VYPR

CVEs

112,173 total · page 1100 of 2,244

  • CVE-2023-41936HigSep 6, 2023
    risk 0.42cvss 7.5epss 0.01

    Jenkins Google Login Plugin 1.7 and earlier uses a non-constant time comparison function when checking whether the provided and expected token are equal, potentially allowing attackers to use statistical methods to obtain a valid token.

  • CVE-2023-41935HigSep 6, 2023
    risk 0.49cvss 7.5epss 0.01

    Jenkins Azure AD Plugin 396.v86ce29279947 and earlier, except 378.380.v545b_1154b_3fb_, uses a non-constant time comparison function when checking whether the provided and expected CSRF protection nonce are equal, potentially allowing attackers to use statistical methods to…

  • CVE-2023-41933HigSep 6, 2023
    risk 0.50cvss 8.8epss 0.01

    Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2023-40531HigSep 6, 2023
    risk 0.52cvss 8.0epss 0.00

    Archer AX6000 firmware versions prior to 'Archer AX6000(JP)_V1_1.3.0 Build 20221208' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.

  • CVE-2023-40357HigSep 6, 2023
    risk 0.52cvss 8.0epss 0.00

    Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer AX50 firmware versions prior to 'Archer AX50(JP)_V1_230529', Archer A10 firmware versions prior to 'Archer…

  • CVE-2023-40193HigSep 6, 2023
    risk 0.52cvss 8.0epss 0.00

    Deco M4 firmware versions prior to 'Deco M4(JP)_V2_1.5.8 Build 20230619' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.

  • CVE-2023-39935HigSep 6, 2023
    risk 0.52cvss 8.0epss 0.00

    Archer C5400 firmware versions prior to 'Archer C5400(JP)_V2_230506' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.

  • CVE-2023-39224HigSep 6, 2023
    risk 0.52cvss 8.0epss 0.00

    Archer C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Note that Archer C5 is no longer supported, therefore the update for this product is not provided.

  • CVE-2023-38588HigSep 6, 2023
    risk 0.52cvss 8.0epss 0.00

    Archer C3150 firmware versions prior to 'Archer C3150(JP)_V2_230511' allows a network-adjacent authenticated attacker to execute arbitrary OS commands.

  • CVE-2023-38568HigSep 6, 2023
    risk 0.57cvss 8.8epss 0.00

    Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504' allows a network-adjacent unauthenticated attacker to execute arbitrary OS commands.

  • CVE-2023-38563HigSep 6, 2023
    risk 0.57cvss 8.8epss 0.00

    Archer C1200 firmware versions prior to 'Archer C1200(JP)_V2_230508' and Archer C9 firmware versions prior to 'Archer C9(JP)_V3_230508' allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands.

  • CVE-2023-37284HigSep 6, 2023
    risk 0.57cvss 8.8epss 0.00

    Improper authentication vulnerability in Archer C20 firmware versions prior to 'Archer C20(JP)_V1_230616' allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command via a crafted request to bypass authentication.

  • CVE-2023-36489HigSep 6, 2023
    risk 0.57cvss 8.8epss 0.00

    Multiple TP-LINK products allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: TL-WR802N firmware versions prior to 'TL-WR802N(JP)_V4_221008', TL-WR841N firmware versions prior to…

  • CVE-2023-32619HigSep 6, 2023
    risk 0.57cvss 8.8epss 0.00

    Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions prior to 'Archer C55(JP)_V1_230506' use hard-coded credentials to login to the affected device, which may allow a network-adjacent unauthenticated attacker to execute an arbitrary…

  • CVE-2023-31188HigSep 6, 2023
    risk 0.52cvss 8.0epss 0.00

    Multiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are as follows: Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505', Archer C55 firmware versions prior to 'Archer…

  • CVE-2023-40601HigSep 6, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versions.

  • CVE-2023-40554HigSep 6, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Blog2Social, Adenion Blog2Social: Social Media Auto Post & Scheduler plugin <= 7.2.0 versions.

  • CVE-2023-30497HigSep 6, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Simon Chuang WP LINE Notify plugin <= 1.4.4 versions.

  • CVE-2023-29441HigSep 6, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Robert Heller WebLibrarian plugin <= 3.5.8.1 versions.

  • CVE-2023-3472HigSep 6, 2023
    risk 0.56cvss 8.6epss 0.00

    Use after free vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 may allow attackers to execute arbitrary code.

  • CVE-2023-3471HigSep 6, 2023
    risk 0.56cvss 8.6epss 0.00

    Buffer overflow vulnerability in Panasonic KW Watcher versions 1.00 through 2.82 may allow attackers to execute arbitrary code.

  • CVE-2023-32163HigSep 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Wacom Drivers for Windows Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Drivers for Windows. An attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2023-32162HigSep 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Wacom Drivers for Windows Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Drivers for Windows. An attacker must first obtain the ability to execute…

  • CVE-2023-30729HigSep 6, 2023
    risk 0.53cvss 8.1epss 0.00

    Improper Certificate Validation in Samsung Email prior to version 6.1.82.0 allows remote attacker to intercept the network traffic including sensitive information.

  • CVE-2023-30710HigSep 6, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in Knox AI prior to SMR Sep-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-30709HigSep 6, 2023
    risk 0.51cvss 7.9epss 0.00

    Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.

  • CVE-2023-30706HigSep 6, 2023
    risk 0.49cvss 7.5epss 0.00

    Improper authorization in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows attacker to read arbitrary file with system privilege.

  • CVE-2023-4719HigSep 6, 2023
    risk 0.47cvss 7.2epss 0.00

    The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `list_type` parameter in versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. Using this vulnerability, unauthenticated attackers could…

  • CVE-2023-32428HigSep 6, 2023
    risk 0.51cvss 7.8epss 0.01

    This issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13.4, tvOS 16.5, iOS 16.5 and iPadOS 16.5, watchOS 9.5. An app may be able to gain root privileges.

  • CVE-2023-32426HigSep 6, 2023
    risk 0.51cvss 7.8epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3. An app may be able to gain root privileges.

  • CVE-2023-32425HigSep 6, 2023
    risk 0.51cvss 7.8epss 0.00

    The issue was addressed with improved memory handling. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5. An app may be able to gain elevated privileges.

  • CVE-2023-32379HigSep 6, 2023
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.4. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2023-32356HigSep 6, 2023
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.

  • CVE-2023-29166HigSep 6, 2023
    risk 0.57cvss 8.8epss 0.00

    A logic issue was addressed with improved state management. This issue is fixed in Pro Video Formats 2.2.5. A user may be able to elevate privileges.

  • CVE-2023-28215HigSep 6, 2023
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.

  • CVE-2023-28214HigSep 6, 2023
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.

  • CVE-2023-28213HigSep 6, 2023
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.

  • CVE-2023-28212HigSep 6, 2023
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.

  • CVE-2023-28211HigSep 6, 2023
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.

  • CVE-2023-28210HigSep 6, 2023
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.

  • CVE-2023-28209HigSep 6, 2023
    risk 0.51cvss 7.8epss 0.00

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.

  • CVE-2023-4487HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    GE CIMPLICITY 2023 is by a process control vulnerability, which could allow a local attacker to insert malicious configuration files in the expected web server execution path to escalate privileges and gain full control of the HMI software.

  • CVE-2023-4763HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Networks in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-4762HigKEVSep 5, 2023
    risk 0.72cvss 8.8epss 0.38

    Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-4761HigSep 5, 2023
    risk 0.53cvss 8.1epss 0.01

    Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-39362HigSep 5, 2023
    risk 0.56cvss 7.2epss 0.82

    Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command injection and obtaining remote code…

  • CVE-2023-39358HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.02

    Cacti is an open source operational monitoring and fault management framework. An authenticated SQL injection vulnerability was discovered which allows authenticated users to perform privilege escalation and remote code execution. The vulnerability resides in the…

  • CVE-2023-39357HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.02

    Cacti is an open source operational monitoring and fault management framework. A defect in the sql_save function was discovered. When the column type is numeric, the sql_save function directly utilizes user input. Many files and functions calling the sql_save function do not…

  • CVE-2023-31132HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability. A low-privileged OS user with access to a Windows host where Cacti is installed can create arbitrary PHP files in a web document…

  • CVE-2023-39359HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.02

    Cacti is an open source operational monitoring and fault management framework. An authenticated SQL injection vulnerability was discovered which allows authenticated users to perform privilege escalation and remote code execution. The vulnerability resides in the `graphs.php`…