VYPR

CVEs

112,517 total · page 1073 of 2,251

  • CVE-2023-33480HigNov 7, 2023
    risk 0.57cvss 8.8epss 0.02

    RemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials to create admin users, escalate privileges, and execute arbitrary code on the target system via a PHP shell. The vulnerabilities are caused by…

  • CVE-2023-5709HigNov 7, 2023
    risk 0.57cvss 8.8epss 0.01

    The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

  • CVE-2023-47510HigNov 7, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPSolutions-HQ WPDBSpringClean plugin <= 1.6 versions.

  • CVE-2023-46845HigNov 7, 2023
    risk 0.47cvss 7.2epss 0.02

    EC-CUBE 3 series (3.0.0 to 3.0.18-p6) and 4 series (4.0.0 to 4.0.6-p3, 4.1.0 to 4.1.2-p2, and 4.2.0 to 4.2.2) contain an arbitrary code execution vulnerability due to improper settings of the template engine Twig included in the product. As a result, arbitrary code may be…

  • CVE-2023-43886HigNov 7, 2023
    risk 0.46cvss 7.1epss 0.01

    A buffer overflow in the HTTP server component of Tenda RX9 Pro v22.03.02.20 might allow an authenticated attacker to overwrite memory.

  • CVE-2023-43885HigNov 7, 2023
    risk 0.53cvss 8.1epss 0.01

    Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the device.

  • CVE-2023-42537HigNov 7, 2023
    risk 0.55cvss 8.4epss 0.00

    An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

  • CVE-2023-42536HigNov 7, 2023
    risk 0.55cvss 8.4epss 0.00

    An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

  • CVE-2023-42535HigNov 7, 2023
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds Write in read_block of vold prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-33074HigNov 7, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Audio when SSR event is triggered after music playback is stopped.

  • CVE-2023-33061HigNov 7, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while parsing WLAN beacon or probe-response frame.

  • CVE-2023-33059HigNov 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Audio while processing the VOC packet data from ADSP.

  • CVE-2023-33056HigNov 7, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware when firmware receives beacon including T2LM IE.

  • CVE-2023-33055HigNov 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in Audio while invoking callback function in driver from ADSP.

  • CVE-2023-33048HigNov 7, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while parsing t2lm buffers.

  • CVE-2023-33047HigNov 7, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while parsing no-inherit IES.

  • CVE-2023-33031HigNov 7, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Automotive Audio while copying data from ADSP shared buffer to the VOC packet data buffer.

  • CVE-2023-28556HigNov 7, 2023
    risk 0.46cvss 7.1epss 0.00

    Cryptographic issue in HLOS during key management.

  • CVE-2023-28545HigNov 7, 2023
    risk 0.53cvss 8.2epss 0.00

    Memory corruption in TZ Secure OS while loading an app ELF.

  • CVE-2023-24852HigNov 7, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory Corruption in Core due to secure memory access by user while loading modem image.

  • CVE-2023-41036HigNov 7, 2023
    risk 0.00cvss 7.8epss 0.00

    Macvim is a text editor for MacOS. Prior to version 178, Macvim makes use of an insecure interprocess communication (IPC) mechanism which could lead to a privilege escalation. Distributed objects are a concept introduced by Apple which allow one program to vend an interface to…

  • CVE-2023-47004HigNov 6, 2023
    risk 0.57cvss 8.8epss 0.01

    Buffer Overflow vulnerability in Redis RedisGraph v.2.x through v.2.12.8 and fixed in v.2.12.9 allows an attacker to execute arbitrary code via the code logic after valid authentication.

  • CVE-2023-5454HigNov 6, 2023
    risk 0.49cvss 7.5epss 0.01

    The Templately WordPress plugin before 2.2.6 does not properly authorize the `saved-templates/delete` REST API call, allowing unauthenticated users to delete arbitrary posts.

  • CVE-2023-5355HigNov 6, 2023
    risk 0.53cvss 8.1epss 0.01

    The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.

  • CVE-2023-5082HigNov 6, 2023
    risk 0.47cvss 7.2epss 0.01

    The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it.

  • CVE-2023-5719HigNov 6, 2023
    risk 0.57cvss 8.8epss 0.01

    The Crimson 3.2 Windows-based configuration tool allows users with administrative access to define new passwords for users and to download the resulting security configuration to a device. If such a password contains the percent (%) character, invalid values will be included,…

  • CVE-2022-48192HigNov 6, 2023
    risk 0.47cvss 7.2epss 0.00

    Cross-site Scripting vulnerability in Softing smartLink SW-HT before 1.30, which allows an attacker to execute a dynamic script (JavaScript, VBScript) in the context of the application.

  • CVE-2023-39345HigNov 6, 2023
    risk 0.49cvss 7.6epss 0.01

    strapi is an open-source headless CMS. Versions prior to 4.13.1 did not properly restrict write access to fielded marked as private in the user registration endpoint. As such malicious users may be able to errantly modify their user records. This issue has been addressed in…

  • CVE-2023-46728HigNov 6, 2023
    risk 0.00cvss 7.5epss 0.06

    Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1.…

  • CVE-2023-46251HigNov 6, 2023
    risk 0.00cvss 7.5epss 0.00

    MyBB is a free and open source forum software. Custom MyCode (BBCode) for the visual editor (_SCEditor_) doesn't escape input properly when rendering HTML, resulting in a DOM-based XSS vulnerability. This weakness can be exploited by pointing a victim to a page where the visual…

  • CVE-2023-45827HigNov 6, 2023
    risk 0.41cvss 7.3epss 0.01

    Dot diver is a lightweight, powerful, and dependency-free TypeScript utility library that provides types and functions to work with object paths in dot notation. In versions prior to 1.0.2 there is a Prototype Pollution vulnerability in the `setByPath` function which can leads…

  • CVE-2023-44398HigNov 6, 2023
    risk 0.00cvss 8.8epss 0.01

    Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds write was found in Exiv2 version v0.28.0. The vulnerable function, `BmffImage::brotliUncompress`, is new in v0.28.0, so earlier versions…

  • CVE-2023-41378HigNov 6, 2023
    risk 0.42cvss 7.5epss 0.01

    In certain conditions for Calico Typha (v3.26.2, v3.25.1 and below), and Calico Enterprise Typha (v3.17.1, v3.16.3, v3.15.3 and below), a client TLS handshake can block the Calico Typha server indefinitely, resulting in denial of service. The TLS Handshake() call is performed…

  • CVE-2023-5950HigNov 6, 2023
    risk 0.56cvss 8.6epss 0.00

    Rapid7 Velociraptor versions prior to 0.7.0-4 suffer from a reflected cross site scripting vulnerability. This vulnerability allows attackers to inject JS into the error path, potentially leading to unauthorized execution of scripts within a user's web browser. This…

  • CVE-2023-3399HigNov 6, 2023
    risk 0.55cvss 8.5epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD…

  • CVE-2023-47185HigNov 6, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions.

  • CVE-2023-47182HigNov 6, 2023
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) leading to a Stored Cross-Site Scripting (XSS) vulnerability in Nazmul Hossain Nihal Login Screen Manager plugin <= 3.5.2 versions.

  • CVE-2023-46823HigNov 6, 2023
    risk 0.49cvss 7.6epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum ImageLinks Interactive Image Builder for WordPress allows SQL Injection.This issue affects ImageLinks Interactive Image Builder for WordPress: from n/a through 1.5.4.

  • CVE-2023-46822HigNov 6, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting') vulnerability in Visser Labs Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin <= 2.7.2 versions.

  • CVE-2023-46821HigNov 6, 2023
    risk 0.49cvss 7.6epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD Security Headers allows auth. (admin+) SQL Injection.This issue affects GD Security Headers: from n/a through 1.7.

  • CVE-2023-46084HigNov 6, 2023
    risk 0.55cvss 8.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bPlugins LLC Icons Font Loader allows SQL Injection.This issue affects Icons Font Loader: from n/a through 1.1.2.

  • CVE-2023-45830HigNov 6, 2023
    risk 0.55cvss 8.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Online ADA Accessibility Suite by Online ADA allows SQL Injection.This issue affects Accessibility Suite by Online ADA: from n/a through 4.12.

  • CVE-2023-45657HigNov 6, 2023
    risk 0.55cvss 8.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSIMYTH Nexter allows SQL Injection.This issue affects Nexter: from n/a through 2.0.3.

  • CVE-2023-45074HigNov 6, 2023
    risk 0.55cvss 8.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress allows SQL Injection.This issue affects Advanced Page Visit Counter – Most Wanted…

  • CVE-2023-45069HigNov 6, 2023
    risk 0.49cvss 7.6epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Best WordPress YouTube Gallery Plugin allows SQL Injection.This issue affects Video Gallery – Best WordPress YouTube Gallery…

  • CVE-2023-45055HigNov 6, 2023
    risk 0.55cvss 8.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InspireUI MStore API allows SQL Injection.This issue affects MStore API: from n/a through 4.0.6.

  • CVE-2023-45001HigNov 6, 2023
    risk 0.55cvss 8.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Castos Seriously Simple Stats allows SQL Injection.This issue affects Seriously Simple Stats: from n/a through 1.5.0.

  • CVE-2023-41685HigNov 6, 2023
    risk 0.49cvss 7.6epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ilGhera Woocommerce Support System allows SQL Injection.This issue affects Woocommerce Support System: from n/a through 1.2.1.

  • CVE-2023-40609HigNov 6, 2023
    risk 0.53cvss 8.2epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aiyaz, maheshpatel Contact form 7 Custom validation allows SQL Injection.This issue affects Contact form 7 Custom validation: from n/a through 1.1.3.

  • CVE-2023-40207HigNov 6, 2023
    risk 0.49cvss 7.6epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RedNao Donations Made Easy – Smart Donations allows SQL Injection.This issue affects Donations Made Easy – Smart Donations: from n/a through 4.0.12.