VYPR

CVEs

113,253 total · page 1048 of 2,266

  • CVE-2024-22191HigJan 16, 2024
    risk 0.41cvss 7.3epss 0.01

    Avo is a framework to create admin panels for Ruby on Rails apps. A stored cross-site scripting (XSS) vulnerability was found in the key_value field of Avo v3.2.3 and v2.46.0. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the victim's…

  • CVE-2024-20952HigJan 16, 2024
    risk 0.48cvss 7.4epss 0.01

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1; Oracle GraalVM for JDK: 17.0.9,…

  • CVE-2024-20932HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 17.0.9; Oracle GraalVM for JDK: 17.0.9; Oracle GraalVM Enterprise Edition:…

  • CVE-2024-20924HigJan 16, 2024
    risk 0.49cvss 7.6epss 0.00

    Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and…

  • CVE-2024-20918HigJan 16, 2024
    risk 0.48cvss 7.4epss 0.01

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u391, 8u391-perf, 11.0.21, 17.0.9, 21.0.1; Oracle GraalVM for JDK: 17.0.9,…

  • CVE-2024-20916HigJan 16, 2024
    risk 0.54cvss 8.3epss 0.00

    Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows high privileged attacker with access to the physical…

  • CVE-2024-0603HigJan 16, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of the argument mylike leads to deserialization. It is possible to initiate the attack remotely. The…

  • CVE-2024-0519HigKEVJan 16, 2024
    risk 0.70cvss 8.8epss 0.04

    Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-0518HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-0517HigJan 16, 2024
    risk 0.59cvss 8.8epss 0.22

    Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-21901HigJan 16, 2024
    risk 0.48cvss 7.4epss 0.00

    Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.7, 8.0.8, 8.0.9, 8.1.0, 8.1.1 and 8.1.2. Easily exploitable…

  • CVE-2023-6336HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.00

    Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.

  • CVE-2023-5097HigJan 16, 2024
    risk 0.46cvss 7.0epss 0.00

    Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7.

  • CVE-2024-0200HigJan 16, 2024
    risk 0.53cvss 7.2epss 0.72

    An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-controlled methods and remote code execution. To exploit this bug, an actor would need to be logged…

  • CVE-2024-23347HigJan 16, 2024
    risk 0.51cvss 7.8epss 0.00

    Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.

  • CVE-2024-22628HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.01

    Budget and Expense Tracker System v1.0 is vulnerable to SQL Injection via /expense_budget/admin/?page=reports/budget&date_start=2023-12-28&date_end=

  • CVE-2024-22627HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.01

    Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_distributor.php?id=.

  • CVE-2024-22626HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.01

    Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_retailer.php?id=.

  • CVE-2024-22625HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.01

    Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_category.php?id=.

  • CVE-2023-22514HigJan 16, 2024
    risk 0.51cvss 7.8epss 0.00

    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.8, and a CVSS Vector of:…

  • CVE-2023-22512HigJan 16, 2024
    risk 0.50cvss 7.5epss 0.14

    This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, this vulnerability allows an unauthenticated attacker to cause a resource to be unavailable for its intended users by…

  • CVE-2024-0578HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument File leads to stack-based buffer overflow. It is possible to launch…

  • CVE-2024-0577HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument lang leads to stack-based buffer overflow. The attack may be…

  • CVE-2024-0576HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been declared as critical. This vulnerability affects the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument sPort leads to stack-based buffer overflow. The…

  • CVE-2023-6373HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.00

    The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting the query, leading to a SQLI exploitable by editors and above. Note: Due to the lack of CSRF check, the issue could also be exploited via a CSRF against a logged…

  • CVE-2023-5922HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.01

    The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via an AJAX action (and REST endpoint, currently disabled in the plugin) have the right to do so, allowing unauthenticated users to access arbitrary draft, private…

  • CVE-2023-4797HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.01

    The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.

  • CVE-2023-4703HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.01

    The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to update the details of any user. Updating the password of an Admin user leads to privilege escalation.

  • CVE-2023-4536HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber to upload arbitrary files to the server, leading to RCE

  • CVE-2023-45235HigJan 16, 2024
    risk 0.54cvss 8.3epss 0.01

    EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of…

  • CVE-2023-45234HigJan 16, 2024
    risk 0.54cvss 8.3epss 0.01

    EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality,…

  • CVE-2023-45233HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.02

    EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

  • CVE-2023-45232HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.02

    EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability.

  • CVE-2023-45230HigJan 16, 2024
    risk 0.54cvss 8.3epss 0.01

    EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or…

  • CVE-2023-2655HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.01

    The Contact Form by WD WordPress plugin through 1.13.23 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

  • CVE-2023-1405HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.01

    The Formidable Forms WordPress plugin before 6.2 unserializes user input, which could allow anonymous users to perform PHP Object Injection when a suitable gadget is present.

  • CVE-2022-3899HigJan 16, 2024
    risk 0.53cvss 8.1epss 0.00

    The 3dprint WordPress plugin before 3.5.6.9 does not protect against CSRF attacks in the modified version of Tiny File Manager included with the plugin, allowing an attacker to craft a malicious request that will delete any number of files or directories on the target server by…

  • CVE-2022-3764HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.01

    The plugin does not filter the "delete_entries" parameter from user requests, leading to an SQL Injection vulnerability.

  • CVE-2022-3604HigJan 16, 2024
    risk 0.51cvss 7.8epss 0.00

    The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.

  • CVE-2022-1538HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.01

    Theme Demo Import WordPress plugin before 1.1.1 does not validate the imported file, allowing high-privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed.

  • CVE-2021-24869HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    The WP Fastest Cache WordPress plugin before 0.9.5 does not escape user input in the set_urls_with_terms method before using it in a SQL statement, leading to an SQL injection exploitable by low privilege users such as subscriber

  • CVE-2021-24566HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.

  • CVE-2021-24151HigJan 16, 2024
    risk 0.47cvss 7.2epss 0.01

    The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings.

  • CVE-2024-0582HigJan 16, 2024
    risk 0.01cvss 7.8epss 0.13

    A memory leak flaw was found in the Linux kernel’s io_uring functionality in how a user registers a buffer ring with IORING_REGISTER_PBUF_RING, mmap() it, and then frees it. This flaw allows a local user to crash or potentially escalate their privileges on the system.

  • CVE-2024-0575HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been classified as critical. This affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument command leads to stack-based buffer overflow. It is possible to…

  • CVE-2024-0574HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this issue is the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument sTime leads to stack-based buffer overflow. The attack may…

  • CVE-2024-0573HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Totolink LR1200GB 9.1.0u.6619_B20230130 and classified as critical. Affected by this vulnerability is the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to stack-based buffer overflow. The…

  • CVE-2024-0572HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, was found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument pppoeUser leads to stack-based buffer overflow. It is possible to…

  • CVE-2024-0571HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. This issue affects the function setSmsCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument text leads to stack-based buffer overflow. The attack may be…

  • CVE-2024-0570HigJan 16, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation leads to improper access controls. The attack can be initiated remotely.…