VYPR

CVEs

112,298 total · page 1082 of 2,246

  • CVE-2023-4776HigOct 16, 2023
    risk 0.57cvss 8.8epss 0.01

    The School Management System WordPress plugin before 2.2.5 uses the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query, leading to a SQL injection exploitable by relatively low-privilege users like Teachers.

  • CVE-2023-4691HigOct 16, 2023
    risk 0.47cvss 7.2epss 0.01

    The WordPress Online Booking and Scheduling Plugin WordPress plugin before 22.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

  • CVE-2023-4643HigOct 16, 2023
    risk 0.57cvss 8.8epss 0.01

    The Enable Media Replace WordPress plugin before 4.1.3 unserializes user input via the Remove Background feature, which could allow Author+ users to perform PHP Object Injection when a suitable gadget is present on the blog

  • CVE-2023-43121HigOct 16, 2023
    risk 0.49cvss 7.5epss 0.01

    A Directory Traversal vulnerability discovered in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7, and before 31.7.2 allows attackers to read arbitrary files.

  • CVE-2023-43118HigOct 16, 2023
    risk 0.57cvss 8.8epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, fixed in 31.7.2 and 32.5.1.5 allows attackers to run arbitrary code and cause other unspecified impacts via /jsonrpc API.

  • CVE-2023-3155HigOct 16, 2023
    risk 0.47cvss 7.2epss 0.01

    The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.

  • CVE-2023-3154HigOct 16, 2023
    risk 0.49cvss 7.5epss 0.01

    The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.

  • CVE-2023-45683HigOct 16, 2023
    risk 0.39cvss 7.1epss 0.00

    github.com/crewjam/saml is a saml library for the go language. In affected versions the package does not validate the ACS Location URI according to the SAML binding being parsed. If abused, this flaw allows attackers to register malicious Service Providers at the IdP and inject…

  • CVE-2023-43120HigOct 16, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attackers to gain escalated privileges via crafted HTTP request.

  • CVE-2023-40180HigOct 16, 2023
    risk 0.42cvss 7.5epss 0.01

    silverstripe-graphql is a package which serves Silverstripe data in GraphQL representations. An attacker could use a recursive graphql query to execute a Distributed Denial of Service attack (DDOS attack) against a website. This mostly affects websites with publicly exposed…

  • CVE-2023-45985HigOct 16, 2023
    risk 0.49cvss 7.5epss 0.01

    TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 were discovered to contain a stack overflow in the function setParentalRules. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2023-45687HigOct 16, 2023
    risk 0.57cvss 8.8epss 0.01

    A session fixation vulnerability in South River Technologies' Titan MFT and Titan SFTP servers on Linux and Windows allows an attacker to bypass the server's authentication if they can trick an administrator into authorizating a session id of their choosing

  • CVE-2023-45686HigOct 16, 2023
    risk 0.47cvss 7.2epss 0.01

    Insufficient path validation when writing a file via WebDAV in South River Technologies' Titan MFT and Titan SFTP servers on Linux allows an authenticated attacker to write a file to any location on the filesystem via path traversal

  • CVE-2023-5422HigOct 16, 2023
    risk 0.57cvss 8.7epss 0.00

    The functions to fetch e-mail via POP3 or IMAP as well as sending e-mail via SMTP use OpenSSL for static SSL or TLS based communication. As the SSL_get_verify_result() function is not used the certificated is trusted always and it can not be ensured that the certificate …

  • CVE-2023-4827HigOct 16, 2023
    risk 0.58cvss 8.8epss 0.07

    The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users perform unwanted file system actions via CSRF attacks by using GET requests, such as uploading a web…

  • CVE-2023-43667HigOct 16, 2023
    risk 0.42cvss 7.5epss 0.01

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create misleading or false log records, making it harder to audit and…

  • CVE-2023-3392HigOct 16, 2023
    risk 0.47cvss 7.2epss 0.01

    The Read More & Accordion WordPress plugin before 3.2.7 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

  • CVE-2023-21414HigOct 16, 2023
    risk 0.46cvss 7.1epss 0.00

    NCC Group has found a flaw during the annual internal penetration test ordered by Axis Communications. The protection for device tampering (commonly known as Secure Boot) contains a flaw which provides an opportunity for a sophisticated attack to bypass this protection. Axis has…

  • CVE-2023-45898HigOct 16, 2023
    risk 0.51cvss 7.8epss 0.00

    The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.

  • CVE-2023-38280HigOct 16, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 260740.

  • CVE-2023-5590HigOct 15, 2023
    risk 0.00cvss 7.5epss 0.01

    NULL Pointer Dereference in GitHub repository seleniumhq/selenium prior to 4.14.0.

  • CVE-2023-5589HigOct 15, 2023
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Judging Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument password leads to sql injection. The attack can be initiated remotely. The…

  • CVE-2023-38312HigOct 15, 2023
    risk 0.49cvss 7.5epss 0.01

    A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbitrary files from the underlying server via the motdfile console variable.

  • CVE-2023-5586HigOct 15, 2023
    risk 0.00cvss 7.8epss 0.00

    NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.3.0-DEV.

  • CVE-2023-45871HigOct 15, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in drivers/net/ethernet/intel/igb/igb_main.c in the IGB driver in the Linux kernel before 6.5.3. A buffer size may not be adequate for frames larger than the MTU.

  • CVE-2022-43740HigOct 14, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Security Verify Access OIDC Provider could allow a remote user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 238921.

  • CVE-2023-45855HigOct 14, 2023
    risk 0.49cvss 7.5epss 0.03

    qdPM 9.2 allows Directory Traversal to list files and directories by navigating to the /uploads URI.

  • CVE-2023-44037HigOct 14, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue in ZPE Systems, Inc Nodegrid OS v.5.8.10 thru v.5.8.13 and v.5.10.3 thru v.5.10.5 allows a remote attacker to obtain sensitive information via the TACACS+ server component.

  • CVE-2023-26155HigOct 14, 2023
    risk 0.48cvss 7.3epss 0.02

    All versions of the package node-qpdf are vulnerable to Command Injection such that the package-exported method encrypt() fails to sanitize its parameter input, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once…

  • CVE-2023-45674HigOct 14, 2023
    risk 0.50cvss 7.7epss 0.01

    Farmbot-Web-App is a web control interface for the Farmbot farm automation platform. An SQL injection vulnerability was found in FarmBot's web app that allows authenticated attackers to extract arbitrary data from its database (including the user table). This issue may lead to…

  • CVE-2023-4257HigOct 13, 2023
    risk 0.49cvss 7.6epss 0.01

    Unchecked user input length in /subsys/net/l2/wifi/wifi_shell.c can cause buffer overflows.

  • CVE-2023-4263HigOct 13, 2023
    risk 0.49cvss 7.6epss 0.00

    Potential buffer overflow vulnerability in the Zephyr IEEE 802.15.4 nRF 15.4 driver

  • CVE-2023-32974HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the…

  • CVE-2023-4499HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability.

  • CVE-2023-41843HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.00

    A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions,…

  • CVE-2023-41682HigOct 13, 2023
    risk 0.53cvss 8.1epss 0.01

    A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all…

  • CVE-2023-41681HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.00

    A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions,…

  • CVE-2023-41680HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.00

    A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions,…

  • CVE-2023-33303HigOct 13, 2023
    risk 0.53cvss 8.1epss 0.00

    A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api request

  • CVE-2023-5240HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.

  • CVE-2023-45468HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Netis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the pingWdogIp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-45464HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Netis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the servDomain parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-45463HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Netis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the hostName parameter in the FUN_0040dabc function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-45130HigOct 13, 2023
    risk 0.00cvss 7.5epss 0.01

    Frontier is Substrate's Ethereum compatibility layer. Prior to commit aea528198b3b226e0d20cce878551fd4c0e3d5d0, at the end of a contract execution, when opcode SUICIDE marks a contract to be deleted, the software uses `storage::remove_prefix` (now renamed to…

  • CVE-2023-29464HigOct 13, 2023
    risk 0.54cvss 8.2epss 0.10

    FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure.…

  • CVE-2023-43079HigOct 13, 2023
    risk 0.47cvss 7.3epss 0.00

    Dell OpenManage Server Administrator, versions 11.0.0.0 and prior, contains an Improper Access Control vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to execute arbitrary code in order to elevate privileges on the…

  • CVE-2023-5571HigOct 13, 2023
    risk 0.42cvss 7.5epss 0.01

    Improper Input Validation in GitHub repository vriteio/vrite prior to 0.3.0.

  • CVE-2023-38250HigOct 13, 2023
    risk 0.52cvss 8.0epss 0.01

    Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead in arbitrary code…

  • CVE-2023-38249HigOct 13, 2023
    risk 0.52cvss 8.0epss 0.01

    Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead in arbitrary code…

  • CVE-2023-38221HigOct 13, 2023
    risk 0.52cvss 8.0epss 0.01

    Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead in arbitrary code…