VYPR

CVEs

113,239 total · page 1049 of 2,265

  • CVE-2023-52113HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.

  • CVE-2023-52111HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Authorization vulnerability in the BootLoader module. Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2023-52110HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    The sensor module has an out-of-bounds access vulnerability.Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-52109HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-4566HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-44117HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-44112HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Out-of-bounds access vulnerability in the device authentication module. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2024-21674HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.02

    This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N allows an…

  • CVE-2024-21673HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.0 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H allows an…

  • CVE-2024-21672HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.3 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H allows an…

  • CVE-2023-22526HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.02

    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact…

  • CVE-2024-22428HigJan 16, 2024
    risk 0.46cvss 7.0epss 0.00

    Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may allow a local unprivileged user to escalate privileges and execute arbitrary code on the affected system. Dell recommends customers upgrade at the earliest…

  • CVE-2024-22362HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.01

    Drupal contains a vulnerability with improper handling of structural elements. If this vulnerability is exploited, an attacker may be able to cause a denial-of-service (DoS) condition.

  • CVE-2023-51282HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.

  • CVE-2023-51257HigJan 16, 2024
    risk 0.51cvss 7.8epss 0.00

    An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.

  • CVE-2023-51059HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in MOKO TECHNOLOGY LTD MOKOSmart MKGW1 BLE Gateway v.1.1.1 and before allows a remote attacker to escalate privileges via the session management component of the administrative web interface.

  • CVE-2023-43449HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in HummerRisk HummerRisk v.1.10 thru 1.4.1 allows an authenticated attacker to execute arbitrary code via a crafted request to the service/LicenseService component.

  • CVE-2023-51810HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in StackIdeas EasyDiscuss v.5.0.5 and fixed in v.5.0.10 allows a remote attacker to obtain sensitive information via a crafted request to the search parameter in the Users module.

  • CVE-2023-47460HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in Knovos Discovery v.22.67.0 allows a remote attacker to execute arbitrary code via the /DiscoveryProcess/Service/Admin.svc/getGridColumnStructure component.

  • CVE-2023-7206HigJan 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, which would result in execution of arbitrary code on affected installations of Cscape.

  • CVE-2024-0562HigJan 15, 2024
    risk 0.51cvss 7.8epss 0.00

    A use-after-free flaw was found in the Linux Kernel. When a disk is removed, bdi_unregister is called to stop further write-back and waits for associated delayed work to complete. However, wb_inode_writeback_end() may schedule bandwidth estimation work after this has completed,…

  • CVE-2023-6991HigJan 15, 2024
    risk 0.57cvss 8.8epss 0.01

    The JSM file_get_contents() Shortcode WordPress plugin before 2.7.1 does not validate one of its shortcode's parameters before making a request to it, which could allow users with contributor role and above to perform SSRF attacks.

  • CVE-2023-6620HigJan 15, 2024
    risk 0.48cvss 7.2epss 0.14

    The POST SMTP Mailer WordPress plugin before 2.8.7 does not properly sanitise and escape several parameters before using them in SQL statements, leading to a SQL injection exploitable by high privilege users such as admin.

  • CVE-2023-6029HigJan 15, 2024
    risk 0.49cvss 7.5epss 0.00

    The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.

  • CVE-2023-5905HigJan 15, 2024
    risk 0.53cvss 8.1epss 0.01

    The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged in user, such as subscribers to export the contents of the blog, including restricted and unpublished…

  • CVE-2023-50729HigJan 15, 2024
    risk 0.55cvss 8.4epss 0.01

    Traccar is an open source GPS tracking system. Prior to 5.11, Traccar is affected by an unrestricted file upload vulnerability in File feature allows attackers to execute arbitrary code on the server. This vulnerability is more prevalent because Traccar is recommended to run web…

  • CVE-2023-4818HigJan 15, 2024
    risk 0.49cvss 7.6epss 0.01

    PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by PAX can be used.  The attacker must have physical USB access to the device in order to exploit this vulnerability.

  • CVE-2023-42137HigJan 15, 2024
    risk 0.51cvss 7.8epss 0.00

    PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow for command execution with high privileges by using malicious symlinks. The attacker must have shell access to the device in order to exploit this vulnerability.

  • CVE-2023-42136HigJan 15, 2024
    risk 0.51cvss 7.8epss 0.00

    PAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands with system account privilege by shell injection starting with a specific word. The attacker must have shell access to the device in order…

  • CVE-2024-0542HigJan 15, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been rated as critical. Affected by this issue is the function formWifiMacFilterGet of the component httpd. The manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched…

  • CVE-2024-0541HigJan 15, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been declared as critical. Affected by this vulnerability is the function formAddSysLogRule of the component httpd. The manipulation of the argument sysRulenEn leads to stack-based buffer overflow. The attack can be…

  • CVE-2024-0539HigJan 15, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda W9 1.0.0.7(4456) and classified as critical. This issue affects the function formQosManage_user of the component httpd. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack may be initiated remotely. The…

  • CVE-2024-0538HigJan 15, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in Tenda W9 1.0.0.7(4456) and classified as critical. This vulnerability affects the function formQosManage_auto of the component httpd. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack can be initiated…

  • CVE-2024-0537HigJan 15, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, was found in Tenda W9 1.0.0.7(4456). This affects the function setWrlBasicInfo of the component httpd. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. It is possible to initiate the attack…

  • CVE-2024-0536HigJan 15, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, has been found in Tenda W9 1.0.0.7(4456). Affected by this issue is the function setWrlAccessList of the component httpd. The manipulation of the argument ssidIndex leads to stack-based buffer overflow. The attack may be…

  • CVE-2024-0535HigJan 15, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical was found in Tenda PA6 1.0.1.21. Affected by this vulnerability is the function cgiPortMapAdd of the file /portmap of the component httpd. The manipulation of the argument groupName leads to stack-based buffer overflow. The attack can be…

  • CVE-2024-0534HigJan 15, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability classified as critical has been found in Tenda A15 15.13.07.13. Affected is an unknown function of the file /goform/SetOnlineDevName of the component Web-based Management Interface. The manipulation of the argument mac leads to stack-based buffer overflow. It is…

  • CVE-2024-0533HigJan 15, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability was found in Tenda A15 15.13.07.13. It has been rated as critical. This issue affects some unknown processing of the file /goform/SetOnlineDevName of the component Web-based Management Interface. The manipulation of the argument devName leads to stack-based…

  • CVE-2023-48383HigJan 15, 2024
    risk 0.49cvss 7.5epss 0.01

    NetVision Information airPASS has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.

  • CVE-2024-0532HigJan 15, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability was found in Tenda A15 15.13.07.13. It has been declared as critical. This vulnerability affects the function set_repeat5 of the file /goform/WifiExtraSet of the component Web-based Management Interface. The manipulation of the argument…

  • CVE-2024-0531HigJan 15, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability was found in Tenda A15 15.13.07.13. It has been classified as critical. This affects an unknown part of the file /goform/setBlackRule of the component Web-based Management Interface. The manipulation of the argument deviceList leads to stack-based buffer…

  • CVE-2024-0510HigJan 13, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in HaoKeKeJi YiQiNiu up to 3.1. Affected by this issue is the function http_post of the file /application/pay/controller/Api.php. The manipulation of the argument url leads to server-side request forgery. The…

  • CVE-2024-0480HigJan 13, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Taokeyun up to 1.0.5. It has been declared as critical. Affected by this vulnerability is the function index of the file application/index/controller/m/Drs.php of the component HTTP POST Request Handler. The manipulation of the argument cid leads to…

  • CVE-2024-0479HigJan 13, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Taokeyun up to 1.0.5. It has been classified as critical. Affected is the function login of the file application/index/controller/m/User.php of the component HTTP POST Request Handler. The manipulation of the argument username leads to sql injection.…

  • CVE-2023-52289HigJan 13, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST request to a /update-resource-data/<file_path> URI (from views.py), allows attackers to write to arbitrary files.

  • CVE-2023-52288HigJan 13, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a GET request to a /resource-data/<file_path>.txt URI (from views.py), allows attackers to read arbitrary files.

  • CVE-2023-51070HigJan 13, 2024
    risk 0.49cvss 7.5epss 0.01

    An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server.

  • CVE-2023-51066HigJan 13, 2024
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.

  • CVE-2023-51065HigJan 13, 2024
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from the QStar Server.

  • CVE-2023-51063HigJan 13, 2024
    risk 0.57cvss 8.8epss 0.00

    QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability within the component qnme-ajax?method=tree_level.