VYPR

CVEs

112,191 total · page 1094 of 2,244

  • CVE-2023-36319HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.02

    File Upload vulnerability in Openupload Stable v.0.4.3 allows a remote attacker to execute arbitrary code via the action parameter of the compress-inc.php file.

  • CVE-2023-40934HigSep 19, 2023
    risk 0.47cvss 7.2epss 0.03

    A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.

  • CVE-2023-40933HigSep 19, 2023
    risk 0.57cvss 8.8epss 0.03

    A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.

  • CVE-2023-22513HigSep 19, 2023
    risk 0.58cvss 8.8epss 0.14

    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high…

  • CVE-2023-42451HigSep 19, 2023
    risk 0.00cvss 7.4epss 0.01

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 3.5.14, 4.0.10, 4.1.8, and 4.2.0-rc2, under certain circumstances, attackers can exploit a flaw in domain name normalization to spoof domains they do not own. Versions 3.5.14, 4.0.10,…

  • CVE-2023-38356HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    MiniTool Power Data Recovery 11.6 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

  • CVE-2023-38355HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    MiniTool Movie Maker 7.0 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

  • CVE-2023-38354HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    MiniTool Shadow Maker version 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

  • CVE-2023-38352HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    MiniTool Partition Wizard 12.8 contains an insecure update mechanism that allows attackers to achieve remote code execution through a man in the middle attack.

  • CVE-2023-38351HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    MiniTool Partition Wizard 12.8 contains an insecure installation mechanism that allows attackers to achieve remote code execution through a man in the middle attack.

  • CVE-2023-42447HigSep 19, 2023
    risk 0.56cvss 8.6epss 0.01

    blurhash-rs is a pure Rust implementation of Blurhash, software for encoding images into ASCII strings that can be turned into a gradient of colors representing the original image. In version 0.1.1, the blurhash parsing code may panic due to multiple panic-guarded out-of-bounds…

  • CVE-2023-42444HigSep 19, 2023
    risk 0.49cvss 8.6epss 0.01

    phonenumber is a library for parsing, formatting and validating international phone numbers. Prior to versions `0.3.3+8.13.9` and `0.2.5+8.11.3`, the phonenumber parsing code may panic due to a panic-guarded out-of-bounds access on the phonenumber string. In a typical deployment…

  • CVE-2023-41890HigSep 19, 2023
    risk 0.49cvss 7.5epss 0.01

    Sustainsys.Saml2 library adds SAML2P support to ASP.NET web sites, allowing the web site to act as a SAML2 Service Provider. Prior to versions 1.0.3 and 2.9.2, when a response is processed, the issuer of the Identity Provider is not sufficiently validated. This could allow a…

  • CVE-2023-4096HigSep 19, 2023
    risk 0.56cvss 8.6epss 0.00

    Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version 1.5.0.0, which exploitation could allow an attacker to perform a brute force attack on the emailed PIN number in order to change the password of a legitimate user.

  • CVE-2023-41179HigKEVSep 19, 2023
    risk 0.59cvss 7.2epss 0.05

    A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected…

  • CVE-2023-31808HigSep 19, 2023
    risk 0.47cvss 7.2epss 0.01

    Technicolor TG670 10.5.N.9 devices contain multiple accounts with hard-coded passwords. One account has administrative privileges, allowing for unrestricted access over the WAN interface if Remote Administration is enabled.

  • CVE-2022-47559HigSep 19, 2023
    risk 0.56cvss 8.6epss 0.00

    Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to execute malicious actions when a user is logged in, affecting availability, privacy and integrity.

  • CVE-2023-4092HigSep 19, 2023
    risk 0.57cvss 8.8epss 0.01

    SQL injection vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to read sensitive data from the database, modify data (insert/update/delete), perform database administration operations and, in some cases,…

  • CVE-2022-47554HigSep 19, 2023
    risk 0.53cvss 8.2epss 0.00

    Exposure of sensitive information in ekorCCP and ekorRCI, potentially allowing a remote attacker to obtain critical information from various .xml files, including .xml files containing credentials, without being authenticated within the web server.

  • CVE-2022-47553HigSep 19, 2023
    risk 0.56cvss 8.6epss 0.01

    Incorrect authorisation in ekorCCP and ekorRCI, which could allow a remote attacker to obtain resources with sensitive information for the organisation, without being authenticated within the web server.

  • CVE-2023-32649HigSep 19, 2023
    risk 0.49cvss 7.5epss 0.01

    A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, allows an unauthenticated attacker to crash the IDS module by sending specially crafted…

  • CVE-2023-2567HigSep 19, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL Injection vulnerability has been found in Nozomi Networks Guardian and CMC, due to improper input validation in certain parameters used in the Query functionality. Authenticated users may be able to execute arbitrary SQL statements on the DBMS used by the web application.

  • CVE-2023-29245HigSep 19, 2023
    risk 0.53cvss 8.1epss 0.01

    A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, may allow an unauthenticated attacker to execute arbitrary SQL statements on the DBMS used by the web…

  • CVE-2023-32186HigSep 19, 2023
    risk 0.49cvss 7.5epss 0.01

    A Allocation of Resources Without Limits or Throttling vulnerability in SUSE RKE2 allows attackers with access to K3s servers apiserver/supervisor port (TCP 6443) cause denial of service. This issue affects RKE2: from 1.24.0 before 1.24.17+rke2r1, from v1.25.0 before…

  • CVE-2023-32184HigSep 19, 2023
    risk 0.51cvss 7.8epss 0.00

    A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute code as the user that runs opensuse-welcome if a custom layout is chosen This issue affects opensuse-welcome: from 0.1 before 0.1.9+git.35.4b9444a.

  • CVE-2023-5009HigSep 19, 2023
    risk 0.54cvss 8.2epss 0.08

    An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies. This was a bypass of…

  • CVE-2023-41443HigSep 18, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.

  • CVE-2023-42443HigSep 18, 2023
    risk 0.46cvss 8.1epss 0.01

    Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine (EVM). In version 0.3.9 and prior, under certain conditions, the memory used by the builtins `raw_call`, `create_from_blueprint` and `create_copy_of` can be corrupted. For `raw_call`, the argument…

  • CVE-2023-39452HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application.

  • CVE-2023-39446HigSep 18, 2023
    risk 0.58cvss 8.9epss 0.00

    Thanks to the weaknesses that the web application has at the user management level, an attacker could obtain the information from the headers that is necessary to create specially designed URLs and originate malicious actions when a legitimate user is logged into the web…

  • CVE-2023-41965HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Sending some requests in the web application of the vulnerable device allows information to be obtained due to the lack of security in the authentication process.

  • CVE-2023-40221HigSep 18, 2023
    risk 0.57cvss 8.8epss 0.01

    The absence of filters when loading some sections in the web application of the vulnerable device allows potential attackers to inject malicious code that will be interpreted when a legitimate user accesses the web section (MAIL SERVER) where the information is…

  • CVE-2023-42328HigSep 18, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the hardcoded session cookie.

  • CVE-2023-41595HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.

  • CVE-2023-42387HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in TDSQL Chitu management platform v.10.3.19.5.0 allows a remote attacker to obtain sensitive information via get_db_info function in install.php.

  • CVE-2023-34195HigSep 18, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in SystemFirmwareManagementRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The implementation of the GetImage method retrieves the value of a runtime variable named GetImageProgress, and later uses this value as a function pointer. This…

  • CVE-2023-32187HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    An Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s servers' apiserver/supervisor port (TCP 6443) cause denial of service. This issue affects k3s: from v1.24.0 before v1.24.17+k3s1, from v1.25.0 before…

  • CVE-2023-41929HigSep 18, 2023
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in Samsung Memory Card & UFD Authentication Utility PC Software before 1.0.1 could allow a local attacker to escalate privileges. (An attacker must already have user privileges on Windows to exploit this vulnerability.)

  • CVE-2023-34999HigSep 18, 2023
    risk 0.55cvss 8.4epss 0.01

    A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) that allows an attacker to perform arbitrary code execution via the admin web interface.

  • CVE-2023-43115HigSep 18, 2023
    risk 0.58cvss 8.8epss 0.05

    In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the…

  • CVE-2023-42525HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later,…

  • CVE-2023-42524HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later,…

  • CVE-2023-42523HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow a remote crash of a scanning engine via unpacking of a PE file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure…

  • CVE-2023-42522HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow a remote crash of a scanning engine via processing of an import struct in a PE file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17…

  • CVE-2023-42521HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow a remote crash of a scanning engine via processing of a compressed file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later,…

  • CVE-2023-5036HigSep 18, 2023
    risk 0.50cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository usememos/memos prior to 0.15.1.

  • CVE-2023-42526HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow a remote crash of a scanning engine via decompression of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and…

  • CVE-2023-42520HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Certain WithSecure products allow a remote crash of a scanning engine via unpacking of crafted data files. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later,…

  • CVE-2023-41349HigSep 18, 2023
    risk 0.57cvss 8.8epss 0.01

    ASUS router RT-AX88U has a vulnerability of using externally controllable format strings within its Advanced Open VPN function. An authenticated remote attacker can exploit the exported OpenVPN configuration to execute an externally-controlled format string attack, resulting in…

  • CVE-2023-35851HigSep 18, 2023
    risk 0.49cvss 7.5epss 0.01

    SUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to obtain sensitive information via a database.