VYPR

CVEs

112,855 total · page 1071 of 2,258

  • CVE-2023-30581HigNov 23, 2023
    risk 0.49cvss 7.5epss 0.01

    The use of __proto__ in process.mainModule.__proto__.require() can bypass the policy mechanism and require modules outside of the policy.json definition. This vulnerability affects all users using the experimental policy mechanism in all active release lines: v16, v18 and, v20. …

  • CVE-2023-48107HigNov 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_has_slash function in the mz_os.c file.

  • CVE-2023-48105HigNov 22, 2023
    risk 0.49cvss 7.5epss 0.01

    An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service via the wasm_loader_prepare_bytecode function in core/iwasm/interpreter/wasm_loader.c.

  • CVE-2023-49102HigNov 22, 2023
    risk 0.57cvss 8.8epss 0.01

    NZBGet 21.1 allows authenticated remote code execution because the unarchive programs (7za and unrar) preserve executable file permissions. An attacker with the Control capability can execute a file by setting the value of SevenZipCommand or UnrarCmd. NOTE: This vulnerability…

  • CVE-2023-47773HigNov 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YAS Global Team Permalinks Customizer plugin <= 2.8.2 versions.

  • CVE-2023-47768HigNov 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Footer Putter plugin <= 1.17 versions.

  • CVE-2023-47767HigNov 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fla-shop.Com Interactive World Map plugin <= 3.2.0 versions.

  • CVE-2023-47766HigNov 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timo Reith Post Status Notifier Lite plugin <= 1.11.0 versions.

  • CVE-2023-30496HigNov 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MagePeople Team WpBusTicketly plugin <= 5.2.5 versions.

  • CVE-2023-47785HigNov 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in LayerSlider plugin <= 7.7.9 versions.

  • CVE-2023-47781HigNov 22, 2023
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Thrive Themes Thrive Theme Builder < 3.24.2 versions.

  • CVE-2023-6263HigNov 22, 2023
    risk 0.54cvss 8.3epss 0.00

    An issue was discovered by IPVM team in Network Optix NxCloud before 23.1.0.40440. It was possible to add a fake VMS server to NxCloud by using the exact identification of a legitimate VMS server. As result, it was possible to retrieve authorization headers from legitimate…

  • CVE-2023-48646HigNov 22, 2023
    risk 0.53cvss 7.2epss 0.82

    Zoho ManageEngine RecoveryManager Plus before 6070 allows admin users to execute arbitrary commands via proxy settings.

  • CVE-2023-48106HigNov 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_resolve function in the mz_os.c file.

  • CVE-2023-47250HigNov 22, 2023
    risk 0.57cvss 8.8epss 0.01

    In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktops of other users by specifying their DISPLAY ID. This allows complete control…

  • CVE-2023-43887HigNov 22, 2023
    risk 0.00cvss 8.1epss 0.01

    Libde265 v1.0.12 was discovered to contain multiple buffer overflows via the num_tile_columns and num_tile_row parameters in the function pic_parameter_set::dump.

  • CVE-2023-6157HigNov 22, 2023
    risk 0.49cvss 7.6epss 0.01

    Improper neutralization of livestatus command delimiters in ajax_search in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.

  • CVE-2023-6156HigNov 22, 2023
    risk 0.49cvss 7.6epss 0.01

    Improper neutralization of livestatus command delimiters in the availability timeline in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.

  • CVE-2023-47315HigNov 22, 2023
    risk 0.57cvss 8.8epss 0.01

    Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to a hard-coded JWT Secret. The secret is hardcoded into the source code available to anyone on Git Hub. This secret is used to sign the application’s JWT token and verify the incoming user-supplied…

  • CVE-2023-43082HigNov 22, 2023
    risk 0.56cvss 8.6epss 0.00

    Dell Unity prior to 5.3 contains a 'man in the middle' vulnerability in the vmadapter component. If a customer has a certificate signed by a third-party public Certificate Authority, the vCenter CA could be spoofed by an attacker who can obtain a CA-signed certificate.

  • CVE-2023-6009HigNov 22, 2023
    risk 0.57cvss 8.8epss 0.01

    The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to insufficient restriction on the 'userpro_update_user_profile' function. This makes it possible for authenticated attackers, with minimal permissions such as a…

  • CVE-2023-6007HigNov 22, 2023
    risk 0.47cvss 7.3epss 0.00

    The UserPro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on multiple functions in all versions up to, and including, 5.1.1. This makes it possible for unauthenticated attackers to add,…

  • CVE-2023-5822HigNov 22, 2023
    risk 0.53cvss 8.1epss 0.02

    The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This makes it possible for…

  • CVE-2023-5815HigNov 22, 2023
    risk 0.53cvss 8.1epss 0.04

    The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnerable to Remote Code Execution via Local File Inclusion in all versions up to, and including,…

  • CVE-2023-5466HigNov 22, 2023
    risk 0.50cvss 8.8epss 0.01

    The Wp anything slider plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

  • CVE-2023-5465HigNov 22, 2023
    risk 0.50cvss 8.8epss 0.01

    The Popup with fancybox plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

  • CVE-2023-48705HigNov 22, 2023
    risk 0.39cvss 7.1epss 0.01

    Nautobot is a Network Source of Truth and Network Automation Platform built as a web application All users of Nautobot versions earlier than 1.6.6 or 2.0.5 are potentially affected by a cross-site scripting vulnerability. Due to incorrect usage of Django's `mark_safe()` API when…

  • CVE-2023-47350HigNov 22, 2023
    risk 0.50cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in SwiftyEdit Content Management System prior to v1.2.0, allows remote attackers to escalate privileges via the user password update functionality.

  • CVE-2023-2841HigNov 22, 2023
    risk 0.47cvss 7.2epss 0.01

    The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in versions up to, and including, 1.5.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

  • CVE-2023-2497HigNov 22, 2023
    risk 0.57cvss 8.8epss 0.00

    The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. This is due to missing or incorrect nonce validation on the 'import_settings' function. This makes it possible for unauthenticated attackers to exploit PHP…

  • CVE-2023-2440HigNov 22, 2023
    risk 0.57cvss 8.8epss 0.00

    The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.1. This is due to missing nonce validation in the 'admin_page', 'userpro_verify_user' and 'verifyUnverifyAllUsers' functions. This makes it possible for…

  • CVE-2023-6252HigNov 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Path traversal vulnerability in Chalemelon Power framework, affecting the getImage parameter. This vulnerability could allow a remote user to read files located on the server and gain access to sensitive information such as configuration files.

  • CVE-2023-27451HigNov 22, 2023
    risk 0.47cvss 7.2epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in Darren Cooney Instant Images plugin <= 5.1.0.2 versions.

  • CVE-2023-5983HigNov 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Botanik Software Pharmacy Automation allows Retrieve Embedded Sensitive Data. This issue affects Pharmacy Automation: before 2.1.133.0.

  • CVE-2023-3103HigNov 22, 2023
    risk 0.52cvss 8.0epss 0.01

    Authentication bypass vulnerability, the exploitation of which could allow a local attacker to perform a Man-in-the-Middle (MITM) attack on the robot's camera video stream. In addition, if a MITM attack is carried out, it is possible to consume the robot's resources, which could…

  • CVE-2023-5921HigNov 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper Enforcement of Behavioral Workflow vulnerability in DECE Software Geodi allows Functionality Bypass. This issue affects Geodi: before 8.0.0.27396.

  • CVE-2023-47016HigNov 22, 2023
    risk 0.00cvss 7.5epss 0.01

    radare2 5.8.9 has an out-of-bounds read in r_bin_object_set_items in libr/bin/bobj.c, causing a crash in r_read_le32 in libr/include/r_endian.h.

  • CVE-2023-29069HigNov 22, 2023
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of the product with malicious DLLs. These files may then have elevated privileges leading to a Privilege Escalation vulnerability.

  • CVE-2023-48161HigNov 22, 2023
    risk 0.46cvss 7.1epss 0.00

    Buffer Overflow vulnerability in GifLib Project GifLib v.5.2.1 allows a local attacker to obtain sensitive information via the DumpSCreen2RGB function in gif2rgb.c

  • CVE-2023-46814HigNov 22, 2023
    risk 0.51cvss 7.8epss 0.00

    A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as…

  • CVE-2021-37942HigNov 22, 2023
    risk 0.46cvss 7.0epss 0.00

    A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application running the APM Java agent. By using this vulnerability, an attacker could execute code at a potentially higher level of permissions…

  • CVE-2023-5299HigNov 22, 2023
    risk 0.47cvss 7.3epss 0.00

    A user with a standard account in Fuji Electric Tellus Lite may overwrite files in the system.

  • CVE-2023-40152HigNov 22, 2023
    risk 0.51cvss 7.8epss 0.00

    When Fuji Electric Tellus Lite V-Simulator parses a specially-crafted input file an out of bounds write may occur.

  • CVE-2023-35127HigNov 22, 2023
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow may occur when Fuji Electric Tellus Lite V-Simulator parses a specially-crafted input file.

  • CVE-2023-48701HigNov 21, 2023
    risk 0.42cvss 7.5epss 0.01

    Statamic CMS is a Laravel and Git powered content management system (CMS). Prior to versions 3.4.15 an 4.36.0, HTML files crafted to look like images may be uploaded regardless of mime validation. This is only applicable on front-end forms using the "Forms" feature containing an…

  • CVE-2023-48699HigNov 21, 2023
    risk 0.48cvss 8.4epss 0.01

    fastbots is a library for fast bot and scraper development using selenium and the Page Object Model (POM) design. Prior to version 0.1.5, an attacker could modify the locators.ini locator file with python code that without proper validation it's executed and it could lead to…

  • CVE-2023-49104HigNov 21, 2023
    risk 0.57cvss 8.7epss 0.01

    An issue was discovered in ownCloud owncloud/oauth2 before 0.6.1, when Allow Subdomains is enabled. An attacker is able to pass in a crafted redirect-url that bypasses validation, and consequently allows an attacker to redirect callbacks to a Top Level Domain controlled by the…

  • CVE-2023-48239HigNov 21, 2023
    risk 0.00cvss 8.5epss 0.01

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.13, 26.0.8, and 27.1.3 of Nextcloud Server and starting in version 20.0.0 and prior to versions 20.0.14.16, 21.0.9.13, 22.2.10.15,…

  • CVE-2023-48228HigNov 21, 2023
    risk 0.00cvss 7.5epss 0.01

    authentik is an open-source identity provider. When initialising a oauth2 flow with a `code_challenge` and `code_method` (thus requesting PKCE), the single sign-on provider (authentik) must check if there is a matching and existing `code_verifier` during the token step. Prior to…

  • CVE-2021-38405HigNov 21, 2023
    risk 0.51cvss 7.8epss 0.01

    The Datalogics APDFL library used in affected products is vulnerable to memory corruption condition while parsing specially crafted PDF files. An attacker could leverage this vulnerability to execute code in the context of the current process.