VYPR

CVEs

112,496 total · page 1074 of 2,250

  • CVE-2022-44569HigNov 3, 2023
    risk 0.51cvss 7.8epss 0.01

    A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.

  • CVE-2022-43555HigNov 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability

  • CVE-2022-43554HigNov 3, 2023
    risk 0.51cvss 7.8epss 0.00

    Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability

  • CVE-2023-3893HigNov 3, 2023
    risk 0.50cvss 8.8epss 0.03

    A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running …

  • CVE-2023-39299HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music…

  • CVE-2023-34179HigNov 3, 2023
    risk 0.49cvss 7.6epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Groundhogg Inc. Groundhogg allows SQL Injection.This issue affects Groundhogg: from n/a through 2.7.11.

  • CVE-2023-32508HigNov 3, 2023
    risk 0.49cvss 7.6epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolf van Gelder Order Your Posts Manually allows SQL Injection.This issue affects Order Your Posts Manually: from n/a through 2.2.5.

  • CVE-2023-32121HigNov 3, 2023
    risk 0.49cvss 7.6epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Highfivery LLC Zero Spam for WordPress allows SQL Injection.This issue affects Zero Spam for WordPress: from n/a through 5.4.4.

  • CVE-2023-25990HigNov 3, 2023
    risk 0.46cvss 7.1epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.1.10.

  • CVE-2023-25800HigNov 3, 2023
    risk 0.53cvss 8.1epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.2.0.

  • CVE-2023-25700HigNov 3, 2023
    risk 0.53cvss 8.2epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Tutor LMS allows SQL Injection.This issue affects Tutor LMS: from n/a through 2.1.10.

  • CVE-2022-46818HigNov 3, 2023
    risk 0.53cvss 8.2epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gopi Ramasamy Email posts to subscribers allows SQL Injection.This issue affects Email posts to subscribers: from n/a through 6.2.

  • CVE-2023-46947HigNov 3, 2023
    risk 0.57cvss 8.8epss 0.01

    Subrion 4.2.1 has a remote command execution vulnerability in the backend.

  • CVE-2023-26015HigNov 3, 2023
    risk 0.46cvss 7.1epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Chris Richardson MapPress Maps for WordPress mappress-google-maps-for-wordpress allows SQL Injection.This issue affects MapPress Maps for WordPress: from n/a through 2.85.4.

  • CVE-2022-47445HigNov 3, 2023
    risk 0.53cvss 8.2epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Web-X Be POPIA Compliant be-popia-compliant allows SQL Injection.This issue affects Be POPIA Compliant: from n/a through 1.2.0.

  • CVE-2022-46859HigNov 3, 2023
    risk 0.55cvss 8.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows SQL Injection.This issue affects Spiffy Calendar: from n/a through 4.9.1.

  • CVE-2022-46808HigNov 3, 2023
    risk 0.53cvss 8.2epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Repute Infosystems ARMember armember-membership allows SQL Injection.This issue affects ARMember: from n/a through 3.4.11.

  • CVE-2022-45805HigNov 3, 2023
    risk 0.53cvss 8.2epss 0.02

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paytm Paytm Payment Gateway paytm-payments allows SQL Injection.This issue affects Paytm Payment Gateway: from n/a through 2.7.3.

  • CVE-2023-4591HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.01

    A local file inclusion vulnerability has been found in WPN-XM Serverstack affecting version 0.8.6, which would allow an unauthenticated user to perform a local file inclusion (LFI) via the /tools/webinterface/index.php?page parameter by sending a GET request. This vulnerability…

  • CVE-2023-41652HigNov 3, 2023
    risk 0.53cvss 8.2epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David F. Carr RSVPMaker rsvpmaker allows SQL Injection.This issue affects RSVPMaker: from n/a through 10.6.6.

  • CVE-2023-34383HigNov 3, 2023
    risk 0.55cvss 8.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP Project Manager wedevs-project-manager allows SQL Injection.This issue affects WP Project Manager: from n/a through 2.6.0.

  • CVE-2023-1476HigNov 3, 2023
    risk 0.00cvss 7.0epss 0.00

    A use-after-free flaw was found in the Linux kernel’s mm/mremap memory address space accounting source code. This issue occurs due to a race condition between rmap walk and mremap, allowing a local user to crash the system or potentially escalate their privileges on the system.

  • CVE-2023-5824HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.05

    A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is…

  • CVE-2023-46848HigNov 3, 2023
    risk 0.57cvss 8.6epss 0.10

    Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input.

  • CVE-2023-46847HigNov 3, 2023
    risk 0.63cvss 8.6epss 0.88

    Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.

  • CVE-2023-1194HigNov 3, 2023
    risk 0.46cvss 7.1epss 0.01

    An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of `NameOffset` in…

  • CVE-2023-41357HigNov 3, 2023
    risk 0.57cvss 8.8epss 0.01

    Galaxy Software Services Corporation Vitals ESP is an online knowledge base management portal, it has insufficient filtering and validation during file upload. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute…

  • CVE-2023-41344HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.01

    NCSIST ManageEngine Mobile Device Manager(MDM) APP's special function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and read arbitrary system files.

  • CVE-2023-41353HigNov 3, 2023
    risk 0.57cvss 8.8epss 0.01

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin access and performing arbitrary system…

  • CVE-2023-41352HigNov 3, 2023
    risk 0.47cvss 7.2epss 0.01

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate…

  • CVE-2023-45024HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.

  • CVE-2023-44271HigNov 3, 2023
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw…

  • CVE-2023-43665HigNov 3, 2023
    risk 0.42cvss 7.5epss 0.01

    In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain inputs with very long, potentially malformed HTML…

  • CVE-2023-41914HigNov 3, 2023
    risk 0.46cvss 7.0epss 0.00

    SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file, overwriting a file, or deleting files.

  • CVE-2023-41350HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha…

  • CVE-2023-41348HigNov 3, 2023
    risk 0.57cvss 8.8epss 0.01

    ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its code-authentication module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary…

  • CVE-2023-41347HigNov 3, 2023
    risk 0.57cvss 8.8epss 0.01

    ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its check token module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary…

  • CVE-2023-41346HigNov 3, 2023
    risk 0.57cvss 8.8epss 0.01

    ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-refresh module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary…

  • CVE-2023-41345HigNov 3, 2023
    risk 0.57cvss 8.8epss 0.01

    ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters within its token-generated module. An authenticated remote attacker can exploit this vulnerability to perform a Command Injection attack to execute arbitrary…

  • CVE-2023-41260HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls.

  • CVE-2023-41259HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.01

    Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email message or a mail-gateway REST API call.

  • CVE-2023-41164HigNov 3, 2023
    risk 0.42cvss 7.5epss 0.01

    In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.

  • CVE-2023-34260HigNov 3, 2023
    risk 0.54cvss 7.5epss 0.73

    Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference such as %2fetc%00index.htm to try to read the /etc directory.

  • CVE-2023-31102HigNov 3, 2023
    risk 0.56cvss 7.8epss 0.71

    Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.

  • CVE-2020-28407HigNov 3, 2023
    risk 0.39cvss 7.1epss 0.00

    In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

  • CVE-2023-36034HigNov 3, 2023
    risk 0.48cvss 7.3epss 0.03

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2017-7252HigNov 3, 2023
    risk 0.49cvss 7.5epss 0.00

    bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.

  • CVE-2023-46352HigNov 2, 2023
    risk 0.49cvss 7.5epss 0.00

    In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can…

  • CVE-2023-39283HigNov 2, 2023
    risk 0.51cvss 7.8epss 0.00

    An SMM memory corruption vulnerability in the SMM driver (SMRAM write) in CsmInt10HookSmm in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to send arbitrary data to SMM which could lead to privilege escalation.

  • CVE-2023-39057HigNov 2, 2023
    risk 0.49cvss 7.5epss 0.01

    An information leak in hirochanKAKIwaiting v13.6.1 allows attackers to obtain the channel access token and send crafted messages.