VYPR

CVEs

112,298 total · page 1083 of 2,246

  • CVE-2023-38220HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Improper Authorization vulnerability that could lead in a security feature bypass in a way that an attacker could access unauthorised…

  • CVE-2023-38219HigOct 13, 2023
    risk 0.57cvss 8.7epss 0.01

    Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into…

  • CVE-2023-38218HigOct 13, 2023
    risk 0.57cvss 8.8epss 0.01

    Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Incorrect Authorization . An authenticated attacker can exploit this to achieve information exposure and privilege escalation.

  • CVE-2023-5557HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.

  • CVE-2023-5563HigOct 13, 2023
    risk 0.46cvss 7.1epss 0.00

    The SJA1000 CAN controller driver backend automatically attempt to recover from a bus-off event when built with CONFIG_CAN_AUTO_BUS_OFF_RECOVERY=y. This results in calling k_sleep() in IRQ context, causing a fatal exception.

  • CVE-2023-44199HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). On Junos MX Series platforms with…

  • CVE-2023-44197HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An Out-of-Bounds Write vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On all Junos OS and Junos OS Evolved devices an rpd crash and…

  • CVE-2023-44194HigOct 13, 2023
    risk 0.55cvss 8.4epss 0.00

    An Incorrect Default Permissions vulnerability in Juniper Networks Junos OS allows an unauthenticated attacker with local access to the device to create a backdoor with root privileges. The issue is caused by improper directory permissions on a certain system directory,…

  • CVE-2023-44192HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause memory leak, leading to Denial of Service (DoS). On all Junos OS QFX5000 Series platforms, when pseudo-VTEP…

  • CVE-2023-44191HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On all Junos OS QFX5000 Series and EX4000 Series platforms, when a high number of VLANs are…

  • CVE-2023-44185HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An Improper Input Validation vulnerability in the routing protocol daemon (rpd) of Juniper Networks allows an attacker to cause a Denial of Service (DoS )to the device upon receiving and processing a specific malformed ISO VPN BGP UPDATE packet. Continued receipt of this…

  • CVE-2023-44182HigOct 13, 2023
    risk 0.47cvss 7.3epss 0.01

    An Unchecked Return Value vulnerability in the user interfaces to the Juniper Networks Junos OS and Junos OS Evolved, the CLI, the XML API, the XML Management Protocol, the NETCONF Management Protocol, the gNMI interfaces, and the J-Web User Interfaces causes unintended effects…

  • CVE-2023-44181HigOct 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An Improperly Implemented Security Check for Standard vulnerability in storm control of Juniper Networks Junos OS QFX5k devices allows packets to be punted to ARP queue causing a l2 loop resulting in a DDOS violations and DDOS syslog. This issue is triggered when Storm control…

  • CVE-2023-36843HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.01

    An Improper Handling of Inconsistent Special Elements vulnerability in the Junos Services Framework (jsf) module of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a crash in the Packet Forwarding Engine (pfe) and thereby resulting in a…

  • CVE-2023-36841HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.01

    An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows a unauthenticated network-based attacker to cause an infinite loop, resulting in a Denial of Service (DoS). An attacker…

  • CVE-2023-27316HigOct 12, 2023
    risk 0.57cvss 8.8epss 0.00

    SnapCenter versions 4.8 through 4.9 are susceptible to a vulnerability which may allow an authenticated SnapCenter Server user to become an admin user on a remote system where a SnapCenter plug-in has been installed.

  • CVE-2023-45510HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.01

    tsMuxer version git-2539d07 was discovered to contain an alloc-dealloc-mismatch (operator new [] vs operator delete) error.

  • CVE-2023-23632HigOct 12, 2023
    risk 0.51cvss 7.8epss 0.00

    BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing unauthorized access to jump items by guessing only the first…

  • CVE-2023-43148HigOct 12, 2023
    risk 0.53cvss 8.1epss 0.00

    SPA-Cart 1.9.0.3 has a Cross Site Request Forgery (CSRF) vulnerability that allows a remote attacker to delete all accounts.

  • CVE-2023-27314HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.01

    ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 and 9.13.1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to cause a crash of the HTTP service.

  • CVE-2023-27313HigOct 12, 2023
    risk 0.54cvss 8.3epss 0.01

    SnapCenter versions 3.x and 4.x prior to 4.9 are susceptible to a vulnerability which may allow an authenticated unprivileged user to gain access as an admin user.

  • CVE-2023-43149HigOct 12, 2023
    risk 0.57cvss 8.8epss 0.01

    SPA-Cart 1.9.0.3 is vulnerable to Cross Site Request Forgery (CSRF) that allows a remote attacker to add an admin user with role status.

  • CVE-2023-5072HigOct 12, 2023
    risk 0.42cvss 7.5epss 0.01

    Denial of Service in JSON-Java versions up to and including 20230618.  A bug in the parser means that an input string of modest size can lead to indefinite amounts of memory being used.

  • CVE-2023-45142HigOct 12, 2023
    risk 0.42cvss 7.5epss 0.01

    OpenTelemetry-Go Contrib is a collection of third-party packages for OpenTelemetry-Go. A handler wrapper out of the box adds labels `http.user_agent` and `http.method` that have unbound cardinality. It leads to the server's potential memory exhaustion when many malicious…

  • CVE-2023-43147HigOct 12, 2023
    risk 0.57cvss 8.8epss 0.00

    PHPJabbers Limo Booking Software 1.0 is vulnerable to Cross Site Request Forgery (CSRF) to add an admin user via the Add Users Function, aka an index.php?controller=pjAdminUsers&action=pjActionCreate URI.

  • CVE-2023-32634HigOct 12, 2023
    risk 0.51cvss 7.8epss 0.00

    An authentication bypass vulnerability exists in the CiRpcServerThread() functionality of SoftEther VPN 5.01.9674 and 4.41-9782-beta. An attacker can perform a local man-in-the-middle attack to trigger this vulnerability.

  • CVE-2023-27516HigOct 12, 2023
    risk 0.47cvss 7.3epss 0.01

    An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. A specially crafted network packet can lead to unauthorized access. An attacker can send a network request to trigger this vulnerability.

  • CVE-2023-25774HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.01

    A denial-of-service vulnerability exists in the vpnserver ConnectionAccept() functionality of SoftEther VPN 5.02. A set of specially crafted network connections can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.

  • CVE-2023-23581HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.01

    A denial-of-service vulnerability exists in the vpnserver EnSafeHttpHeaderValueStr functionality of SoftEther VPN 5.01.9674 and 5.02. A specially crafted network packet can lead to denial of service.

  • CVE-2023-22308HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.01

    An integer underflow vulnerability exists in the vpnserver OvsProcessData functionality of SoftEther VPN 5.01.9674 and 5.02. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-23651HigOct 12, 2023
    risk 0.55cvss 8.5epss 0.01

    Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP Google Analytics Extension plugin <= 4.0.4 versions.

  • CVE-2023-45047HigOct 12, 2023
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in LeadSquared, Inc LeadSquared Suite plugin <= 0.7.4 versions.

  • CVE-2023-32723HigOct 12, 2023
    risk 0.55cvss 8.5epss 0.01

    Request to LDAP is sent before user permissions are checked.

  • CVE-2023-32721HigOct 12, 2023
    risk 0.49cvss 7.6epss 0.01

    A stored XSS has been found in the Zabbix web application in the Maps element if a URL field is set with spaces before URL.

  • CVE-2023-40829HigOct 12, 2023
    risk 0.49cvss 7.5epss 0.00

    There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5.x and 2.6.930000.

  • CVE-2023-1943HigOct 12, 2023
    risk 0.52cvss 8.0epss 0.01

    Privilege Escalation in kOps using GCE/GCP Provider in Gossip Mode.

  • CVE-2023-5476HigOct 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Blink History in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-5474HigOct 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Heap buffer overflow in PDF in Google Chrome prior to 118.0.5993.70 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium)

  • CVE-2023-5218HigOct 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2023-39325HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.04

    A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the…

  • CVE-2023-44186HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An Improper Handling of Exceptional Conditions vulnerability in AS PATH processing of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a BGP update message with an AS PATH containing a large number of 4-byte ASes, leading to a Denial of Service (DoS).…

  • CVE-2023-3781HigOct 11, 2023
    risk 0.51cvss 7.8epss 0.00

    there is a possible use-after-free write due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-5535HigOct 11, 2023
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to v9.0.2010.

  • CVE-2023-43661HigOct 11, 2023
    risk 0.54cvss 8.8epss 0.47

    Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows users to create templates allows them to execute any code on the server during the bad filtration and old twig version. Commit 6fb043e109d2a262ce3974e863c54e9e5f5e0587 of…

  • CVE-2023-40142HigOct 11, 2023
    risk 0.51cvss 7.8epss 0.00

    In TBD of TBD, there is a possible way to bypass carrier restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40141HigOct 11, 2023
    risk 0.51cvss 7.8epss 0.00

    In temp_residency_name_store of thermal_metrics.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-35661HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.00

    In ProfSixDecomTcpSACKoption of RohcPacketCommon.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-35652HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.00

    In ProtocolEmergencyCallListIndAdapter::Init of protocolcalladapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with baseband firmware compromise required. User interaction is not needed for…

  • CVE-2023-35649HigOct 11, 2023
    risk 0.47cvss 7.2epss 0.00

    In several functions of Exynos modem files, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-44961HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability in Koha Library Software 23.0.5.04 and before allows a remote attacker to obtain sensitive information via the intranet/cgi bin/cataloging/ysearch.pl. component.