VYPR

CVEs

112,172 total · page 1101 of 2,244

  • CVE-2023-41317HigSep 5, 2023
    risk 0.42cvss 7.5epss 0.01

    The Apollo Router is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Affected versions are subject to a Denial-of-Service (DoS) type vulnerability which causes the Router to panic and terminate when…

  • CVE-2020-35593HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host.

  • CVE-2023-40918HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.01

    KnowStreaming 3.3.0 is vulnerable to Escalation of Privileges. Unauthorized users can create a new user with an admin role.

  • CVE-2015-2202HigSep 5, 2023
    risk 0.47cvss 7.2epss 0.01

    Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.

  • CVE-2015-2201HigSep 5, 2023
    risk 0.47cvss 7.2epss 0.01

    Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users.

  • CVE-2015-1391HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.00

    Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism.

  • CVE-2023-3375HigSep 5, 2023
    risk 0.47cvss 7.2epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Unisign Bookreen allows OS Command Injection. This issue affects Bookreen: before 3.0.0.

  • CVE-2023-34998HigSep 5, 2023
    risk 0.53cvss 8.1epss 0.01

    An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary authentication. An attacker can sniff network traffic to trigger this…

  • CVE-2023-34353HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.01

    An authentication bypass vulnerability exists in the OAS Engine authentication functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted network sniffing can lead to decryption of sensitive information. An attacker can sniff network traffic to…

  • CVE-2023-31242HigSep 5, 2023
    risk 0.53cvss 8.1epss 0.03

    An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially-crafted series of network requests can lead to arbitrary authentication. An attacker can send a sequence of requests to trigger this…

  • CVE-2023-41108HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.01

    TEF portal 2023-07-17 is vulnerable to authenticated remote code execution.

  • CVE-2023-2453HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.01

    There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently passed to a ‘require_once’ statement. This allows arbitrary files with the ‘.php’ extension for which the absolute path is known to be included and…

  • CVE-2022-41763HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to the AMS server, could inject code in the PING function. The privileges of the command executed depend on the user that runs the…

  • CVE-2023-39448HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.01

    Path traversal vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to alter or create arbitrary files on the server, resulting in arbitrary code execution.

  • CVE-2023-4540HigSep 5, 2023
    risk 0.00cvss 7.5epss 0.01

    Improper Handling of Exceptional Conditions vulnerability in Daurnimator lua-http library allows Excessive Allocation and a denial of service (DoS) attack to be executed by sending a properly crafted request to the server. Such a request causes the program to enter an infinite…

  • CVE-2023-41909HigSep 5, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.

  • CVE-2023-33021HigSep 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in Graphics while processing user packets for command submission.

  • CVE-2023-33020HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA during CSA IE.

  • CVE-2023-33019HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station receives invalid channel in CSA IE.

  • CVE-2023-33016HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN firmware while parsing MLO (multi-link operation).

  • CVE-2023-33015HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Firmware while interpreting MBSSID IE of a received beacon frame.

  • CVE-2023-28584HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing channel switch announcement (CSA).

  • CVE-2023-28573HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN HAL while parsing WMI command parameters.

  • CVE-2023-28567HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN HAL while handling command through WMI interfaces.

  • CVE-2023-28565HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN HAL while handling command streams through WMI interfaces.

  • CVE-2023-28564HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN HAL while passing command parameters through WMI interfaces.

  • CVE-2023-28560HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN HAL while processing devIndex from untrusted WMI payload.

  • CVE-2023-28559HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN FW while processing command parameters from untrusted WMI payload.

  • CVE-2023-28558HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN handler while processing PhyID in Tx status handler.

  • CVE-2023-28557HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN HAL while processing command parameters from untrusted WMI payload.

  • CVE-2023-28549HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN HAL while parsing Rx buffer in processing TLV payload.

  • CVE-2023-28548HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN HAL while processing Tx/Rx commands from QDART.

  • CVE-2023-28544HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in WLAN while sending transmit command from HLOS to UTF handlers.

  • CVE-2023-28543HigSep 5, 2023
    risk 0.53cvss 8.1epss 0.00

    A malformed DLC can trigger Memory Corruption in SNPE library due to out of bounds read, such as by loading an untrusted model (e.g. from a remote source).

  • CVE-2023-28538HigSep 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.

  • CVE-2023-21664HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption in Core Platform while printing the response buffer in log.

  • CVE-2023-21662HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Memory corruption in Core Platform while printing the response buffer in log.

  • CVE-2023-21653HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in Modem while processing RRC reconfiguration message.

  • CVE-2023-21646HigSep 5, 2023
    risk 0.49cvss 7.5epss 0.00

    Transient DOS in Modem while processing invalid System Information Block 1.

  • CVE-2022-40534HigSep 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption due to improper validation of array index in Audio.

  • CVE-2022-33275HigSep 5, 2023
    risk 0.55cvss 8.4epss 0.00

    Memory corruption due to improper validation of array index in WLAN HAL when received lm_itemNum is out of range.

  • CVE-2023-35892HigSep 5, 2023
    risk 0.46cvss 7.1epss 0.01

    IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: …

  • CVE-2023-41058HigSep 4, 2023
    risk 0.42cvss 7.5epss 0.01

    Parse Server is an open source backend server. In affected versions the Parse Cloud trigger `beforeFind` is not invoked in certain conditions of `Parse.Query`. This can pose a vulnerability for deployments where the `beforeFind` trigger is used as a security layer to modify the…

  • CVE-2023-41055HigSep 4, 2023
    risk 0.00cvss 7.5epss 0.01

    LibreY is a fork of LibreX, a framework-less and javascript-free privacy respecting meta search engine. LibreY is subject to a Server-Side Request Forgery (SSRF) vulnerability in the `engines/google/text.php` and `engines/duckduckgo/text.php` files in versions before commit…

  • CVE-2023-41054HigSep 4, 2023
    risk 0.00cvss 8.2epss 0.01

    LibreY is a fork of LibreX, a framework-less and javascript-free privacy respecting meta search engine. LibreY is subject to a Server-Side Request Forgery (SSRF) vulnerability in the `image_proxy.php` file of LibreY before commit 8f9b9803f231e2954e5b49987a532d28fe50a627. This…

  • CVE-2023-28072HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell Alienware Command Center, versions prior to 5.5.51.0, contain a deserialization of untrusted data vulnerability. A local malicious user could potentially send specially crafted requests to the .NET Remoting server to run arbitrary code on the system.

  • CVE-2023-4752HigSep 4, 2023
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.1858.

  • CVE-2023-4750HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.1857.

  • CVE-2023-4733HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.1840.

  • CVE-2023-3222HigSep 4, 2023
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could create an automatic script to test all…