VYPR

CVEs

112,298 total · page 1081 of 2,246

  • CVE-2023-41715HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.01

    SonicOS post-authentication Improper Privilege Management vulnerability in the SonicOS SSL VPN Tunnel allows users to elevate their privileges inside the tunnel.

  • CVE-2023-41713HigOct 17, 2023
    risk 0.49cvss 7.5epss 0.01

    SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.

  • CVE-2023-36321HigOct 17, 2023
    risk 0.00cvss 7.5epss 0.01

    Connected Vehicle Systems Alliance (COVESA) up to v2.18.8 was discovered to contain a buffer overflow via the component /shared/dlt_common.c.

  • CVE-2023-41631HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.01

    eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the file upload function.

  • CVE-2023-41629HigOct 17, 2023
    risk 0.49cvss 7.5epss 0.01

    A lack of input sanitizing in the file download feature of eSST Monitoring v2.147.1 allows attackers to execute a path traversal.

  • CVE-2023-22108HigOct 17, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to…

  • CVE-2023-22102HigOct 17, 2023
    risk 0.54cvss 8.3epss 0.01

    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.1.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL…

  • CVE-2023-22101HigOct 17, 2023
    risk 0.53cvss 8.1epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via T3, IIOP to…

  • CVE-2023-22100HigOct 17, 2023
    risk 0.51cvss 7.9epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…

  • CVE-2023-22099HigOct 17, 2023
    risk 0.53cvss 8.2epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…

  • CVE-2023-22098HigOct 17, 2023
    risk 0.53cvss 8.2epss 0.01

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox…

  • CVE-2023-22094HigOct 17, 2023
    risk 0.51cvss 7.9epss 0.00

    Vulnerability in the MySQL Installer product of Oracle MySQL (component: Installer: General). Supported versions that are affected are Prior to 1.6.8. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Installer executes…

  • CVE-2023-22087HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in the Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2023-22086HigOct 17, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to…

  • CVE-2023-22085HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in the Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2023-22019HigOct 17, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP…

  • CVE-2023-37537HigOct 17, 2023
    risk 0.51cvss 7.8epss 0.00

    An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges.

  • CVE-2023-45907HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.00

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/delete.

  • CVE-2023-45906HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.00

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/user/add.

  • CVE-2023-45905HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.00

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/add.

  • CVE-2023-45904HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.00

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /variable/update.

  • CVE-2023-45903HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.00

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/label/delete.

  • CVE-2023-45902HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.00

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/attachment/delete.

  • CVE-2023-45901HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.00

    Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin\/category\/add.

  • CVE-2023-43959HigOct 17, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.

  • CVE-2023-20598HigOct 17, 2023
    risk 0.51cvss 7.8epss 0.00

    An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitrary code execution.

  • CVE-2023-44824HigOct 17, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component.

  • CVE-2023-45007HigOct 17, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Fotomoto plugin <= 1.2.8 versions.

  • CVE-2023-45006HigOct 17, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ByConsole WooODT Lite – WooCommerce Order Delivery or Pickup with Date Time Location plugin <= 2.4.6 versions.

  • CVE-2023-45004HigOct 17, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wp3sixty Woo Custom Emails plugin <= 2.2 versions.

  • CVE-2023-39902HigOct 17, 2023
    risk 0.46cvss 7.0epss 0.00

    A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family processors. Under certain conditions, a crafted Flattened Image Tree (FIT) format structure can be used to overwrite SPL memory, allowing…

  • CVE-2023-45003HigOct 17, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Arrow Plugins Social Feed | Custom Feed for Social Media Networks plugin <= 2.2.0 versions.

  • CVE-2023-45005HigOct 17, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Castos Seriously Simple Stats plugin <= 1.5.1 versions.

  • CVE-2023-41752HigOct 17, 2023
    risk 0.42cvss 7.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Traffic Server.This issue affects Apache Traffic Server: from 8.0.0 through 8.1.8, from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 8.1.9 or 9.2.3, which fixes the issue.

  • CVE-2023-39456HigOct 17, 2023
    risk 0.46cvss 7.5epss 0.53

    Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 9.2.3, which fixes the issue.

  • CVE-2023-45375HigOct 17, 2023
    risk 0.60cvss 8.8epss 0.38

    In the module "PireosPay" (pireospay) before version 1.7.10 from 01generator.com for PrestaShop, a guest can perform SQL injection via `PireosPayValidationModuleFrontController::postProcess().`

  • CVE-2023-45358HigOct 17, 2023
    risk 0.55cvss 8.5epss 0.00

    Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data…

  • CVE-2023-34210HigOct 17, 2023
    risk 0.50cvss 7.7epss 0.01

    SQL Injection in create customer group function in EasyUse MailHunter Ultimate 2023 and earlier allow remote authenticated users to execute arbitrary SQL commands via the ctl00$ContentPlaceHolder1$txtCustSQL parameter.

  • CVE-2022-22375HigOct 17, 2023
    risk 0.47cvss 7.2epss 0.01

    IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 221681.

  • CVE-2023-30991HigOct 16, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 254037.

  • CVE-2023-45131HigOct 16, 2023
    risk 0.52cvss 7.5epss 0.02

    Discourse is an open source platform for community discussion. New chat messages can be read by making an unauthenticated POST request to MessageBus. This issue is patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse. Users are advised to upgrade. There are no known…

  • CVE-2023-44388HigOct 16, 2023
    risk 0.49cvss 7.5epss 0.01

    Discourse is an open source platform for community discussion. A malicious request can cause production log files to quickly fill up and thus result in the server running out of disk space. This problem has been patched in the 3.1.1 stable and 3.2.0.beta2 versions of Discourse.…

  • CVE-2023-43659HigOct 16, 2023
    risk 0.52cvss 8.0epss 0.00

    Discourse is an open source platform for community discussion. Improper escaping of user input allowed for Cross-site Scripting attacks via the digest email preview UI. This issue only affects sites with CSP disabled. This issue has been patched in the 3.1.1 stable release as…

  • CVE-2023-43658HigOct 16, 2023
    risk 0.00cvss 8.0epss 0.01

    dicourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar in the first post of a topic. Improper escaping of event titles could lead to Cross-site Scripting (XSS) within the 'email preview' UI when a site has CSP…

  • CVE-2023-45141HigOct 16, 2023
    risk 0.49cvss 8.6epss 0.00

    Fiber is an express inspired web framework written in Go. A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the application, which allows an attacker to obtain tokens and forge malicious requests on behalf of a user. This can lead to unauthorized actions…

  • CVE-2023-42459HigOct 16, 2023
    risk 0.00cvss 8.6epss 0.01

    Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). In affected versions specific DATA submessages can be sent to a discovery locator which may trigger a free error. This can remotely crash any Fast-DDS process.…

  • CVE-2023-5133HigOct 16, 2023
    risk 0.49cvss 7.5epss 0.01

    This user-activity-log-pro WordPress plugin before 2.3.4 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.

  • CVE-2023-5003HigOct 16, 2023
    risk 0.51cvss 7.5epss 0.26

    The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to…

  • CVE-2023-4971HigOct 16, 2023
    risk 0.47cvss 7.2epss 0.01

    The Weaver Xtreme Theme Support WordPress plugin before 6.3.1 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import a malicious file and a suitable gadget chain is present on the blog.

  • CVE-2023-4861HigOct 16, 2023
    risk 0.47cvss 7.2epss 0.01

    The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be able to gain full control of the server, such as a multisite installation. This leads to remote code execution.