VYPR

CVEs

112,919 total · page 1065 of 2,259

  • CVE-2023-48123HigDec 6, 2023
    risk 0.05cvss 8.8epss 0.68

    An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.

  • CVE-2023-46751HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the function gdev_prn_open_printer_seekable() in Artifex Ghostscript through 10.02.0 allows remote attackers to crash the application via a dangling pointer.

  • CVE-2023-45285HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.01

    Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not…

  • CVE-2023-39539HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.01

    AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a PNG Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. 

  • CVE-2023-39538HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a BMP Logo file with dangerous type by Local access. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or Availability. 

  • CVE-2023-48859HigDec 6, 2023
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK A3002RU version 2.0.0-B20190902.1958 has a post-authentication RCE due to incorrect access control, allows attackers to bypass front-end security restrictions and execute arbitrary code.

  • CVE-2023-6288HigDec 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environment variable.

  • CVE-2023-32268HigDec 6, 2023
    risk 0.47cvss 7.2epss 0.01

    Exposure of Proxy Administrator Credentials An authenticated administrator equivalent Filr user can access the credentials of proxy administrators.

  • CVE-2023-6514HigDec 6, 2023
    risk 0.57cvss 8.8epss 0.00

    The Bluetooth module of some Huawei Smart Screen products has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions.  Successful exploitation of this vulnerability may allow attackers…

  • CVE-2023-6458HigDec 6, 2023
    risk 0.46cvss 7.1epss 0.01

    Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal.

  • CVE-2023-49247HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-49246HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-49245HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-49244HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Permission management vulnerability in the multi-user module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-49243HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of unauthorized access to email attachments in the email module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-49242HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Free broadcast vulnerability in the running management module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-49241HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    API permission control vulnerability in the network management module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-49240HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-49239HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Unauthorized access vulnerability in the card management module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-44113HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of missing permission verification for APIs in the Designed for Reliability (DFR) module. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-44099HigDec 6, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability of data verification errors in the kernel module. Successful exploitation of this vulnerability may cause WLAN interruption.

  • CVE-2023-49897HigKEVDec 6, 2023
    risk 0.73cvss 8.8epss 0.51

    An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

  • CVE-2023-22523HigDec 6, 2023
    risk 0.58cvss 8.8epss 0.11

    This vulnerability, if exploited, allows an attacker to perform privileged RCE (Remote Code Execution) on machines with the Assets Discovery agent installed. The vulnerability exists between the Assets Discovery application (formerly known as Insight Discovery) and the Assets…

  • CVE-2023-22522HigDec 6, 2023
    risk 0.58cvss 8.8epss 0.13

    This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confluence page. Using this approach, an attacker is able to achieve Remote Code Execution (RCE) on an affected instance. Publicly…

  • CVE-2023-6510HigDec 6, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)

  • CVE-2023-6509HigDec 6, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: High)

  • CVE-2023-6508HigDec 6, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-5970HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.01

    Improper authentication in the SMA100 SSL-VPN virtual office portal allows a remote authenticated attacker to create an identical external domain user using accent characters, resulting in an MFA bypass.

  • CVE-2023-44221HigKEVDec 5, 2023
    risk 0.65cvss 7.2epss 0.75

    Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.

  • CVE-2023-45287HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Before Go 1.20, the RSA based TLS key exchanges used the math/big library, which is not constant time. RSA blinding was applied to prevent timing attacks, but analysis shows this may not have been fully effective. In particular it appears as if the removal of PKCS#1 padding may…

  • CVE-2023-45084HigDec 5, 2023
    risk 0.46cvss 7.0epss 0.00

    An issue exists in SoftIron HyperCloud where drive caddy removal and reinsertion without a reboot may erroneously cause the system to recognize the caddy as new media and wipe all data on the drives due to a missing synchronization flaw, which impacts data availability and…

  • CVE-2023-44297HigDec 5, 2023
    risk 0.46cvss 7.1epss 0.00

    Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code…

  • CVE-2023-6357HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.01

    A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.

  • CVE-2023-49448HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete.

  • CVE-2023-49447HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update.

  • CVE-2023-49446HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/save.

  • CVE-2023-49398HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/delete.

  • CVE-2023-49397HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/updateStatus.

  • CVE-2023-49396HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/save.

  • CVE-2023-49395HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/update.

  • CVE-2023-49383HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/save.

  • CVE-2023-49382HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/delete.

  • CVE-2023-49381HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/update.

  • CVE-2023-49380HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/delete.

  • CVE-2023-49379HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /admin/friend_link/save.

  • CVE-2023-49378HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/form/save.

  • CVE-2023-49377HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/update.

  • CVE-2023-49376HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/delete.

  • CVE-2023-49375HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/update.

  • CVE-2023-49374HigDec 5, 2023
    risk 0.57cvss 8.8epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/update.