VYPR

CVEs

112,307 total · page 1076 of 2,247

  • CVE-2023-46345HigOct 26, 2023
    risk 0.49cvss 7.5epss 0.01

    Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/xlsparse.c.

  • CVE-2023-43905HigOct 26, 2023
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecified vectors.

  • CVE-2023-30969HigOct 26, 2023
    risk 0.53cvss 8.2epss 0.00

    The Palantir Tiles1 service was found to be vulnerable to an API wide issue where the service was not performing authentication/authorization on all the endpoints.

  • CVE-2023-38849HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

  • CVE-2023-38848HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

  • CVE-2023-38847HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

  • CVE-2023-38846HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

  • CVE-2023-38845HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

  • CVE-2023-5574HigOct 25, 2023
    risk 0.46cvss 7.0epss 0.01

    A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a…

  • CVE-2023-5367HigOct 25, 2023
    risk 0.51cvss 7.8epss 0.01

    A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in…

  • CVE-2023-5044HigOct 25, 2023
    risk 0.54cvss 7.6epss 0.57

    Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.

  • CVE-2023-5043HigOct 25, 2023
    risk 0.50cvss 7.6epss 0.02

    Ingress nginx annotation injection causes arbitrary command execution.

  • CVE-2022-4886HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.02

    Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.

  • CVE-2023-42856HigOct 25, 2023
    risk 0.51cvss 7.8epss 0.00

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. Processing a file may lead to unexpected app termination or arbitrary code execution.

  • CVE-2023-42852HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.02

    A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.

  • CVE-2023-42847HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. An attacker may be able to access passkeys without authentication.

  • CVE-2023-42844HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. A website may be able to access sensitive user data when resolving symlinks.

  • CVE-2023-42841HigOct 25, 2023
    risk 0.51cvss 7.8epss 0.00

    The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Ventura 13.6.1. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2023-41976HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.02

    A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.

  • CVE-2023-40447HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.02

    The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.

  • CVE-2023-40445HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    The issue was addressed with improved UI handling. This issue is fixed in iOS 17.1 and iPadOS 17.1. A device may persistently fail to lock.

  • CVE-2023-40423HigOct 25, 2023
    risk 0.51cvss 7.8epss 0.00

    The issue was addressed with improved memory handling. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Monterey 12.7.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Ventura 13.6.1, macOS Sonoma 14.1. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2023-40404HigOct 25, 2023
    risk 0.51cvss 7.8epss 0.01

    A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sonoma 14.1. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2023-40401HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    The issue was addressed with additional permissions checks. This issue is fixed in macOS Ventura 13.6.1. An attacker may be able to access passkeys without authentication.

  • CVE-2023-32359HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2. A user's password may be read aloud by VoiceOver.

  • CVE-2023-5728HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

  • CVE-2023-5724HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.02

    Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

  • CVE-2023-5717HigOct 25, 2023
    risk 0.00cvss 7.8epss 0.01

    A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation. If perf_read_group() is called while an event's sibling_list is smaller than its child's sibling_list, it can…

  • CVE-2023-5671HigOct 25, 2023
    risk 0.51cvss 7.8epss 0.00

    HP Print and Scan Doctor for Windows may potentially be vulnerable to escalation of privilege. HP is releasing software updates to mitigate the potential vulnerability.

  • CVE-2023-5472HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-5363HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.03

    Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) lengths. This can lead to potential truncation or overruns during the initialisation of some symmetric ciphers. Impact summary: A truncation in the IV can result in non-uniqueness,…

  • CVE-2023-5311HigOct 25, 2023
    risk 0.50cvss 8.8epss 0.01

    The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and…

  • CVE-2023-4692HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap…

  • CVE-2023-4607HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.00

    An authenticated XCC user can change permissions for any user through a crafted API command.

  • CVE-2023-4606HigOct 25, 2023
    risk 0.53cvss 8.1epss 0.00

    An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.

  • CVE-2023-46654HigOct 25, 2023
    risk 0.46cvss 8.1epss 0.01

    Jenkins CloudBees CD Plugin 1.1.32 and earlier follows symbolic links to locations outside of the expected directory during the cleanup process of the 'CloudBees CD - Publish Artifact' post-build step, allowing attackers able to configure jobs to delete arbitrary files on the…

  • CVE-2023-46346HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control…

  • CVE-2023-46136HigOct 25, 2023
    risk 0.45cvss 8.0epss 0.01

    Werkzeug is a comprehensive WSGI web application library. In versions on the 3.x branch prior to 3.0.1 and on the 2.x branch prior to 2.3.8, if an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes…

  • CVE-2023-46124HigOct 25, 2023
    risk 0.46cvss 8.2epss 0.01

    Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in runtime environments, and the enforcement of privacy regulations in code. The Fides web application allows a custom integration to be uploaded as a ZIP file containing…

  • CVE-2023-46119HigOct 25, 2023
    risk 0.42cvss 7.5epss 0.01

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server crashes when uploading a file without extension. This vulnerability has been patched in versions 5.5.6 and 6.3.1.

  • CVE-2023-46102HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.00

    The Android Client application, when enrolled to the AppHub server, connects to an MQTT broker to exchange messages and receive commands to execute on the HMI device. The protocol builds on top of MQTT to implement the remote management of the device is encrypted with a…

  • CVE-2023-46071HigOct 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ClickDatos Protección de Datos RGPD plugin <= 3.1.0 versions.

  • CVE-2023-46070HigOct 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Emmanuel GEORJON EG-Attachments plugin <= 2.1.3 versions.

  • CVE-2023-45990HigOct 25, 2023
    risk 0.52cvss 8.0epss 0.01

    Insecure Permissions vulnerability in WenwenaiCMS v.1.0 allows a remote attacker to escalate privileges.

  • CVE-2023-45851HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.00

    The Android Client application, when enrolled to the AppHub server,connects to an MQTT broker without enforcing any server authentication.  This issue allows an attacker to force the Android Client application to connect to a malicious MQTT broker, enabling it to send fake…

  • CVE-2023-45837HigOct 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in XYDAC Ultimate Taxonomy Manager plugin <= 2.0 versions.

  • CVE-2023-45835HigOct 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Libsyn Libsyn Publisher Hub plugin <= 1.4.4 versions.

  • CVE-2023-45772HigOct 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Scribit Proofreading plugin <= 1.0.11 versions.

  • CVE-2023-45770HigOct 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Fastwpspeed Fast WP Speed plugin <= 1.0.0 versions.

  • CVE-2023-45769HigOct 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Alex Raven WP Report Post plugin <= 2.1.2 versions.