VYPR

CVEs

112,927 total · page 1054 of 2,259

  • CVE-2023-49002HigDec 27, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in Xenom Technologies (sinous) Phone Dialer-voice Call Dialer v.1.2.5 allows an attacker to bypass intended access restrictions via interaction with com.funprime.calldialer.ui.activities.OutgoingActivity.

  • CVE-2023-51080HigDec 27, 2023
    risk 0.42cvss 7.5epss 0.01

    The NumberUtil.toBigDecimal method in hutool-core v5.8.23 was discovered to contain a stack overflow.

  • CVE-2023-51075HigDec 27, 2023
    risk 0.42cvss 7.5epss 0.01

    hutool-core v5.8.23 was discovered to contain an infinite loop in the StrSplitter.splitByRegex function. This vulnerability allows attackers to cause a Denial of Service (DoS) via manipulation of the first two parameters.

  • CVE-2023-47882HigDec 27, 2023
    risk 0.46cvss 7.1epss 0.00

    The Kami Vision YI IoT com.yunyi.smartcamera application through 4.1.9_20231127 for Android allows a remote attacker to execute arbitrary JavaScript code via an implicit intent to the com.ants360.yicamera.activity.WebViewActivity component.

  • CVE-2023-52075HigDec 27, 2023
    risk 0.49cvss 7.5epss 0.01

    ReVanced API proxies requests needed to feed the ReVanced Manager and website with data. Up to and including commit 71f81f7f20cd26fd707335bca9838fa3e7df20d2, ReVanced API lacks error caching causing rate limit to be triggered thus increasing server load. This causes a denial of…

  • CVE-2023-40038HigDec 27, 2023
    risk 0.57cvss 8.8epss 0.00

    Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They use the first 6 characters of the SSID and the last 6 characters of the BSSID, decrementing the last digit.)

  • CVE-2023-52077HigDec 27, 2023
    risk 0.00cvss 8.9epss 0.01

    Nexkey is a lightweight fork of Misskey v12 optimized for small to medium size servers. Prior to 12.23Q4.5, Nexkey allows external apps using tokens issued by administrators and moderators to call admin APIs. This allows malicious third-party apps to perform operations such as…

  • CVE-2023-51664HigDec 27, 2023
    risk 0.41cvss 7.3epss 0.03

    tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. This issue…

  • CVE-2023-51443HigDec 27, 2023
    risk 0.00cvss 7.5epss 0.01

    FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.11, when handling DTLS-SRTP for media setup, FreeSWITCH is susceptible to…

  • CVE-2023-3171HigDec 27, 2023
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in EAP-7 during deserialization of certain classes, which permits instantiation of HashMap and HashTable with no checks on resources consumed. This issue could allow an attacker to submit malicious requests using these classes, which could eventually exhaust the…

  • CVE-2023-52096HigDec 26, 2023
    risk 0.49cvss 7.5epss 0.01

    SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (such as when an application receives a StartTransaction Open Charge Point Protocol message with a timestamp parameter of 1000000). This may lead to a SQL…

  • CVE-2023-6250HigDec 26, 2023
    risk 0.49cvss 7.5epss 0.00

    The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag

  • CVE-2023-6114HigDec 26, 2023
    risk 0.51cvss 7.5epss 0.31

    The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2 does not disallow listing the `backups-dup-lite/tmp` directory (or the `backups-dup-pro/tmp` directory in the Pro version), which temporarily stores files containing sensitive data.…

  • CVE-2023-5939HigDec 26, 2023
    risk 0.47cvss 7.2epss 0.01

    The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file in an unsafe manner, leading to remote code execution by privileged users.

  • CVE-2023-5931HigDec 26, 2023
    risk 0.57cvss 8.8epss 0.01

    The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary files such as PHP on the server

  • CVE-2023-5674HigDec 26, 2023
    risk 0.58cvss 8.8epss 0.11

    The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.

  • CVE-2023-5673HigDec 26, 2023
    risk 0.57cvss 8.8epss 0.01

    The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to emails, allowing attackers to upload PHP files, leading to remote code execution.

  • CVE-2023-5645HigDec 26, 2023
    risk 0.57cvss 8.8epss 0.01

    The WP Mail Log WordPress plugin before 1.1.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as Contributor.

  • CVE-2023-5644HigDec 26, 2023
    risk 0.49cvss 7.6epss 0.01

    The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints, allowing users with the Contributor role to view and delete data that should only be accessible to Admin users.

  • CVE-2023-5203HigDec 26, 2023
    risk 0.49cvss 7.5epss 0.02

    The WP Sessions Time Monitoring Full Automatic WordPress plugin before 1.0.9 does not sanitize the request URL or query parameters before using them in an SQL query, allowing unauthenticated attackers to extract sensitive data from the database via blind time based SQL injection…

  • CVE-2023-52086HigDec 26, 2023
    risk 0.00cvss 8.1epss 0.01

    resumable.php (aka PHP backend for resumable.js) 0.1.4 before 3c6dbf5 allows arbitrary file upload anywhere in the filesystem via ../ in multipart/form-data content to upload.php. (File overwrite hasn't been possible with the code available in GitHub in recent years, however.)

  • CVE-2023-51107HigDec 26, 2023
    risk 0.49cvss 7.5epss 0.01

    A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in functon compute_color() of jquant2.c. NOTE: this is disputed by the supplier because there was not reasonable evidence to determine the existence of a vulnerability or identify…

  • CVE-2023-51106HigDec 26, 2023
    risk 0.49cvss 7.5epss 0.01

    A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function pnm_binary_read_image() of load-pnm.c when fz_colorspace_n returns zero.

  • CVE-2023-51105HigDec 26, 2023
    risk 0.49cvss 7.5epss 0.01

    A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompress_rle4() of load-bmp.c.

  • CVE-2023-51104HigDec 26, 2023
    risk 0.49cvss 7.5epss 0.01

    A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_read_image() of load-pnm.c when span equals zero.

  • CVE-2023-51103HigDec 26, 2023
    risk 0.49cvss 7.5epss 0.01

    A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in the function fz_new_pixmap_from_float_data() of pixmap.c.

  • CVE-2023-49949HigDec 26, 2023
    risk 0.53cvss 8.1epss 0.01

    Passwork before 6.2.0 allows remote authenticated users to bypass 2FA by sending all one million of the possible 6-digit codes.

  • CVE-2023-50968HigDec 26, 2023
    risk 0.54cvss 7.5epss 0.63

    Arbitrary file properties reading vulnerability in Apache Software Foundation Apache OFBiz when user operates an uri call without authorizations. The same uri can be operated to realize a SSRF attack also without authorizations. Users are recommended to upgrade to version…

  • CVE-2023-5180HigDec 26, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Open Design Alliance Drawings SDK before 2024.12. A corrupted value of number of sectors used by the Fat structure in a crafted DGN file leads to an out-of-bounds write. An attacker can leverage this vulnerability to execute code in the context of the…

  • CVE-2023-46681HigDec 26, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in VR-S1000 firmware Ver. 2.37 and earlier allows an authenticated attacker who can access to the product's command line interface to execute an arbitrary command.

  • CVE-2023-28616HigDec 26, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the password has an equals sign or space character. The serverd process logs such passwords in cleartext, and…

  • CVE-2023-38321HigDec 25, 2023
    risk 0.49cvss 7.5epss 0.01

    OpenNDS, as used in Sierra Wireless ALEOS before 4.17.0.12 and other products, allows remote attackers to cause a denial of service (NULL pointer dereference, daemon crash, and Captive Portal outage) via a GET request to /opennds_auth/ that lacks a custom query string parameter…

  • CVE-2023-49226HigDec 25, 2023
    risk 0.47cvss 7.2epss 0.03

    An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users with admin privileges to execute arbitrary commands as root.

  • CVE-2023-36486HigDec 25, 2023
    risk 0.00cvss 7.2epss 0.01

    The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user by uploading a workflow definition file with a malicious filename.

  • CVE-2023-36485HigDec 25, 2023
    risk 0.00cvss 7.2epss 0.01

    The workflow-engine of ILIAS before 7.23 and 8 before 8.3 allows remote authenticated users to run arbitrary system commands on the application server as the application user via a malicious BPMN2 workflow definition file.

  • CVE-2023-47091HigDec 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Stormshield Network Security (SNS) SNS 4.3.13 through 4.3.22 before 4.3.23, SNS 4.6.0 through 4.6.9 before 4.6.10, and SNS 4.7.0 through 4.7.1 before 4.7.2. An attacker can overflow the cookie threshold, making an IPsec connection impossible.

  • CVE-2023-37188HigDec 25, 2023
    risk 0.00cvss 7.5epss 0.01

    C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_rate_decompress at zfp/blosc2-zfp.c.

  • CVE-2023-37187HigDec 25, 2023
    risk 0.00cvss 7.5epss 0.01

    C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the zfp/blosc2-zfp.c zfp_acc_decompress. function.

  • CVE-2023-37186HigDec 25, 2023
    risk 0.00cvss 7.5epss 0.01

    C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference in ndlz/ndlz8x8.c via a NULL pointer to memset.

  • CVE-2023-37185HigDec 25, 2023
    risk 0.00cvss 7.5epss 0.01

    C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_prec_decompress at zfp/blosc2-zfp.c.

  • CVE-2023-28872HigDec 25, 2023
    risk 0.57cvss 8.8epss 0.01

    Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\NcpSupport* location.

  • CVE-2023-51772HigDec 25, 2023
    risk 0.57cvss 8.8epss 0.01

    One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape…

  • CVE-2023-49328HigDec 25, 2023
    risk 0.47cvss 7.2epss 0.01

    On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote code execution via Argument Injection in the server-to-server module.

  • CVE-2023-31455HigDec 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort.

  • CVE-2023-31289HigDec 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort.

  • CVE-2022-39822HigDec 25, 2023
    risk 0.57cvss 8.8epss 0.01

    In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET parameter. An authenticated attacker is required for exploitation.

  • CVE-2022-39818HigDec 25, 2023
    risk 0.57cvss 8.8epss 0.02

    In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. This allows authenticated users to execute commands, with root privileges, on the operating system.

  • CVE-2023-49880HigDec 25, 2023
    risk 0.49cvss 7.5epss 0.01

    In the Message Entry and Repair (MER) facility of IBM Financial Transaction Manager for SWIFT Services 3.2.4 the sending address and the message type of FIN messages are assumed to be immutable. However, an attacker might modify these elements of a business transaction. IBM…

  • CVE-2023-43064HigDec 25, 2023
    risk 0.46cvss 7.0epss 0.00

    Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause arbitrary code to run with the privilege of the user invoking the facsimile support. IBM X-Force ID: …

  • CVE-2021-38927HigDec 25, 2023
    risk 0.47cvss 7.2epss 0.00

    IBM Aspera Console 3.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: …