VYPR

CVEs

112,299 total · page 1079 of 2,246

  • CVE-2022-4943HigOct 20, 2023
    risk 0.49cvss 7.5epss 0.01

    The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when changing plugin settings in versions up to, and including, 5.6.5. This makes it possible for unauthenticated attackers to change the plugin's…

  • CVE-2022-4290HigOct 20, 2023
    risk 0.57cvss 8.8epss 0.01

    The Cyr to Lat plugin for WordPress is vulnerable to authenticated SQL Injection via the 'ctl_sanitize_title' function in versions up to, and including, 3.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…

  • CVE-2022-3342HigOct 20, 2023
    risk 0.42cvss 7.5epss 0.01

    The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the 'zeroBSCRM_CSVImporterLitehtml_app' function in versions up to, and including, 5.3.1. While the function performs a nonce check, steps 2 and 3 of the check do…

  • CVE-2022-2441HigOct 20, 2023
    risk 0.57cvss 8.8epss 0.01

    The ImageMagick Engine plugin for WordPress is vulnerable to remote code execution via the 'cli_path' parameter in versions up to, and including 1.7.5. This makes it possible for unauthenticated users to run arbitrary commands leading to remote command execution, granted they…

  • CVE-2021-4334HigOct 20, 2023
    risk 0.57cvss 8.8epss 0.01

    The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a missing capability check on the fpd_update_options function in versions up to, and including, 4.6.9. This makes it possible for authenticated attackers with…

  • CVE-2020-36714HigOct 20, 2023
    risk 0.48cvss 7.4epss 0.00

    The Brizy plugin for WordPress is vulnerable to authorization bypass due to a incorrect capability check on the is_administrator() function in versions up to, and including, 1.0.125. This makes it possible for authenticated attackers to access and interact with available AJAX…

  • CVE-2023-5576HigOct 20, 2023
    risk 0.52cvss 8.0epss 0.01

    The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 0.9.91 via Google Drive API secrets stored in plaintext in the publicly visible plugin source. This could allow unauthenticated…

  • CVE-2023-5524HigOct 20, 2023
    risk 0.53cvss 8.2epss 0.00

    Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution via specific file types

  • CVE-2023-5523HigOct 20, 2023
    risk 0.56cvss 8.6epss 0.00

    Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution

  • CVE-2023-4598HigOct 20, 2023
    risk 0.50cvss 8.8epss 0.01

    The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 5.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

  • CVE-2023-4402HigOct 20, 2023
    risk 0.53cvss 8.1epss 0.01

    The Essential Blocks plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2.0 via deserialization of untrusted input in the get_products function. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present in…

  • CVE-2023-4274HigOct 20, 2023
    risk 0.57cvss 8.7epss 0.01

    The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 0.9.89. This allows authenticated attackers with administrative privileges to delete the contents of arbitrary directories on the server, which…

  • CVE-2023-39680HigOct 20, 2023
    risk 0.49cvss 7.5epss 0.01

    Sollace Unicopia version 1.1.1 and before was discovered to deserialize untrusted data, allowing attackers to execute arbitrary code.

  • CVE-2023-2325HigOct 20, 2023
    risk 0.47cvss 7.3epss 0.00

    Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on users browser via stored HTML document.

  • CVE-2022-4712HigOct 20, 2023
    risk 0.47cvss 7.2epss 0.00

    The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the log parameter when logging in to the site in versions up to, and including, 9.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…

  • CVE-2020-36698HigOct 20, 2023
    risk 0.57cvss 8.8epss 0.01

    The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized user interaction in versions up to, and including, 2.50. This is due to missing capability checks on several AJAX actions and nonce disclosure in the source page of the administrative…

  • CVE-2023-40361HigOct 20, 2023
    risk 0.51cvss 7.8epss 0.00

    SECUDOS Qiata (DOMOS OS) 4.13 has Insecure Permissions for the previewRm.sh daily cronjob. To exploit this, an attacker needs access as a low-privileged user to the underlying DOMOS system. Every user on the system has write permission for previewRm.sh, which is executed by the…

  • CVE-2023-46277HigOct 20, 2023
    risk 0.44cvss 7.8epss 0.00

    please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.)

  • CVE-2023-34052HigOct 20, 2023
    risk 0.51cvss 7.8epss 0.00

    VMware Aria Operations for Logs contains a deserialization vulnerability. A malicious actor with non-administrative access to the local system can trigger the deserialization of data which could result in authentication bypass.

  • CVE-2023-46115HigOct 20, 2023
    risk 0.48cvss 8.4epss 0.00

    Tauri is a framework for building binaries for all major desktop platforms. This advisory is not describing a vulnerability in the Tauri code base itself but a commonly used misconfiguration which could lead to leaking of the private key and updater key password into bundled…

  • CVE-2023-44385HigOct 19, 2023
    risk 0.56cvss 8.6epss 0.00

    The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. Attackers may send malicious links/QRs to victims that, when visited, will make the victim to call arbitrary services in their Home Assistant installation.…

  • CVE-2023-43345HigOct 19, 2023
    risk 0.56cvss 8.6epss 0.00

    Cross-site scripting (XSS) vulnerability in opensolution Quick CMS v.6.7 allows a local attacker to execute arbitrary code via a crafted script to the Content - Name parameter in the Pages Menu component.

  • CVE-2023-41898HigOct 19, 2023
    risk 0.56cvss 8.6epss 0.00

    Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is vulnerable to arbitrary URL loading in a WebView. This enables all sorts of attacks, including arbitrary JavaScript execution, limited native code execution,…

  • CVE-2023-41897HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.01

    Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the web page is allowed to be framed. The omission of this and correlating headers facilitates covert…

  • CVE-2023-41896HigOct 19, 2023
    risk 0.46cvss 7.1epss 0.00

    Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebSocket authentication logic in tandem with the `state` parameter. The state parameter contains the…

  • CVE-2023-41895HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.01

    Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in to another website that specifies the `redirect_uri` and `client_id` parameters. Although the `redirect_uri` validation typically…

  • CVE-2023-44690HigOct 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py

  • CVE-2023-45823HigOct 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Artifact Hub is a web-based application that enables finding, installing, and publishing packages and configurations for CNCF projects. During a security audit of Artifact Hub's code base a security researcher identified a bug in which by using symbolic links in certain kinds of…

  • CVE-2023-30132HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue discovered in IXP Data EasyInstall 6.6.14907.0 allows attackers to gain escalated privileges via static Cryptographic Key.

  • CVE-2023-27795HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue found in IXP Data Easy Install v.6.6.14884.0 allows a local attacker to gain privileges via a static XOR key.

  • CVE-2023-27793HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue discovered in IXP Data Easy Install v.6.6.14884.0 allows local attackers to gain escalated privileges via weak encoding of sensitive information.

  • CVE-2023-27792HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions applied to sub directories.

  • CVE-2023-40145HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.01

    In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary commands after login to the device.

  • CVE-2023-27791HigOct 19, 2023
    risk 0.53cvss 8.1epss 0.01

    An issue found in IXP Data Easy Install 6.6.148840 allows a remote attacker to escalate privileges via insecure PRNG.

  • CVE-2023-41089HigOct 19, 2023
    risk 0.52cvss 8.0epss 0.01

    The affected product is vulnerable to an improper authentication vulnerability, which may allow an attacker to impersonate a legitimate user as long as the device keeps the session active, since the attack takes advantage of the cookie header to generate "legitimate"…

  • CVE-2023-5059HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    Santesoft Sante FFT Imaging lacks proper validation of user-supplied data when parsing DICOM files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2023-39431HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    Sante DICOM Viewer Pro lacks proper validation of user-supplied data when parsing DICOM files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2023-38128HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.01

    An out-of-bounds write vulnerability exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause a type confusion, which can lead to memory corruption and eventually arbitrary code execution. An attacker can provide a…

  • CVE-2023-38127HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.01

    An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. An…

  • CVE-2023-35986HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    Sante DICOM Viewer Pro lacks proper validation of user-supplied data when parsing DICOM files. This could lead to a stack-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2023-34366HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.01

    A use-after-free vulnerability exists in the Figure stream parsing functionality of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause memory corruption, resulting in arbitrary code execution. Victim would need to open a malicious file to trigger this…

  • CVE-2023-45277HigOct 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system directories, and read arbitrary files.

  • CVE-2023-35126HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    An out-of-bounds write vulnerability exists within the parsers for both the "DocumentViewStyles" and "DocumentEditStyles" streams of Ichitaro 2023 1.0.1.59372 when processing types 0x0000-0x0009 of a style record with the type 0x2008. A specially crafted document can cause…

  • CVE-2023-43251HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.01

    XNSoft Nconvert 7.136 has an Exception Handler Chain Corrupted via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

  • CVE-2023-35187HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.03

    The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability allows an unauthenticated user to achieve the Remote Code Execution.

  • CVE-2023-35186HigOct 19, 2023
    risk 0.52cvss 8.0epss 0.02

    The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution.

  • CVE-2023-35184HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.01

    The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse a SolarWinds service resulting in a remote code execution.

  • CVE-2023-35183HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows authenticated users to abuse local resources to Privilege Escalation.

  • CVE-2023-35182HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.02

    The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability can be abused by unauthenticated users on SolarWinds ARM Server.

  • CVE-2023-35181HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows users to abuse incorrect folder permission resulting in Privilege Escalation.