.

  • CVE-2023-6919HigJan 26, 2024
    risk 0.49cvss 7.5epss 0.01

    Path Traversal: '/../filedir' vulnerability in Biges Safe Life Technologies Electronics Inc. VGuard allows Absolute Path Traversal. This issue affects VGuard: before V500.0003.R008.4011.C0012.B351.C.

  • CVE-2024-21385HigJan 26, 2024
    risk 0.54cvss 8.3epss 0.01

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2024-23620HigJan 26, 2024
    risk 0.57cvss 8.8epss 0.00

    An improper privilege management vulnerability exists in IBM Merge Healthcare eFilm Workstation. A local, authenticated attacker can exploit this vulnerability to escalate privileges to SYSTEM.

  • CVE-2024-21620HigJan 25, 2024
    risk 0.57cvss 8.8epss 0.01

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series allows an attacker to construct a URL that when visited by another user enables the attacker to execute…

  • CVE-2023-51833HigJan 25, 2024
    risk 0.53cvss 8.1epss 0.04

    A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in the debug.cgi page.

  • CVE-2024-24399HigJan 25, 2024
    risk 0.48cvss 7.2epss 0.16

    An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the backend/languages/index.php languages area.

  • CVE-2024-22636HigJan 25, 2024
    risk 0.57cvss 8.8epss 0.01

    PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited via injecting a crafted payload into the Content field.

  • CVE-2023-52251HigJan 25, 2024
    risk 0.67cvss 8.8epss 0.85

    An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages.

  • CVE-2024-23817HigJan 25, 2024
    risk 0.46cvss 7.1epss 0.01

    Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vulnerability in the Home page of the Dolibarr Application. This vulnerability allows an attacker to inject arbitrary HTML tags and…

  • CVE-2024-23656HigJan 25, 2024
    risk 0.42cvss 7.5epss 0.00

    Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1. `cmd/dex/serve.go` line 425 seemingly sets TLS 1.2 as minimum version, but the whole `tlsConfig` is ignored after `TLS cert…

  • CVE-2024-23655HigJan 25, 2024
    risk 0.49cvss 7.5epss 0.01

    Tuta is an encrypted email service. Starting in version 3.118.12 and prior to version 3.119.10, an attacker is able to send a manipulated email so that the user can no longer use the app to get access to received emails. By sending a manipulated email, an attacker could put the…

  • CVE-2023-52356HigJan 25, 2024
    risk 0.49cvss 7.5epss 0.02

    A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.

  • CVE-2023-52355HigJan 25, 2024
    risk 0.42cvss 7.5epss 0.02

    An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

  • CVE-2023-6267HigJan 25, 2024
    risk 0.56cvss 8.6epss 0.01

    A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource may consume is being processed (deserialized) prior to the security constraints being evaluated and applied. This does not happen with…

  • CVE-2024-22749HigJan 25, 2024
    risk 0.51cvss 7.8epss 0.01

    GPAC v2.3 was detected to contain a buffer overflow via the function gf_isom_new_generic_sample_description function in the isomedia/isom_write.c:4577

  • CVE-2024-0822HigJan 25, 2024
    risk 0.00cvss 7.5epss 0.01

    An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in the CreateUserSession command.

  • CVE-2023-52076HigJan 25, 2024
    risk 0.00cvss 8.5epss 0.01

    Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the…

  • CVE-2023-40547HigJan 25, 2024
    risk 0.54cvss 8.3epss 0.05

    A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write…

  • CVE-2023-3181HigJan 25, 2024
    risk 0.51cvss 7.8epss 0.00

    The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~nsu.tmp and copies itself to it as Au_.exe. The C:\Windows\Temp~nsu.tmp\Au_.exe file is automatically launched as SYSTEM when the system reboots or when a…

  • CVE-2024-22432HigJan 25, 2024
    risk 0.51cvss 7.8epss 0.00

    Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has low privilege access to Networker Client system could potentially exploit this vulnerability, leading to the…

  • CVE-2024-23855HigJan 25, 2024
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting (XSS) vulnerability via /cupseasylive/taxcodemodify.php, in multiple parameters. Exploitation of…

  • CVE-2024-23985HigJan 25, 2024
    risk 0.52cvss 7.5epss 0.04

    EzServer 6.4.017 allows a denial of service (daemon crash) via a long string, such as one for the RNTO command.

  • CVE-2023-24676HigJan 24, 2024
    risk 0.47cvss 7.2epss 0.01

    An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the download_zip_url parameter when installing a new module. NOTE: this is disputed because exploitation requires that the attacker is able to enter requests as an…

  • CVE-2024-23646HigJan 24, 2024
    risk 0.50cvss 8.8epss 0.01

    Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The application allows users to create zip files from available files on the site. In the 1.x branch prior to version 1.3.2, parameter `selectedIds` is susceptible to SQL Injection. Any backend user…

  • CVE-2021-42146HigJan 24, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow remote attackers to reuse the same epoch number within two times the TCP maximum segment lifetime, which is prohibited in RFC6347. This vulnerability allows remote attackers to…

  • CVE-2021-42145HigJan 24, 2024
    risk 0.49cvss 7.5epss 0.00

    An assertion failure discovered in in check_certificate_request() in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers to cause a denial of service.

  • CVE-2024-23904HigJan 24, 2024
    risk 0.49cvss 7.5epss 0.01

    Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to read content from arbitrary files on the Jenkins…

  • CVE-2024-23898HigJan 24, 2024
    risk 0.56cvss 8.8epss 0.67

    Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, resulting in a cross-site WebSocket hijacking (CSWSH) vulnerability, allowing attackers to execute…

  • CVE-2024-23649HigJan 24, 2024
    risk 0.42cvss 7.5epss 0.01

    Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users can report private messages, even when they're neither sender nor recipient of the message. The API response to creating a private message report contains the…

  • CVE-2024-23648HigJan 24, 2024
    risk 0.50cvss 8.8epss 0.01

    Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to the the user requesting a password change an email containing an URL to reset its password. The URL sent contains a unique token, valid during 24 hours,…

  • CVE-2023-51890HigJan 24, 2024
    risk 0.49cvss 7.5epss 0.01

    An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume CPU resources via crafted string in the application URL.

  • CVE-2023-51888HigJan 24, 2024
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in the nomath() function in Mathtex v.1.05 and before allows a remote attacker to cause a denial of service via a crafted string in the application URL.

  • CVE-2024-23641HigJan 24, 2024
    risk 0.42cvss 7.5epss 0.01

    SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and previewed/hosted sveltekit app throws `Request with GET/HEAD method cannot have body.` and crashes the preview/hosting. After this happens, one must manually restart the…

  • CVE-2023-51886HigJan 24, 2024
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a denial of service when using \convertpath.

  • CVE-2024-22154HigJan 24, 2024
    risk 0.49cvss 7.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15.

  • CVE-2023-50943HigJan 24, 2024
    risk 0.42cvss 7.5epss 0.01

    Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attacker to poison the XCom data by bypassing the protection of "enable_xcom_pickling=False" configuration setting resulting in poisoned data after XCom deserialization. This vulnerability is…

  • CVE-2024-22309HigJan 24, 2024
    risk 0.57cvss 8.7epss 0.01

    Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from n/a through 5.1.0.