VYPR

CVEs

112,924 total · page 1061 of 2,259

  • CVE-2023-6478HigDec 13, 2023
    risk 0.50cvss 7.6epss 0.02

    A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.

  • CVE-2023-6377HigDec 13, 2023
    risk 0.51cvss 7.8epss 0.02

    A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is…

  • CVE-2023-48791HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.01

    An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via…

  • CVE-2023-48782HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.03

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters

  • CVE-2023-46675HigDec 13, 2023
    risk 0.52cvss 8.0epss 0.01

    An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error or in the event where debug level logging is enabled in Kibana. Elastic has released Kibana 8.11.2 which resolves this issue. The messages recorded in the log…

  • CVE-2023-46671HigDec 13, 2023
    risk 0.52cvss 8.0epss 0.01

    An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error. Elastic has released Kibana 8.11.1 which resolves this issue. The error message recorded in the log may contain account credentials for the kibana_system…

  • CVE-2023-41678HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.01

    A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute unauthorized code or commands via specifically crafted request.

  • CVE-2023-41673HigDec 13, 2023
    risk 0.46cvss 7.1epss 0.00

    An improper authorization vulnerability [CWE-285] in Fortinet FortiADC version 7.4.0 and before 7.2.2 may allow a low privileged user to read or backup the full system configuration via HTTP or HTTPS requests.

  • CVE-2023-36639HigDec 13, 2023
    risk 0.47cvss 7.2epss 0.01

    A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiPAM versions 1.0.0…

  • CVE-2022-27488HigDec 13, 2023
    risk 0.54cvss 8.3epss 0.00

    A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6.0.x FortiRecorder version…

  • CVE-2023-45801HigDec 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper Authentication vulnerability in Nadatel DVR allows Information Elicitation.This issue affects DVR: from 3.0.0 before 9.9.0.

  • CVE-2023-47579HigDec 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Relyum RELY-PCIe 22.2.1 devices suffer from a system group misconfiguration, allowing read access to the central password hash file of the operating system.

  • CVE-2023-47578HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.00

    Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices are susceptible to Cross Site Request Forgery (CSRF) attacks due to the absence of CSRF protection in the web interface.

  • CVE-2023-47576HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection through the web interface.

  • CVE-2023-47573HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue discovered in Relyum RELY-PCIe 22.2.1 devices. The authorization mechanism is not enforced in the web interface, allowing a low-privileged user to execute administrative functions.

  • CVE-2023-45800HigDec 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hanbiro Hanbiro groupware allows Information Elicitation.This issue affects Hanbiro groupware: from V3.8.79 before V3.8.81.1.

  • CVE-2023-6753HigDec 13, 2023
    risk 0.50cvss 8.8epss 0.01

    Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2.

  • CVE-2023-3517HigDec 12, 2023
    risk 0.55cvss 8.5epss 0.01

    Hitachi Vantara Pentaho Data Integration & Analytics versions before 9.5.0.1 and 9.3.0.5, including 8.3.x does not restrict JNDI identifiers during the creation of XActions, allowing control of system level data sources.

  • CVE-2023-5764HigDec 12, 2023
    risk 0.39cvss 7.1epss 0.01

    A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying…

  • CVE-2023-5379HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens…

  • CVE-2023-50252HigDec 12, 2023
    risk 0.02cvss 8.3epss 0.24

    php-svg-lib is an SVG file parsing / rendering library. Prior to version 0.5.1, when handling `` tag that references an `` tag, it merges the attributes from the `` tag to the `` tag. The problem pops up especially when the `href` attribute from the…

  • CVE-2023-48225HigDec 12, 2023
    risk 0.58cvss 8.9epss 0.01

    Laf is a cloud development platform. Prior to version 1.0.0-beta.13, the control of LAF app enV is not strict enough, and in certain scenarios of privatization environment, it may lead to sensitive information leakage in secret and configmap. In ES6 syntax, if an obj directly…

  • CVE-2023-49089HigDec 12, 2023
    risk 0.50cvss 7.7epss 0.01

    Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.0, Backoffice users with permissions to create packages can use path traversal and thereby write outside of the expected location. Versions 8.18.10,…

  • CVE-2023-36696HigDec 12, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

  • CVE-2023-36391HigDec 12, 2023
    risk 0.51cvss 7.8epss 0.07

    Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

  • CVE-2023-36020HigDec 12, 2023
    risk 0.49cvss 7.6epss 0.01

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

  • CVE-2023-36011HigDec 12, 2023
    risk 0.51cvss 7.8epss 0.01

    Win32k Elevation of Privilege Vulnerability

  • CVE-2023-36010HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.03

    Microsoft Defender Denial of Service Vulnerability

  • CVE-2023-36006HigDec 12, 2023
    risk 0.57cvss 8.8epss 0.02

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

  • CVE-2023-36005HigDec 12, 2023
    risk 0.51cvss 7.5epss 0.24

    Windows Telephony Server Elevation of Privilege Vulnerability

  • CVE-2023-36004HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.01

    Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability

  • CVE-2023-35644HigDec 12, 2023
    risk 0.51cvss 7.8epss 0.06

    Windows Sysmain Service Elevation of Privilege Vulnerability

  • CVE-2023-35643HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.03

    DHCP Server Service Information Disclosure Vulnerability

  • CVE-2023-35641HigDec 12, 2023
    risk 0.58cvss 8.8epss 0.07

    Internet Connection Sharing (ICS) Remote Code Execution Vulnerability

  • CVE-2023-35639HigDec 12, 2023
    risk 0.57cvss 8.8epss 0.02

    Microsoft ODBC Driver Remote Code Execution Vulnerability

  • CVE-2023-35638HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.03

    DHCP Server Service Denial of Service Vulnerability

  • CVE-2023-35634HigDec 12, 2023
    risk 0.52cvss 8.0epss 0.01

    Windows Bluetooth Driver Remote Code Execution Vulnerability

  • CVE-2023-35633HigDec 12, 2023
    risk 0.51cvss 7.8epss 0.09

    Windows Kernel Elevation of Privilege Vulnerability

  • CVE-2023-35632HigDec 12, 2023
    risk 0.51cvss 7.8epss 0.07

    Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

  • CVE-2023-35631HigDec 12, 2023
    risk 0.51cvss 7.8epss 0.07

    Win32k Elevation of Privilege Vulnerability

  • CVE-2023-35630HigDec 12, 2023
    risk 0.58cvss 8.8epss 0.06

    Internet Connection Sharing (ICS) Remote Code Execution Vulnerability

  • CVE-2023-35628HigDec 12, 2023
    risk 0.60cvss 8.1epss 0.93

    Windows MSHTML Platform Remote Code Execution Vulnerability

  • CVE-2023-35624HigDec 12, 2023
    risk 0.48cvss 7.3epss 0.01

    Azure Connected Machine Agent Elevation of Privilege Vulnerability

  • CVE-2023-35622HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows DNS Spoofing Vulnerability

  • CVE-2023-35621HigDec 12, 2023
    risk 0.49cvss 7.5epss 0.02

    Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability

  • CVE-2023-21740HigDec 12, 2023
    risk 0.51cvss 7.8epss 0.01

    Windows Media Remote Code Execution Vulnerability

  • CVE-2023-28465HigDec 12, 2023
    risk 0.42cvss 7.5epss 0.01

    The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name chosen by the attacker. NOTE:…

  • CVE-2020-10676HigDec 12, 2023
    risk 0.57cvss 8.8epss 0.01

    In Rancher 2.x before 2.6.13 and 2.7.x before 2.7.4, an incorrectly applied authorization check allows users who have certain access to a namespace to move that namespace to a different project.

  • CVE-2018-16153HigDec 12, 2023
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some situations.

  • CVE-2015-8314HigDec 12, 2023
    risk 0.42cvss 7.5epss 0.01

    The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.