VYPR

CVEs

112,298 total · page 1080 of 2,246

  • CVE-2023-45883HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers a repair of the software, a pop-up window opens with SYSTEM privileges. Standard users may use this to gain arbitrary code execution as…

  • CVE-2023-43252HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.01

    XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow via a crafted image file.

  • CVE-2023-46227HigOct 19, 2023
    risk 0.42cvss 7.5epss 0.01

    Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [1] to solve it. …

  • CVE-2022-27813HigOct 19, 2023
    risk 0.53cvss 8.1epss 0.00

    Motorola MTM5000 series firmwares lack properly configured memory protection of pages shared between the OMAP-L138 ARM and DSP cores. The SoC provides two memory protection units, MPU1 and MPU2, to enforce the trust boundary between the two cores. Since both units are left…

  • CVE-2022-26943HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.00

    The Motorola MTM5000 series firmwares generate TETRA authentication challenges using a PRNG using a tick count register as its sole entropy source. Low boottime entropy and limited re-seeding of the pool renders the authentication challenge vulnerable to two attacks. First, due…

  • CVE-2022-26942HigOct 19, 2023
    risk 0.53cvss 8.2epss 0.00

    The Motorola MTM5000 series firmwares lack pointer validation on arguments passed to trusted execution environment (TEE) modules. Two modules are used, one responsible for KVL key management and the other for TETRA cryptographic functionality. In both modules, an adversary with…

  • CVE-2022-25334HigOct 19, 2023
    risk 0.53cvss 8.2epss 0.00

    The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) lacks a bounds check on the signature size field in the SK_LOAD module loading routine, present in mask ROM. A module with a sufficiently large signature field causes a stack overflow,…

  • CVE-2022-25333HigOct 19, 2023
    risk 0.53cvss 8.2epss 0.00

    The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) performs an RSA check implemented in mask ROM when loading a module through the SK_LOAD routine. However, only the module header authenticity is validated. An adversary can re-use any correctly…

  • CVE-2022-24402HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.01

    The TETRA TEA1 keystream generator implements a key register initialization function that compresses the 80-bit key to only 32 bits for usage during the keystream generation phase, which is insufficient to safeguard against exhaustive search attacks.

  • CVE-2022-24401HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.00

    Adversary-induced keystream re-use on TETRA air-interface encrypted traffic using any TEA keystream generator. IV generation is based upon several TDMA frame counters, which are frequently broadcast by the infrastructure in an unauthenticated manner. An active adversary can…

  • CVE-2022-24400HigOct 19, 2023
    risk 0.49cvss 7.5epss 0.00

    A flaw in the TETRA authentication procecure allows a MITM adversary that can predict the MS challenge RAND2 to set session key DCK to zero.

  • CVE-2023-46229HigOct 19, 2023
    risk 0.54cvss 8.8epss 0.45

    LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.

  • CVE-2023-46228HigOct 19, 2023
    risk 0.00cvss 7.8epss 0.00

    zchunk before 1.3.2 has multiple integer overflows via malformed zchunk files to lib/comp/comp.c, lib/comp/zstd/zstd.c, lib/dl/multipart.c, or lib/header.c.

  • CVE-2023-37503HigOct 19, 2023
    risk 0.53cvss 8.1epss 0.00

    HCL Compass is vulnerable to insecure password requirements. An attacker could easily guess the password and gain access to user accounts.

  • CVE-2023-5336HigOct 19, 2023
    risk 0.50cvss 8.8epss 0.01

    The iPanorama 360 – WordPress Virtual Tour Builder plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2023-37504HigOct 19, 2023
    risk 0.46cvss 7.1epss 0.00

    HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called.  If the session identifier can be discovered, it could be replayed to the application and used to impersonate the…

  • CVE-2023-34437HigOct 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device.

  • CVE-2023-45812HigOct 18, 2023
    risk 0.42cvss 7.5epss 0.01

    The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when a…

  • CVE-2023-43800HigOct 18, 2023
    risk 0.40cvss 7.3epss 0.00

    Arduino Create Agent is a package to help manage Arduino development. The vulnerability affects the endpoint `/v2/pkgs/tools/installed`. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass the CORS configuration, can escalate his…

  • CVE-2023-43802HigOct 18, 2023
    risk 0.39cvss 7.1epss 0.00

    Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/upload` which handles request with the `filename` parameter. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass the…

  • CVE-2023-4601HigOct 18, 2023
    risk 0.53cvss 8.1epss 0.01

    A stack-based buffer overflow vulnerability exists in NI System Configuration that could result in information disclosure and/or arbitrary code execution. Successful exploitation requires that an attacker can provide a specially crafted response. This affects NI System…

  • CVE-2023-35663HigOct 18, 2023
    risk 0.49cvss 7.5epss 0.00

    In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-35656HigOct 18, 2023
    risk 0.49cvss 7.5epss 0.00

    In multiple functions of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-26300HigOct 18, 2023
    risk 0.51cvss 7.8epss 0.00

    A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow escalation of privilege. HP is releasing firmware updates to mitigate the potential vulnerability.

  • CVE-2023-45912HigOct 18, 2023
    risk 0.49cvss 7.5epss 0.01

    WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 fails to validate user sessions, allowing unauthenticated attackers to read files from the underlying operating system and obtain directory listings.

  • CVE-2023-46009HigOct 18, 2023
    risk 0.51cvss 7.8epss 0.00

    gifsicle-1.94 was found to have a floating point exception (FPE) vulnerability via resize_stream at src/xform.c.

  • CVE-2023-45383HigOct 18, 2023
    risk 0.49cvss 7.5epss 0.01

    In the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the…

  • CVE-2023-43250HigOct 18, 2023
    risk 0.51cvss 7.8epss 0.01

    XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow. There is a User Mode Write AV via a crafted image file. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

  • CVE-2023-45632HigOct 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado SpiderVPlayer plugin <= 1.5.22 versions.

  • CVE-2023-45602HigOct 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.785 versions.

  • CVE-2023-30781HigOct 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Theme Blvd Tweeple plugin <= 0.9.5 versions.

  • CVE-2023-46004HigOct 18, 2023
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Best Courier Management System 1.0 is vulnerable to Arbitrary file upload in the update_user function.

  • CVE-2023-45071HigOct 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Stored Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin <= 1.15.18 versions.

  • CVE-2023-45070HigOct 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin <= 1.15.18 versions.

  • CVE-2023-45065HigOct 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit plugin <= 1.42 versions.

  • CVE-2023-45727HigKEVOct 18, 2023
    risk 0.61cvss 7.5epss 0.04

    Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted…

  • CVE-2023-5632HigOct 18, 2023
    risk 0.00cvss 7.5epss 0.01

    In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to be added, which results excessive CPU consumption. This could be used by a malicious actor to perform denial of service type…

  • CVE-2023-45064HigOct 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Daisuke Takahashi(Extend Wings) OPcache Dashboard plugin <= 0.3.1 versions.

  • CVE-2023-45062HigOct 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Thomas Scholl canvasio3D Light plugin <= 2.4.6 versions.

  • CVE-2023-45054HigOct 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AWESOME TOGI Product Category Tree plugin <= 2.5 versions.

  • CVE-2023-25476HigOct 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ezoic AmpedSense – AdSense Split Tester plugin <= 4.68 versions.

  • CVE-2023-42319HigOct 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a crafted GraphQL query. NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand…

  • CVE-2023-5538HigOct 18, 2023
    risk 0.47cvss 7.2epss 0.01

    The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

  • CVE-2023-39331HigOct 18, 2023
    risk 0.49cvss 7.5epss 0.01

    A previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path traversal vulnerability arises because the implementation does not protect itself against the application overwriting built-in utility functions with user-defined…

  • CVE-2023-38552HigOct 18, 2023
    risk 0.49cvss 7.5epss 0.01

    When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This…

  • CVE-2023-5626HigOct 18, 2023
    risk 0.00cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16.

  • CVE-2023-5552HigOct 18, 2023
    risk 0.46cvss 7.1epss 0.01

    A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewall version 19.5 MR3 (19.5.3) and older, if the password type is set to “Specified by sender”.

  • CVE-2023-45811HigOct 17, 2023
    risk 0.46cvss 8.1epss 0.00

    Synchrony deobfuscator is a javascript cleaner & deobfuscator. A `__proto__` pollution vulnerability exists in versions before v2.4.4. Successful exploitation could lead to arbitrary code execution. A `__proto__` pollution vulnerability exists in the `LiteralMap` transformer…

  • CVE-2023-42507HigOct 17, 2023
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow vulnerability exists in OnSinView2 versions 2.0.1 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user open a specially crafted OnSinView2 project file.

  • CVE-2023-42506HigOct 17, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper restriction of operations within the bounds of a memory buffer issue exists in OnSinView2 versions 2.0.1 and earlier. If this vulnerability is exploited, information may be disclosed or arbitrary code may be executed by having a user open a specially crafted OnSinView2…