VYPR

CVEs

112,283 total · page 1090 of 2,246

  • CVE-2023-43835HigOct 2, 2023
    risk 0.57cvss 8.8epss 0.01

    Super Store Finder 3.7 and below is vulnerable to authenticated Arbitrary PHP Code Injection that could lead to Remote Code Execution when settings overwrite config.inc.php content.

  • CVE-2023-3769HigOct 2, 2023
    risk 0.56cvss 8.6epss 0.01

    Incorrect data input validation vulnerability, which could allow an attacker with access to the network to implement fuzzing techniques that would allow him to gain knowledge about specially crafted packets that would create a DoS condition through the MMS protocol when…

  • CVE-2023-41580HigOct 2, 2023
    risk 0.00cvss 7.5epss 0.01

    Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server and access sensitive data via a crafted POST request.

  • CVE-2023-5106HigOct 2, 2023
    risk 0.00cvss 8.2epss 0.01

    An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.

  • CVE-2023-3768HigOct 2, 2023
    risk 0.56cvss 8.6epss 0.01

    Incorrect data input validation vulnerability, which could allow an attacker with access to the network to implement fuzzing techniques that would allow him to gain knowledge about specially crafted packets that would create a DoS condition through the MMS protocol when…

  • CVE-2023-44245HigOct 2, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Leap Contractor Contact Form Website to Workflow Tool plugin <= 4.0.0 versions.

  • CVE-2023-44144HigOct 2, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Dreamfox Payment gateway per Product for WooCommerce plugin <= 3.2.7 versions.

  • CVE-2023-44474HigOct 2, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MD Jakir Hosen Tiger Forms – Drag and Drop Form Builder plugin <= 2.0.0 versions.

  • CVE-2023-44244HigOct 2, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FooPlugins FooGallery plugin <= 2.2.44 versions.

  • CVE-2023-41856HigOct 2, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ClickToTweet.Com Click To Tweet plugin <= 2.0.14 versions.

  • CVE-2023-41692HigOct 2, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Hennessey Digital Attorney theme <= 3 theme.

  • CVE-2023-32820HigOct 2, 2023
    risk 0.49cvss 7.5epss 0.00

    In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07932637; Issue ID: ALPS07932637.

  • CVE-2023-43907HigOct 1, 2023
    risk 0.51cvss 7.8epss 0.01

    OptiPNG v0.7.7 was discovered to contain a global buffer overflow via the 'buffer' variable at gifread.c.

  • CVE-2023-44488HigSep 30, 2023
    risk 0.00cvss 7.5epss 0.02

    VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.

  • CVE-2022-4956HigSep 30, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability classified as critical has been found in Caphyon Advanced Installer 19.7. This affects an unknown part of the component WinSxS DLL Handler. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to…

  • CVE-2023-5207HigSep 30, 2023
    risk 0.53cvss 8.2epss 0.01

    A vulnerability was discovered in GitLab CE and EE affecting all versions starting 16.0 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. An authenticated attacker could perform arbitrary pipeline execution under the context of another user.

  • CVE-2023-5318HigSep 30, 2023
    risk 0.42cvss 7.5epss 0.01

    Use of Hard-coded Credentials in GitHub repository microweber/microweber prior to 2.0.

  • CVE-2022-35908HigSep 29, 2023
    risk 0.57cvss 8.8epss 0.01

    Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent.

  • CVE-2023-26218HigSep 29, 2023
    risk 0.52cvss 8.0epss 0.01

    The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected…

  • CVE-2023-39410HigSep 29, 2023
    risk 0.42cvss 7.5epss 0.02

    When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should…

  • CVE-2023-5289HigSep 29, 2023
    risk 0.50cvss 8.8epss 0.01

    Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.4.

  • CVE-2023-41691HigSep 29, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pensopay WooCommerce PensoPay plugin <= 6.3.1 versions.

  • CVE-2023-41663HigSep 29, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Giovambattista Fazioli WP Bannerize Pro plugin <= 1.6.9 versions.

  • CVE-2023-41662HigSep 29, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ulf Benjaminsson WP-dTree plugin <= 4.4.5 versions.

  • CVE-2023-41658HigSep 29, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Photo Gallery Slideshow & Masonry Tiled Gallery plugin <= 1.0.13 versions.

  • CVE-2023-39308HigSep 29, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.7 versions.

  • CVE-2023-32477HigSep 29, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-privileged malicious user may potentially exploit this vulnerability to gain elevated privileges.

  • CVE-2023-44466HigSep 29, 2023
    risk 0.04cvss 8.8epss 0.55

    An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of the AUTH frames. This occurs because of an untrusted length taken from a TCP…

  • CVE-2023-30591HigSep 29, 2023
    risk 0.04cvss 7.5epss 0.54

    Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name…

  • CVE-2023-44464HigSep 29, 2023
    risk 0.44cvss 7.8epss 0.00

    pretix before 2023.7.2 allows Pillow to parse EPS files.

  • CVE-2023-5077HigSep 29, 2023
    risk 0.49cvss 7.6epss 0.00

    The Vault and Vault Enterprise ("Vault") Google Cloud secrets engine did not preserve existing Google Cloud IAM Conditions upon creating or updating rolesets. Fixed in Vault 1.13.0.

  • CVE-2023-43662HigSep 28, 2023
    risk 0.01cvss 8.6epss 0.08

    ShokoServer is a media server which specializes in organizing anime. In affected versions the `/api/Image/WithPath` endpoint is accessible without authentication and is supposed to return default server images. The endpoint accepts the parameter `serverImagePath`, which is not…

  • CVE-2023-43014HigSep 28, 2023
    risk 0.57cvss 8.8epss 0.01

    Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'last_name' parameters of user.php page, allowing an authenticated attacker to dump all the contents of the database contents.

  • CVE-2023-4316HigSep 28, 2023
    risk 0.42cvss 7.5epss 0.01

    Zod in versions 3.21.0 up to and including 3.22.3 allows an attacker to perform a denial of service while validating emails.

  • CVE-2023-43740HigSep 28, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

  • CVE-2023-43226HigSep 28, 2023
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in dede/baidunews.php in DedeCMS 5.7.111 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2023-5256HigSep 28, 2023
    risk 0.42cvss 7.5epss 0.01

    In certain scenarios, Drupal's JSON:API module will output error backtraces. With some configurations, this may cause sensitive information to be cached and made available to anonymous users, leading to privilege escalation. This vulnerability only affects sites with the…

  • CVE-2023-43657HigSep 28, 2023
    risk 0.00cvss 7.2epss 0.00

    discourse-encrypt is a plugin that provides a secure communication channel through Discourse. Improper escaping of encrypted topic titles could lead to a cross site scripting (XSS) issue when a site has content security policy (CSP) headers disabled. Having CSP disabled is a…

  • CVE-2023-40375HigSep 28, 2023
    risk 0.48cvss 7.4epss 0.00

    Integrated application server for IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system. IBM X-Force ID: …

  • CVE-2023-5217HigKEVSep 28, 2023
    risk 0.66cvss 8.8epss 0.49

    Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-5187HigSep 28, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-5186HigSep 28, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: High)

  • CVE-2023-43868HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via websGetVar function.

  • CVE-2023-43867HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanL2TP function.

  • CVE-2023-43866HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard7 function.

  • CVE-2023-43865HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanPPTP function.

  • CVE-2023-43864HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard55 function.

  • CVE-2023-43863HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanDhcpplus function.

  • CVE-2023-43862HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formLanguageChange function.

  • CVE-2023-43861HigSep 28, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWanPPPoE function.