VYPR

CVEs

112,283 total · page 1088 of 2,246

  • CVE-2023-5346HigOct 5, 2023
    risk 0.57cvss 8.8epss 0.02

    Type confusion in V8 in Google Chrome prior to 117.0.5938.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-4401HigOct 5, 2023
    risk 0.51cvss 7.8epss 0.01

    Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the CLI use of the ‘more’ command. A local or remote authenticated attacker could potentially exploit this vulnerability, leading to the ability to gain root-level access.…

  • CVE-2023-43069HigOct 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell SmartFabric Storage Software v1.4 (and earlier) contain(s) an OS Command Injection Vulnerability in the CLI. An authenticated local attacker could potentially exploit this vulnerability, leading to possible injection of parameters to curl or docker.

  • CVE-2023-43068HigOct 5, 2023
    risk 0.51cvss 7.8epss 0.01

    Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the restricted shell in SSH. An authenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands.

  • CVE-2023-4570HigOct 5, 2023
    risk 0.50cvss 8.8epss 0.00

    An improper access restriction in NI MeasurementLink Python services could allow an attacker on an adjacent network to reach services exposed on localhost. These services were previously thought to be unreachable outside of the node. This affects measurement plug-ins written…

  • CVE-2023-45160HigOct 5, 2023
    risk 0.57cvss 8.8epss 0.01

    In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script. by replacing a resource script file created by an instruction at run time with a malicious script. The 1E Client's temporary…

  • CVE-2023-44839HigOct 5, 2023
    risk 0.49cvss 7.5epss 0.08

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Encryption parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-44838HigOct 5, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the TXPower parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-44837HigOct 5, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Password parameter in the SetWanSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-44836HigOct 5, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the SSID parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-44835HigOct 5, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Mac parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-44834HigOct 5, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the StartTime parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-44833HigOct 5, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the GuardInt parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-44832HigOct 5, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the MacAddress parameter in the SetWanSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-44831HigOct 5, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the Type parameter in the SetWLanRadioSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-44830HigOct 5, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the EndTime parameter in the SetParentsControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-44829HigOct 5, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the AdminPassword parameter in the SetDeviceSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-44828HigOct 5, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-823G A1V1.0.2B05 was discovered to contain a buffer overflow via the CurrentPassword parameter in the CheckPasswdSettings function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2023-45159HigOct 5, 2023
    risk 0.55cvss 8.4epss 0.00

    1E Client installer can perform arbitrary file deletion on protected files.   A non-privileged user could provide a symbolic link or Windows junction to point to a protected directory in the installer that the 1E Client would then clear on service startup. A hotfix is…

  • CVE-2023-45198HigOct 5, 2023
    risk 0.49cvss 7.5epss 0.00

    ftpd before "NetBSD-ftpd 20230930" can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.

  • CVE-2023-26236HigOct 5, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGuard EPDR processes, it is possible to perform a Local Privilege Escalation on Windows by sending a crafted message to a named pipe.

  • CVE-2023-43321HigOct 4, 2023
    risk 0.57cvss 8.8epss 0.01

    File Upload vulnerability in Digital China Networks DCFW-1800-SDC v.3.0 allows an authenticated attacker to execute arbitrary code via the wget function in the /sbin/cloudadmin.sh component.

  • CVE-2023-40299HigOct 4, 2023
    risk 0.00cvss 7.8epss 0.00

    Kong Insomnia 2023.4.0 on macOS allows attackers to execute code and access restricted files, or make requests for TCC permissions, by using the DYLD_INSERT_LIBRARIES environment variable.

  • CVE-2023-43809HigOct 4, 2023
    risk 0.42cvss 7.5epss 0.01

    Soft Serve is a self-hostable Git server for the command line. Prior to version 0.6.2, a security vulnerability in Soft Serve could allow an unauthenticated, remote attacker to bypass public key authentication when keyboard-interactive SSH authentication is active, through the…

  • CVE-2023-43805HigOct 4, 2023
    risk 0.00cvss 7.5epss 0.01

    Nexkey is a fork of Misskey, an open source, decentralized social media platform. Prior to version 12.121.9, incomplete URL validation can allow users to bypass authentication for access to the job queue dashboard. Version 12.121.9 contains a fix for this issue. As a workaround,…

  • CVE-2023-43793HigOct 4, 2023
    risk 0.00cvss 7.5epss 0.01

    Misskey is an open source, decentralized social media platform. Prior to version 2023.9.0, by editing the URL, a user can bypass the authentication of the Bull dashboard, which is the job queue management UI, and access it. Version 2023.9.0 contains a fix. There are no known…

  • CVE-2023-36618HigOct 4, 2023
    risk 0.57cvss 8.8epss 0.03

    Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-privileged authenticated users.

  • CVE-2023-44209HigOct 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 29051, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186.

  • CVE-2023-42449HigOct 4, 2023
    risk 0.53cvss 8.1epss 0.01

    Hydra is the two-layer scalability solution for Cardano. Prior to version 0.13.0, it is possible for a malicious head initializer to extract one or more PTs for the head they are initializing due to incorrect data validation logic in the head token minting policy which then…

  • CVE-2023-42824HigKEVOct 4, 2023
    risk 0.63cvss 7.8epss 0.01

    The issue was addressed with improved checks. This issue is fixed in iOS 16.7.1 and iPadOS 16.7.1. A local attacker may be able to elevate their privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.6.

  • CVE-2023-42448HigOct 4, 2023
    risk 0.00cvss 8.1epss 0.01

    Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, the specification states that the contestation period in the datum of the UTxO at the head validator must stay unchanged as the state progresses from Open to Closed (Close transaction), but no such…

  • CVE-2023-39191HigOct 4, 2023
    risk 0.53cvss 8.2epss 0.01

    An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF privileges to…

  • CVE-2023-20259HigOct 4, 2023
    risk 0.56cvss 8.6epss 0.01

    A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU utilization, which could impact access to the web-based management interface and cause delays with call processing. This API is…

  • CVE-2023-43838HigOct 4, 2023
    risk 0.51cvss 7.8epss 0.01

    An arbitrary file upload vulnerability in Personal Management System v1.4.64 allows attackers to execute arbitrary code via uploading a crafted SVG file into a user profile's avatar.

  • CVE-2023-4237HigOct 4, 2023
    risk 0.47cvss 7.3epss 0.00

    A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the log files, compromising the system's confidentiality,…

  • CVE-2023-3971HigOct 4, 2023
    risk 0.48cvss 7.3epss 0.01

    An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.

  • CVE-2023-5373HigOct 4, 2023
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected is the function register of the file Master.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely.…

  • CVE-2023-43261HigOct 4, 2023
    risk 0.53cvss 7.5epss 0.59

    An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.

  • CVE-2023-3361HigOct 4, 2023
    risk 0.50cvss 7.7epss 0.00

    A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in plain text in the generated output instead of an ID for a…

  • CVE-2023-3037HigOct 4, 2023
    risk 0.56cvss 8.6epss 0.01

    Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote attacker to access the platform without authentication and retrieve personal data via the jsonGrid parameter.

  • CVE-2023-22618HigOct 4, 2023
    risk 0.53cvss 8.1epss 0.00

    If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privileges by manipulating a web request. This affects (for example) WaveLite Metro 200 and Fan, WaveLite Metro 200 OPS and Fans, WaveLite…

  • CVE-2023-4997HigOct 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Improper authorisation of regular users in ProIntegra Uptime DC software (versions below 2.0.0.33940) allows them to change passwords of all other users including administrators leading to a privilege escalation.

  • CVE-2023-4586HigOct 4, 2023
    risk 0.48cvss 7.4epss 0.00

    A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack.

  • CVE-2023-3512HigOct 4, 2023
    risk 0.49cvss 7.5epss 0.01

    Relative path traversal vulnerability in Setelsa Security's ConacWin CB, in its 3.8.2.2 version and earlier, the exploitation of which could allow an attacker to perform an arbitrary download of files from the system via the "Download file" parameter.

  • CVE-2023-2809HigOct 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version, the exploitation of which could allow a remote attacker to extract SQL database credentials from the DLL application. This vulnerability could be linked to known techniques to obtain remote execution…

  • CVE-2023-1584HigOct 4, 2023
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Quarkus. Quarkus OIDC can leak both ID and access tokens in the authorization code flow when an insecure HTTP protocol is used, which can allow attackers to access sensitive user data directly from the ID token or by using the access token to access user data…

  • CVE-2023-5377HigOct 4, 2023
    risk 0.00cvss 7.1epss 0.00

    Out-of-bounds Read in GitHub repository gpac/gpac prior to v2.2.2-DEV.

  • CVE-2023-5369HigOct 4, 2023
    risk 0.46cvss 7.1epss 0.00

    Before correction, the copy_file_range system call checked only for the CAP_READ and CAP_WRITE capabilities on the input and output file descriptors, respectively. Using an offset is logically equivalent to seeking, and the system call must additionally require the CAP_SEEK…

  • CVE-2023-30733HigOct 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Stack-based Buffer Overflow in vulnerability HDCP trustlet prior to SMR Oct-2023 Release 1 allows local privileged attackers to perform code execution.

  • CVE-2023-30692HigOct 4, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.