VYPR

CVEs

112,199 total · page 1092 of 2,244

  • CVE-2023-3664HigSep 25, 2023
    risk 0.47cvss 7.2epss 0.01

    The FileOrganizer WordPress plugin through 1.0.2 does not restrict functionality on multisite instances, allowing site admins to gain full control over the server.

  • CVE-2023-3550HigSep 25, 2023
    risk 0.48cvss 7.3epss 0.01

    Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the…

  • CVE-2023-3547HigSep 25, 2023
    risk 0.57cvss 8.8epss 0.00

    The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly check nonce values in several actions, allowing an attacker to perform CSRF attacks.

  • CVE-2023-32614HigSep 25, 2023
    risk 0.46cvss 7.0epss 0.01

    A heap-based buffer overflow vulnerability exists in the create_png_object functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2023-32284HigSep 25, 2023
    risk 0.53cvss 8.1epss 0.01

    An out-of-bounds write vulnerability exists in the tiff_planar_adobe functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2023-23567HigSep 25, 2023
    risk 0.53cvss 8.1epss 0.01

    A heap-based buffer overflow vulnerability exists in the CreateDIBfromPict functionality of Accusoft ImageGear 20.1. A specially crafted file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2023-0633HigSep 25, 2023
    risk 0.47cvss 7.2epss 0.00

    In Docker Desktop on Windows before 4.12.0 an argument injection to installer may result in local privilege escalation (LPE).This issue affects Docker Desktop: before 4.12.0.

  • CVE-2023-0626HigSep 25, 2023
    risk 0.52cvss 8.0epss 0.01

    Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker Desktop: before 4.12.0.

  • CVE-2023-0625HigSep 25, 2023
    risk 0.52cvss 8.0epss 0.01

    Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0.

  • CVE-2023-41303HigSep 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock structure to be modified.

  • CVE-2023-41302HigSep 25, 2023
    risk 0.49cvss 7.5epss 0.00

    Redirection permission verification vulnerability in the home screen module. Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2023-41301HigSep 25, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2023-41300HigSep 25, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of parameters not being strictly verified in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.

  • CVE-2023-41293HigSep 25, 2023
    risk 0.49cvss 7.5epss 0.00

    Data security classification vulnerability in the DDMP module. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-41299HigSep 25, 2023
    risk 0.49cvss 7.5epss 0.00

    DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.

  • CVE-2023-41298HigSep 25, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-39409HigSep 25, 2023
    risk 0.49cvss 7.5epss 0.00

    DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.

  • CVE-2023-39408HigSep 25, 2023
    risk 0.49cvss 7.5epss 0.00

    DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.

  • CVE-2023-41872HigSep 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Xtemos WoodMart plugin <= 7.2.4 versions.

  • CVE-2023-41874HigSep 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Order Delivery Date for WooCommerce plugin <= 3.20.0 versions.

  • CVE-2023-1625HigSep 24, 2023
    risk 0.41cvss 7.4epss 0.01

    An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of…

  • CVE-2023-1260HigSep 24, 2023
    risk 0.45cvss 8.0epss 0.02

    An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a…

  • CVE-2023-38346HigSep 22, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have relative or absolute file paths. A developer using the "tarExtract" function may expect that the…

  • CVE-2023-42821HigSep 22, 2023
    risk 0.42cvss 7.5epss 0.01

    The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `0.0.0-20230922105210-14b16010c2ee`, which corresponds with commit `14b16010c2ee7ff33a940a541d993bd043a88940`, parsing malformed markdown input…

  • CVE-2023-41031HigSep 22, 2023
    risk 0.52cvss 8.0epss 0.02

    Command injection in homemng.htm in Juplink RX4-1500 versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows remote authenticated attackers to execute commands via specially crafted requests to the vulnerable endpoint.

  • CVE-2023-41029HigSep 22, 2023
    risk 0.52cvss 8.0epss 0.02

    Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows authenticated remote attackers to execute commands as root via specially crafted HTTP requests to the vulnerable…

  • CVE-2023-41027HigSep 22, 2023
    risk 0.52cvss 8.0epss 0.01

    Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 and V1.0.5 allows an authenticated attacker to leak the password for the administrative account via requests to the vulnerable endpoint.

  • CVE-2023-42798HigSep 22, 2023
    risk 0.53cvss 8.2epss 0.00

    AutomataCI is a template git repository equipped with a native built-in semi-autonomous CI tools. An issue in versions 1.4.1 and below can let a release job reset the git root repository to the first commit. Version 1.5.0 has a patch for this issue. As a workaround, make sure…

  • CVE-2022-4039HigSep 22, 2023
    risk 0.52cvss 8.0epss 0.01

    A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in…

  • CVE-2023-34319HigSep 22, 2023
    risk 0.51cvss 7.8epss 0.00

    The fix for XSA-423 added logic to Linux'es netback driver to deal with a frontend splitting a packet in a way such that not all of the headers would come in one piece. Unfortunately the logic introduced there didn't account for the extreme case of the entire packet being split…

  • CVE-2022-3874HigSep 22, 2023
    risk 0.45cvss 8.0epss 0.02

    A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora CoreOS configurations in templates, possibly resulting in arbitrary command execution on the…

  • CVE-2023-43784HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.00

    Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey fields that are related to an Amazon AWS Firehose component. NOTE: the vendor's position is that there is no security threat.

  • CVE-2023-43783HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if it has been created by a local adversary before Cadence started. The adversary can leverage this to create or overwrite files via a symlink attack. In some…

  • CVE-2023-43767HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client…

  • CVE-2023-43766HigSep 22, 2023
    risk 0.51cvss 7.8epss 0.00

    Certain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure…

  • CVE-2023-43765HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow Denial of Service in the aeelf component. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for…

  • CVE-2023-43761HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow Denial of Service (infinite loop). This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15,…

  • CVE-2023-43760HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow Denial of Service via a fuzzed PE32 file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for…

  • CVE-2023-23364HigSep 22, 2023
    risk 0.53cvss 8.1epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We have already fixed the vulnerability in the following…

  • CVE-2023-23363HigSep 22, 2023
    risk 0.53cvss 8.1epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors. We have already fixed the vulnerability in the following versions:…

  • CVE-2023-23362HigSep 22, 2023
    risk 0.57cvss 8.8epss 0.01

    An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute commands via susceptible QNAP devices. We have already fixed the vulnerability in the following versions: QTS…

  • CVE-2023-31718HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.01

    FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.

  • CVE-2023-31717HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.02

    A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.

  • CVE-2023-31716HigSep 22, 2023
    risk 0.49cvss 7.5epss 0.01

    FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log

  • CVE-2023-5068HigSep 21, 2023
    risk 0.51cvss 7.8epss 0.00

    Delta Electronics DIAScreen may write past the end of an allocated buffer while parsing a specially crafted input file. This could allow an attacker to execute code in the context of the current process.

  • CVE-2023-4504HigSep 21, 2023
    risk 0.46cvss 7.0epss 0.01

    Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

  • CVE-2023-42261HigSep 21, 2023
    risk 0.49cvss 7.5epss 0.01

    Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication…

  • CVE-2023-38343HigSep 21, 2023
    risk 0.49cvss 7.5epss 0.01

    An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side…

  • CVE-2023-42280HigSep 21, 2023
    risk 0.49cvss 7.5epss 0.01

    mee-admin 1.5 is vulnerable to Directory Traversal. The download method in the CommonFileController.java file does not verify the incoming data, resulting in arbitrary file reading.

  • CVE-2023-41993HigKEVSep 21, 2023
    risk 0.72cvss 8.8epss 0.29

    The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.