VYPR

CVEs

8,988 total · page 107 of 180

  • CVE-2023-47842CriMar 26, 2024
    risk 0.59cvss 9.1epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Zachary Segal CataBlog.This issue affects CataBlog: from n/a through 1.7.0.

  • CVE-2023-38388CriMar 26, 2024
    risk 0.60cvss 9.0epss 0.23

    Unrestricted Upload of File with Dangerous Type vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from n/a through 3.3.5.

  • CVE-2023-29386CriMar 26, 2024
    risk 0.59cvss 9.1epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in Julien Crego Manager for Icomoon.This issue affects Manager for Icomoon: from n/a through 2.0.

  • CVE-2023-28787CriMar 26, 2024
    risk 0.63cvss 9.3epss 0.32

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.4.

  • CVE-2023-23656CriMar 26, 2024
    risk 0.65cvss 10.0epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in MainWP MainWP File Uploader Extension.This issue affects MainWP File Uploader Extension: from n/a through 4.1.

  • CVE-2024-30231CriMar 26, 2024
    risk 0.59cvss 9.1epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through 2.4.1.

  • CVE-2024-28048CriMar 26, 2024
    risk 0.64cvss 9.8epss 0.01

    OS command injection vulnerability exists in ffBull ver.4.11, which may allow a remote unauthenticated attacker to execute an arbitrary OS command with the privilege of the running web server. Note that the developer was unreachable, therefore, users should consider stop using…

  • CVE-2024-29666CriMar 25, 2024
    risk 0.64cvss 9.8epss 0.00

    Insecure Permissions vulnerability in Vehicle Monitoring platform system CMSV6 v.7.31.0.2 through v.7.32.0.3 allows a remote attacker to escalate privileges via the default password component.

  • CVE-2024-29650CriMar 25, 2024
    risk 0.57cvss 9.8epss 0.03

    An issue in @thi.ng/paths v.5.1.62 and before allows a remote attacker to execute arbitrary code via the mutIn and mutInManyUnsafe components.

  • CVE-2024-2865CriMar 25, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Quality Management System allows SQL Injection. This issue affects Quality Management System: through 25032024.

  • CVE-2022-36407CriMar 25, 2024
    risk 0.64cvss 9.9epss 0.00

    Insertion of Sensitive Information into Log File vulnerability in Hitachi Virtual Storage Platform, Hitachi Virtual Storage Platform VP9500, Hitachi Virtual Storage Platform G1000, G1500, Hitachi Virtual Storage Platform F1500, Hitachi Virtual Storage Platform 5100, 5500, 5100H,…

  • CVE-2024-27956CriMar 21, 2024
    risk 0.75cvss 9.9epss 0.94

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.

  • CVE-2024-29732CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthenticated user to retrieve, update and delete all the information of database. This vulnerability was found on login page via "user" parameter.

  • CVE-2024-1148CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.00

    Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files.

  • CVE-2024-1147CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.00

    Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files.

  • CVE-2024-2161CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.00

    Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .

  • CVE-2024-1202CriMar 21, 2024
    risk 0.64cvss 9.8epss 0.00

    Authentication Bypass by Primary Weakness vulnerability in XPodas Octopod allows Authentication Bypass. This issue affects Octopod: before v1.  NOTE: The vendor was contacted and it was learned that the product is not supported.

  • CVE-2024-1811CriMar 20, 2024
    risk 0.64cvss 9.8epss 0.00

    A potential vulnerability has been identified in OpenText ArcSight Platform. The vulnerability could be remotely exploited.

  • CVE-2024-1711CriMar 20, 2024
    risk 0.64cvss 9.8epss 0.01

    The Create by Mediavine plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.9.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

  • CVE-2024-28389CriMar 19, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileges and obtain sensitive information via the SpinWheelFrameSpinWheelModuleFrontController::sendEmail() method.

  • CVE-2024-28394CriMar 19, 2024
    risk 0.64cvss 9.8epss 0.02

    An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & Export module.

  • CVE-2024-28303CriMar 19, 2024
    risk 0.64cvss 9.8epss 0.00

    Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/index.php.

  • CVE-2024-29135CriMar 19, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.15.

  • CVE-2024-2636CriMar 19, 2024
    risk 0.59cvss 9.0epss 0.00

    An Unrestricted Upload of File vulnerability has been found on Cegid Meta4 HR, that allows an attacker to upload malicios files to the server via '/config/espanol/update_password.jsp' file. Modifying the 'M4_NEW_PASSWORD' parameter, an attacker could store a malicious JSP file…

  • CVE-2024-2051CriMar 18, 2024
    risk 0.64cvss 9.8epss 0.00

    CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the login form.

  • CVE-2024-28125CriMar 18, 2024
    risk 0.64cvss 9.8epss 0.01

    FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of FitNesse has claimed that this is not a vulnerability but a product specification and this is currently under further investigation.

  • CVE-2024-29151CriMar 18, 2024
    risk 0.59cvss 9.1epss 0.00

    Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.

  • CVE-2021-47157CriMar 18, 2024
    risk 0.57cvss 9.8epss 0.00

    The Kossy module before 0.60 for Perl allows JSON hijacking because of X-Requested-With mishandling.

  • CVE-2021-47155CriMar 18, 2024
    risk 0.59cvss 9.1epss 0.00

    The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

  • CVE-2018-25099CriMar 18, 2024
    risk 0.57cvss 9.8epss 0.00

    In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag.

  • CVE-2022-47036CriMar 18, 2024
    risk 0.64cvss 9.8epss 0.00

    Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. It can be used for "debug login" by an admin. NOTE: the vulnerability is not fixed by the 2.1.1 firmware; instead, it is fixed in…

  • CVE-2024-27957CriMar 17, 2024
    risk 0.65cvss 10.0epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1.

  • CVE-2023-7017CriMar 15, 2024
    risk 0.64cvss 9.8epss 0.00

    Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Energy service. A challenge request can be sent to the lock with a command to prepare for an update, rather than an unlock request, allowing…

  • CVE-2023-7006CriMar 15, 2024
    risk 0.59cvss 9.1epss 0.00

    The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks integrity.

  • CVE-2024-1917CriMar 15, 2024
    risk 0.64cvss 9.8epss 0.00

    Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.

  • CVE-2024-1916CriMar 15, 2024
    risk 0.64cvss 9.8epss 0.00

    Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.

  • CVE-2024-1915CriMar 15, 2024
    risk 0.64cvss 9.8epss 0.00

    Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.

  • CVE-2024-0803CriMar 15, 2024
    risk 0.64cvss 9.8epss 0.00

    Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.

  • CVE-2024-0802CriMar 15, 2024
    risk 0.64cvss 9.8epss 0.00

    Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to read arbitrary information from a target product or execute malicious code on a target product by sending a…

  • CVE-2024-2172CriMar 13, 2024
    risk 0.64cvss 9.8epss 0.01

    The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and…

  • CVE-2023-6825CriMar 13, 2024
    risk 0.70cvss 9.9epss 0.76

    The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function.…

  • CVE-2024-25331CriMar 12, 2024
    risk 0.61cvss 9.3epss 0.03

    DIR-822 Rev. B Firmware v2.02KRB09 and DIR-822-CA Rev. B Firmware v2.03WWb01 suffer from a LAN-Side Unauthenticated Remote Code Execution (RCE) vulnerability elevated from HNAP Stack-Based Buffer Overflow.

  • CVE-2024-2184CriMar 11, 2024
    risk 0.64cvss 9.8epss 0.00

    Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C…

  • CVE-2023-49340CriMar 9, 2024
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management portal.

  • CVE-2024-22857CriMar 7, 2024
    risk 0.64cvss 9.8epss 0.04

    Heap based buffer flow in zlog v1.1.0 to v1.2.17 in zlog_rule_new().The size of record_name is MAXLEN_PATH(1024) + 1 but file_path may have data upto MAXLEN_CFG_LINE(MAXLEN_PATH*4) + 1. So a check was missing in zlog_rule_new() while copying the record_name from file_path + 1…

  • CVE-2023-51786CriMar 7, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privileges and obtain sensitive information via Incorrect Access Control.

  • CVE-2024-27304CriMar 6, 2024
    risk 0.57cvss 9.8epss 0.02

    pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the…

  • CVE-2023-7103CriMar 5, 2024
    risk 0.64cvss 9.8epss 0.00

    Authentication Bypass by Primary Weakness vulnerability in ZKSoftware Biometric Security Solutions UFace 5 allows Authentication Bypass. This issue affects UFace 5: through 12022024.

  • CVE-2024-21767CriMar 1, 2024
    risk 0.61cvss 9.4epss 0.00

    A remote attacker may be able to bypass access control of Commend WS203VICM by creating a malicious request.

  • CVE-2024-1624CriMar 1, 2024
    risk 0.61cvss 9.4epss 0.00

    An OS Command Injection vulnerability affecting documentation server on 3DEXPERIENCE from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x, SIMULIA Abaqus from Release 2022 through Release 2024, SIMULIA Isight from Release 2022 through Release 2024 and CATIA…