VYPR

CVEs

112,921 total · page 1064 of 2,259

  • CVE-2023-46157HigDec 8, 2023
    risk 0.57cvss 8.8epss 0.02

    File-Manager in MGT CloudPanel 2.0.0 through 2.3.2 allows the lowest privilege user to achieve OS command injection by changing file ownership and changing file permissions to 4755.

  • CVE-2023-32460HigDec 8, 2023
    risk 0.57cvss 8.8epss 0.00

    Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.

  • CVE-2023-26158HigDec 8, 2023
    risk 0.53cvss 8.2epss 0.01

    All versions of the package mockjs are vulnerable to Prototype Pollution via the Util.extend function due to missing check if the attribute resolves to the object prototype. By adding or modifying attributes of an object prototype, it is possible to create attributes that exist…

  • CVE-2023-48122HigDec 8, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in microweber v.2.0.1 and fixed in v.2.0.4 allows a remote attacker to obtain sensitive information via the HTTP GET method.

  • CVE-2023-43305HigDec 8, 2023
    risk 0.53cvss 8.2epss 0.01

    An issue in studio kent mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

  • CVE-2023-43744HigDec 8, 2023
    risk 0.47cvss 7.2epss 0.02

    An OS command injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an administrator to execute arbitrary OS commands via a file name parameter in a patch application…

  • CVE-2023-43743HigDec 8, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an authenticated attacker to execute arbitrary SQL queries on the backend database via the filter parameter…

  • CVE-2023-5058HigDec 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Technology™ 4 potentially allows denial-of-service attacks or arbitrary code execution.

  • CVE-2023-6580HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.02

    A vulnerability, which was classified as critical, was found in D-Link DIR-846 FW100A53DBR. This affects an unknown part of the file /HNAP1/ of the component QoS POST Handler. The manipulation of the argument smartqos_express_devices/smartqos_normal_devices leads to…

  • CVE-2023-6579HigDec 7, 2023
    risk 0.49cvss 7.3epss 0.24

    A vulnerability, which was classified as critical, has been found in osCommerce 4. Affected by this issue is some unknown functionality of the file /b2b-supermarket/shopping-cart of the component POST Parameter Handler. The manipulation of the argument estimate[country_id] leads…

  • CVE-2023-6578HigDec 7, 2023
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in Software AG WebMethods 10.11.x/10.15.x. Affected is an unknown function of the file wm.server/connect/. The manipulation leads to improper access controls. It is possible to launch the attack remotely. To access a file…

  • CVE-2023-4486HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause…

  • CVE-2023-49468HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc.

  • CVE-2023-49467HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merging_candidates function at motion.cc.

  • CVE-2023-49465HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc.

  • CVE-2023-49464HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::get_luma_bits_per_pixel_from_configuration_unci.

  • CVE-2023-49463HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    libheif v1.17.5 was discovered to contain a segmentation violation via the function find_exif_tag at /libheif/exif.cc.

  • CVE-2023-49462HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    libheif v1.17.5 was discovered to contain a segmentation violation via the component /libheif/exif.cc.

  • CVE-2023-49460HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::decode_uncompressed_image.

  • CVE-2023-6333HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.00

    The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could allow an attacker to inject arbitrary scripts into the endpoint of a web interface that could run malicious javascript code during a user's session.

  • CVE-2023-39909HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.

  • CVE-2023-33413HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary…

  • CVE-2023-33412HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a…

  • CVE-2023-33411HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal,…

  • CVE-2023-49967HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.

  • CVE-2023-39171HigDec 7, 2023
    risk 0.47cvss 7.2epss 0.01

    SENEC Storage Box V1,V2 and V3 accidentially expose a management UI accessible with publicly known admin credentials.

  • CVE-2023-39167HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data.

  • CVE-2023-49958HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Dalmann OCPP.Core through 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. The server processes mishandle StartTransaction messages containing additional, arbitrary properties, or duplicate properties. The last occurrence of a…

  • CVE-2023-49957HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. It permits multiple transactions with the same connectorId and idTag, contrary to the expected ConcurrentTx status. This could result in critical transaction…

  • CVE-2023-49956HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. A StopTransaction message with any random transactionId terminates active transactions.

  • CVE-2023-49955HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Dalmann OCPP.Core before 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. It does not validate the length of the chargePointVendor field in a BootNotification message, potentially leading to server instability and a denial of service…

  • CVE-2023-41804HigDec 7, 2023
    risk 0.46cvss 7.1epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Brainstorm Force Starter Templates — Elementor, WordPress & Beaver Builder Templates.This issue affects Starter Templates — Elementor, WordPress & Beaver Builder Templates: from n/a through 3.2.4.

  • CVE-2022-45362HigDec 7, 2023
    risk 0.50cvss 7.2epss 0.42

    Server-Side Request Forgery (SSRF) vulnerability in Paytm Paytm Payment Gateway.This issue affects Paytm Payment Gateway: from n/a through 2.7.0.

  • CVE-2023-48861HigDec 7, 2023
    risk 0.51cvss 7.8epss 0.00

    DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitrary code via urlmon.dll.

  • CVE-2023-48841HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.

  • CVE-2023-48840HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.

  • CVE-2023-48835HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.

  • CVE-2023-48834HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in pjActionAjaxSend in Car Rental v3.0 allows attackers to cause resource exhaustion.

  • CVE-2023-48833HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in pjActionAJaxSend in Time Slots Booking Calendar 4.0 allows attackers to cause resource exhaustion.

  • CVE-2023-48831HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of rate limiting in pjActionAJaxSend in Availability Booking Calendar 5.0 allows attackers to cause resource exhaustion.

  • CVE-2023-48830HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.

  • CVE-2023-48826HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.

  • CVE-2023-48207HigDec 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the Reservations list component.

  • CVE-2023-43304HigDec 7, 2023
    risk 0.53cvss 8.2epss 0.01

    An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

  • CVE-2023-43303HigDec 7, 2023
    risk 0.53cvss 8.2epss 0.01

    An issue in craftbeer bar canvas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token (via captured network traffic).

  • CVE-2023-43302HigDec 7, 2023
    risk 0.53cvss 8.2epss 0.01

    An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

  • CVE-2023-43301HigDec 7, 2023
    risk 0.53cvss 8.2epss 0.01

    An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

  • CVE-2023-43300HigDec 7, 2023
    risk 0.53cvss 8.2epss 0.01

    An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

  • CVE-2023-46307HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in server.js in etcd-browser 87ae63d75260. By supplying a /../../../ Directory Traversal input to the URL's GET request while connecting to the remote server port specified during setup, an attacker can retrieve local operating system files from the…

  • CVE-2023-41106HigDec 7, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Zimbra Collaboration (ZCS) before 10.0.3. An attacker can gain access to a Zimbra account. This is also fixed in 9.0.0 Patch 35 and 8.8.15 Patch 42.