VYPR

CVEs

112,283 total · page 1087 of 2,246

  • CVE-2023-44848HigOct 10, 2023
    risk 0.53cvss 8.1epss 0.01

    An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_template.php component.

  • CVE-2023-44847HigOct 10, 2023
    risk 0.47cvss 7.2epss 0.01

    An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component.

  • CVE-2023-44846HigOct 10, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ notify.php component.

  • CVE-2023-5463HigOct 9, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in XINJE XDPPro up to 3.7.17a. It has been rated as critical. Affected by this issue is some unknown functionality in the library cfgmgr32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The exploit has…

  • CVE-2023-43641HigOct 9, 2023
    risk 0.01cvss 8.8epss 0.17

    libcue provides an API for parsing and extracting data from CUE sheets. Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. A user of the GNOME desktop environment can be exploited by downloading a cue sheet from a malicious webpage. Because the file is saved…

  • CVE-2023-44811HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability in MooSocial v.3.1.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the admin Password Change Function.

  • CVE-2023-44392HigOct 9, 2023
    risk 0.00cvss 8.2epss 0.01

    Garden provides automation for Kubernetes development and testing. Prior tov ersions 0.13.17 and 0.12.65, Garden has a dependency on the cryo library, which is vulnerable to code injection due to an insecure implementation of deserialization. Garden stores serialized objects…

  • CVE-2023-42455HigOct 9, 2023
    risk 0.00cvss 8.8epss 0.01

    Wazuh is a security detection, visibility, and compliance open source project. In versions 4.4.0 and 4.4.1, it is possible to get the Wazuh API administrator key used by the Dashboard using the browser development tools. This allows a logged user to the dashboard to become…

  • CVE-2023-44378HigOct 9, 2023
    risk 0.39cvss 7.1epss 0.00

    gnark is a zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.9.0, for some in-circuit values, it is possible to construct two valid decomposition to bits. In addition to the canonical decomposition of `a`, for small values there exists a second…

  • CVE-2023-43698HigOct 9, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation (’Cross-site Scripting’) in RDT400 in SICK APU allows an unprivileged remote attacker to run arbitrary code in the clients browser via injecting code into the website.

  • CVE-2023-45248HigOct 9, 2023
    risk 0.47cvss 7.3epss 0.00

    Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 36497, Acronis Cyber Protect 16 (Windows) before build 37391.

  • CVE-2023-45247HigOct 9, 2023
    risk 0.46cvss 7.1epss 0.00

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 36497, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169.

  • CVE-2023-43700HigOct 9, 2023
    risk 0.50cvss 7.7epss 0.01

    Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authentication.

  • CVE-2023-43699HigOct 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APU allows an unprivileged remote attacker to guess the password via trial-and-error as the login attempts are not limited.

  • CVE-2023-43696HigOct 9, 2023
    risk 0.53cvss 8.2epss 0.01

    Improper Access Control in SICK APU allows an unprivileged remote attacker to download as well as upload arbitrary files via anonymous access to the FTP server.

  • CVE-2023-45612HigOct 9, 2023
    risk 0.56cvss 8.6epss 0.01

    In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE

  • CVE-2023-45371HigOct 9, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. There is no rate limit for merging items.

  • CVE-2023-45363HigOct 9, 2023
    risk 0.44cvss 7.5epss 0.23

    An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants…

  • CVE-2023-45356HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access, via dtb pages of the platform…

  • CVE-2023-45355HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 and 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access via the webservice. This…

  • CVE-2023-45354HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated remote attacker to execute arbitrary code on the operating system by using the Common Management Portal web interface. This is also known as OCMP-6589.

  • CVE-2023-45353HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system by leveraging the Common Management Portal web interface for Authenticated remote upload and creation of…

  • CVE-2023-45352HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to execute arbitrary code on the operating system via a Common Management Portal web interface Path traversal vulnerability allowing write access outside the…

  • CVE-2023-45351HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.1, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.42.1, and 4000 Manager V10 R0 allow Authenticated Command Injection via AShbr. This is also known as OSFOURK-24039.

  • CVE-2023-45350HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape 4000 Manager V10 R1 before V10 R1.42.1 and 4000 Manager V10 R0 allow Privilege escalation that may lead to the ability of an authenticated attacker to run arbitrary code via AScm. This is also known as OSFOURK-24034.

  • CVE-2023-45349HigOct 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.34.7, 4000 Assistant V10 R1.42.0, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.34.7, 4000 Manager V10 R1.42.0, and 4000 Manager V10 R0 expose sensitive information that may allow lateral movement to the backup…

  • CVE-2023-40635HigOct 8, 2023
    risk 0.51cvss 7.8epss 0.00

    In linkturbo, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-40634HigOct 8, 2023
    risk 0.51cvss 7.8epss 0.00

    In phasechecksercer, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed

  • CVE-2023-40632HigOct 8, 2023
    risk 0.49cvss 7.5epss 0.00

    In jpg driver, there is a possible use after free due to a logic error. This could lead to remote information disclosure no additional execution privileges needed

  • CVE-2023-43615HigOct 7, 2023
    risk 0.49cvss 7.5epss 0.01

    Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.

  • CVE-2023-36123HigOct 7, 2023
    risk 0.51cvss 7.8epss 0.01

    Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to execute arbitrary code and gain sensitive information.

  • CVE-2023-44860HigOct 6, 2023
    risk 0.50cvss 7.5epss 0.20

    An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization component in the HTTP request.

  • CVE-2023-44061HigOct 6, 2023
    risk 0.57cvss 8.8epss 0.01

    File Upload vulnerability in Simple and Nice Shopping Cart Script v.1.0 allows a remote attacker to execute arbitrary code via the upload function in the edit profile component.

  • CVE-2023-3725HigOct 6, 2023
    risk 0.49cvss 7.6epss 0.01

    Potential buffer overflow vulnerability in the Zephyr CAN bus subsystem

  • CVE-2023-45303HigOct 6, 2023
    risk 0.55cvss 8.4epss 0.01

    ThingsBoard before 3.5 allows Server-Side Template Injection if users are allowed to modify an email template, because Apache FreeMarker supports freemarker.template.utility.Execute (for content sent to the /api/admin/settings endpoint).

  • CVE-2023-45282HigOct 6, 2023
    risk 0.42cvss 7.5epss 0.01

    In NASA Open MCT (aka openmct) before 3.1.0, prototype pollution can occur via an import action.

  • CVE-2023-21266HigOct 6, 2023
    risk 0.51cvss 7.8epss 0.00

    In multiple functions of ActivityManagerService.java, there is a possible way to escape Google Play protection due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-5366HigOct 6, 2023
    risk 0.46cvss 7.1epss 0.00

    A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect…

  • CVE-2023-23366HigOct 6, 2023
    risk 0.50cvss 7.7epss 0.01

    A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-23365HigOct 6, 2023
    risk 0.50cvss 7.7epss 0.01

    A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-39928HigOct 6, 2023
    risk 0.57cvss 8.8epss 0.01

    A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger…

  • CVE-2023-43810HigOct 6, 2023
    risk 0.42cvss 7.5epss 0.01

    OpenTelemetry, also known as OTel for short, is a vendor-neutral open-source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, logs. Autoinstrumentation out of the box adds the label `http_method` that has…

  • CVE-2023-35897HigOct 6, 2023
    risk 0.55cvss 8.4epss 0.00

    IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary code on the system using a specially crafted file, caused by a DLL hijacking flaw. IBM X-Force ID: 259246.

  • CVE-2023-45246HigOct 6, 2023
    risk 0.46cvss 7.1epss 0.00

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 36343, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39169.

  • CVE-2023-45244HigOct 6, 2023
    risk 0.46cvss 7.1epss 0.00

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 35895, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 37391.

  • CVE-2023-26153HigOct 6, 2023
    risk 0.47cvss 8.3epss 0.03

    Versions of the package geokit-rails before 2.5.0 are vulnerable to Command Injection due to unsafe deserialisation of YAML within the 'geo_location' cookie. This issue can be exploited remotely via a malicious cookie value. **Note:** An attacker can use this vulnerability to…

  • CVE-2023-44212HigOct 5, 2023
    risk 0.46cvss 7.1epss 0.00

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 31477.

  • CVE-2023-44211HigOct 5, 2023
    risk 0.46cvss 7.1epss 0.00

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 31637, Acronis Cyber Protect 16 (Linux, Windows) before build 37391.

  • CVE-2023-39323HigOct 5, 2023
    risk 0.53cvss 8.1epss 0.02

    Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". The line directive requires…

  • CVE-2023-43284HigOct 5, 2023
    risk 0.57cvss 8.8epss 0.02

    D-Link Wireless MU-MIMO Gigabit AC1200 Router DIR-846 100A53DBR-Retail devices allow an authenticated remote attacker to execute arbitrary code via an unspecified manipulation of the QoS POST parameter.