VYPR

CVEs

8,988 total · page 105 of 180

  • CVE-2024-22144CriApr 25, 2024
    risk 0.59cvss 9.0epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Eli Scheetz Anti-Malware Security and Brute-Force Firewall gotmls allows Code Injection.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a through 4.21.96.

  • CVE-2023-51484CriApr 25, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Authentication vulnerability in wp-buy Login as User or Customer (User Switching) allows Privilege Escalation.This issue affects Login as User or Customer (User Switching): from n/a through 3.8.

  • CVE-2023-51482CriApr 25, 2024
    risk 0.64cvss 9.9epss 0.00

    Improper Authentication vulnerability in EazyPlugins Eazy Plugin Manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Eazy Plugin Manager: from n/a through 4.1.2.

  • CVE-2023-51478CriApr 25, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.

  • CVE-2023-51477CriApr 24, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Authentication vulnerability in BUDDYBOSS DMCC BuddyBoss Theme allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BuddyBoss Theme: from n/a through 2.4.60.

  • CVE-2023-51472CriApr 24, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Privilege Escalation.This issue affects Checkout Mestres WP: from n/a through 7.1.9.7.

  • CVE-2023-51425CriApr 24, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Privilege Management vulnerability in Jacques Malgrange Rencontre – Dating Site allows Privilege Escalation.This issue affects Rencontre – Dating Site: from n/a through 3.10.1.

  • CVE-2023-31090CriApr 24, 2024
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates):…

  • CVE-2024-32954CriApr 24, 2024
    risk 0.59cvss 9.1epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.5.

  • CVE-2024-32836CriApr 24, 2024
    risk 0.59cvss 9.1epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay.This issue affects WP-Lister Lite for eBay: from n/a through <= 3.5.11.

  • CVE-2024-32709CriApr 24, 2024
    risk 0.68cvss 9.3epss 0.93

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5.

  • CVE-2024-32948CriApr 24, 2024
    risk 0.59cvss 9.1epss 0.00

    Missing Authorization vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.28.

  • CVE-2024-21511CriApr 23, 2024
    risk 0.57cvss 9.8epss 0.00

    Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.

  • CVE-2024-27574CriApr 22, 2024
    risk 0.59cvss 9.1epss 0.00

    SQL Injection vulnerability in Trainme Academy version Ichin v.1.3.2 allows a remote attacker to obtain sensitive information via the informacion, idcurso, and tit parameters.

  • CVE-2024-32238CriApr 22, 2024
    risk 0.71cvss 9.8epss 0.88

    H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the management system page login interface.

  • CVE-2023-47435CriApr 19, 2024
    risk 0.64cvss 9.8epss 0.00

    An issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass authentication and access password protected pages.

  • CVE-2024-30564CriApr 18, 2024
    risk 0.57cvss 9.8epss 0.04

    An issue inandrei-tatar nora-firebase-common between v.1.0.41 and v.1.12.2 allows a remote attacker to execute arbitrary code via a crafted script to the updateState parameter of the updateStateInternal method.

  • CVE-2024-2796CriApr 18, 2024
    risk 0.60cvss 9.3epss 0.00

    A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsson.

  • CVE-2024-29021CriApr 18, 2024
    risk 0.59cvss 9.0epss 0.02

    Judge0 is an open-source online code execution system. The default configuration of Judge0 leaves the service vulnerable to a sandbox escape via Server Side Request Forgery (SSRF). This allows an attacker with sufficient access to the Judge0 API to obtain unsandboxed code…

  • CVE-2024-28189CriApr 18, 2024
    risk 0.66cvss 10.0epss 0.58

    Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file within the sandbox. An attacker can abuse this by creating a symbolic link (symlink) to a file outside the sandbox, allowing the attacker to run chown on…

  • CVE-2024-28185CriApr 18, 2024
    risk 0.66cvss 10.0epss 0.65

    Judge0 is an open-source online code execution system. The application does not account for symlinks placed inside the sandbox directory, which can be leveraged by an attacker to write to arbitrary files and gain code execution outside of the sandbox. When executing a…

  • CVE-2024-32599CriApr 18, 2024
    risk 0.65cvss 10.0epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Deepak anand WP Dummy Content Generator wp-dummy-content-generator.This issue affects WP Dummy Content Generator: from n/a through <= 3.2.1.

  • CVE-2023-49742CriApr 18, 2024
    risk 0.64cvss 9.9epss 0.01

    Missing Authorization vulnerability in Support Genix.This issue affects Support Genix: from n/a through 1.2.3.

  • CVE-2024-32514CriApr 17, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.4.

  • CVE-2024-3871CriApr 16, 2024
    risk 0.64cvss 9.8epss 0.03

    The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and stack overflows vulnerabilities. Successful exploitation of these flaws would allow remote…

  • CVE-2024-2912CriApr 16, 2024
    risk 0.59cvss 10.0epss 0.07

    An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted POST request. By exploiting this vulnerability, attackers can execute arbitrary commands on the server hosting the BentoML application.…

  • CVE-2024-32128CriApr 15, 2024
    risk 0.61cvss 9.3epss 0.11

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Realtyna Realtyna Organic IDX plugin.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.4.

  • CVE-2024-3765CriApr 14, 2024
    risk 0.64cvss 9.8epss 0.00

    A vulnerability classified as critical was found in Xiongmai AHB7804R-MH-V2, AHB8004T-GL, AHB8008T-GL, AHB7004T-GS-V3, AHB7004T-MHV2, AHB8032F-LME and XM530_R80X30-PQ_8M. Affected by this vulnerability is an unknown functionality of the component Sofia Service. The manipulation…

  • CVE-2024-28878CriApr 12, 2024
    risk 0.62cvss 9.6epss 0.00

    IO-1020 Micro ELD downloads source code or an executable from an adjacent location and executes the code without sufficiently verifying the origin or integrity of the code.

  • CVE-2023-51409CriApr 12, 2024
    risk 0.72cvss 10.0epss 0.93

    Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.

  • CVE-2024-21508CriApr 11, 2024
    risk 0.60cvss 9.8epss 0.46

    Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

  • CVE-2024-25912CriApr 11, 2024
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.

  • CVE-2024-31461CriApr 10, 2024
    risk 0.52cvss 9.1epss 0.00

    Plane, an open-source project management tool, has a Server-Side Request Forgery (SSRF) vulnerability in versions prior to 0.17-dev. This issue may allow an attacker to send arbitrary requests from the server hosting the application, potentially leading to unauthorized access to…

  • CVE-2024-3098CriApr 10, 2024
    risk 0.57cvss 9.8epss 0.00

    A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the `safe_eval` function, allowing for prompt injection leading to arbitrary code execution. This issue arises due to insufficient validation of input, which can be…

  • CVE-2024-1643CriApr 10, 2024
    risk 0.52cvss 9.1epss 0.00

    By knowing an organization's ID, an attacker can join the organization without permission and gain the ability to read and modify all data within that organization. This vulnerability allows unauthorized access and modification of sensitive information, posing a significant…

  • CVE-2024-3566CriApr 10, 2024
    risk 0.65cvss 9.8epss 0.11

    A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

  • CVE-2024-23080CriApr 10, 2024
    risk 0.59cvss 9.1epss 0.00

    Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::wordBased(Locale). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a…

  • CVE-2024-3136CriApr 9, 2024
    risk 0.61cvss 9.8epss 0.54

    The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the…

  • CVE-2024-2804CriApr 9, 2024
    risk 0.64cvss 9.8epss 0.01

    The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up to, and including, 2.0.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

  • CVE-2024-1813CriApr 9, 2024
    risk 0.64cvss 9.8epss 0.08

    The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to…

  • CVE-2023-1083CriApr 9, 2024
    risk 0.64cvss 9.8epss 0.00

    An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates.

  • CVE-2024-23078CriApr 8, 2024
    risk 0.59cvss 9.1epss 0.00

    JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the…

  • CVE-2024-27488CriApr 8, 2024
    risk 0.64cvss 9.8epss 0.00

    Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate…

  • CVE-2024-31345CriApr 7, 2024
    risk 0.59cvss 9.1epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Poster: from n/a through 1.2.

  • CVE-2024-31286CriApr 7, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.

  • CVE-2024-31280CriApr 7, 2024
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.5.

  • CVE-2024-31849CriApr 5, 2024
    risk 0.71cvss 9.8epss 0.92

    A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.

  • CVE-2024-31848CriApr 5, 2024
    risk 0.71cvss 9.8epss 0.94

    A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.

  • CVE-2024-31218CriApr 5, 2024
    risk 0.57cvss 9.8epss 0.00

    Webhood is a self-hosted URL scanner used analyzing phishing and malicious sites. Webhood's backend container images in versions 0.9.0 and earlier are subject to Missing Authentication for Critical Function vulnerability. This vulnerability allows an unauthenticated attacker to…

  • CVE-2024-27448CriApr 5, 2024
    risk 0.60cvss 9.1epss 0.13

    MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to lib/mailserver.js writing arbitrary code into the routes.js file.