VYPR

CVEs

112,168 total · page 1103 of 2,244

  • CVE-2023-41628HigSep 1, 2023
    risk 0.49cvss 7.5epss 0.02

    An issue in O-RAN Software Community E2 G-Release allows attackers to cause a Denial of Service (DoS) by incorrectly initiating the messaging procedure between the E2Node and E2Term components.

  • CVE-2023-41627HigSep 1, 2023
    risk 0.49cvss 7.5epss 0.01

    O-RAN Software Community ric-plt-lib-rmr v4.9.0 does not validate the source of the routing tables it receives, potentially allowing attackers to send forged routing tables to the device.

  • CVE-2023-40968HigSep 1, 2023
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in hzeller timg v.1.5.1 and before allows a remote attacker to cause a denial of service via the 0x61200000045c address.

  • CVE-2023-40771HigSep 1, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function.

  • CVE-2023-36088HigSep 1, 2023
    risk 0.49cvss 7.5epss 0.01

    Server Side Request Forgery (SSRF) vulnerability in NebulaGraph Studio version 3.7.0, allows remote attackers to gain sensitive information.

  • CVE-2023-28366HigSep 1, 2023
    risk 0.00cvss 7.5epss 0.01

    The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc…

  • CVE-2023-37997HigSep 1, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Dharmesh Patel Post List With Featured Image plugin <= 1.2 versions.

  • CVE-2023-37893HigSep 1, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Chop-Chop Coming Soon Chop Chop plugin <= 2.2.4 versions.

  • CVE-2023-34011HigSep 1, 2023
    risk 0.46cvss 7.1epss 0.00

    Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ShopConstruct plugin <= 1.1.2 versions.

  • CVE-2023-40970HigSep 1, 2023
    risk 0.57cvss 8.8epss 0.01

    Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php.

  • CVE-2023-40239HigSep 1, 2023
    risk 0.49cvss 7.5epss 0.00

    Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or…

  • CVE-2022-46527HigSep 1, 2023
    risk 0.49cvss 7.5epss 0.01

    ELSYS ERS 1.5 Sound v2.3.8 was discovered to contain a buffer overflow via the NFC data parser.

  • CVE-2023-39685HigSep 1, 2023
    risk 0.42cvss 7.5epss 0.01

    An issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON string.

  • CVE-2023-24674HigSep 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.

  • CVE-2023-4698HigSep 1, 2023
    risk 0.42cvss 7.5epss 0.01

    Improper Input Validation in GitHub repository usememos/memos prior to 0.13.2.

  • CVE-2023-4697HigSep 1, 2023
    risk 0.50cvss 8.8epss 0.01

    Improper Privilege Management in GitHub repository usememos/memos prior to 0.13.2.

  • CVE-2023-4695HigSep 1, 2023
    risk 0.00cvss 8.1epss 0.01

    Use of Predictable Algorithm in Random Number Generator in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

  • CVE-2023-4481HigSep 1, 2023
    risk 0.50cvss 7.5epss 0.15

    An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When certain specific crafted BGP UPDATE messages are received…

  • CVE-2023-40187HigAug 31, 2023
    risk 0.48cvss 7.3epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions of the 3.x beta branch are subject to a Use-After-Free issue in the `avc420_ensure_buffer` and `avc444_ensure_buffer` functions. If the value of…

  • CVE-2023-41749HigAug 31, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (Windows) before build 32047, Acronis Cyber Protect 15 (Windows) before build 35979.

  • CVE-2023-39355HigAug 31, 2023
    risk 0.00cvss 7.0epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Versions of FreeRDP on the 3.x release branch before beta3 are subject to a Use-After-Free in processing `RDPGFX_CMDID_RESETGRAPHICS` packets. If `context->maxPlaneSize` is…

  • CVE-2022-46869HigAug 31, 2023
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation during installation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278, Acronis True Image OEM (Windows) before build 42575.

  • CVE-2023-41744HigAug 31, 2023
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Agent (macOS) before build 30600, Acronis Cyber Protect 15 (macOS) before build 35979.

  • CVE-2023-41743HigAug 31, 2023
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40278, Acronis Cyber Protect Cloud Agent (Windows) before build 31637, Acronis Cyber Protect 15…

  • CVE-2023-34392HigAug 31, 2023
    risk 0.53cvss 8.2epss 0.00

    A Missing Authentication for Critical Function vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run arbitrary commands on managed devices by an authorized device operator. See Instruction Manual Appendix A…

  • CVE-2023-34391HigAug 31, 2023
    risk 0.48cvss 7.4epss 0.00

    Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software on Windows allows Leveraging/Manipulating Configuration File Search Paths. See Instruction Manual Appendix A [Cybersecurity] tag dated 20230522 for more…

  • CVE-2023-31175HigAug 31, 2023
    risk 0.57cvss 8.8epss 0.00

    An Execution with Unnecessary Privileges vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run system commands with the highest level privilege on the system. See Instruction Manual Appendix A and Appendix E…

  • CVE-2023-31174HigAug 31, 2023
    risk 0.48cvss 7.4epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual Appendix A and Appendix…

  • CVE-2023-31173HigAug 31, 2023
    risk 0.50cvss 7.7epss 0.00

    Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator on Windows allows Authentication Bypass. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details. This issue affects SEL-5037 SEL Grid…

  • CVE-2023-41742HigAug 31, 2023
    risk 0.49cvss 7.5epss 0.00

    Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30430, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.

  • CVE-2022-46868HigAug 31, 2023
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation during recovery due to improper soft link handling. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40173.

  • CVE-2022-45451HigAug 31, 2023
    risk 0.51cvss 7.8epss 0.00

    Local privilege escalation due to insecure driver communication port permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40173, Acronis Agent (Windows) before build 30600, Acronis Cyber Protect 15 (Windows) before build…

  • CVE-2023-41640HigAug 31, 2023
    risk 0.57cvss 8.8epss 0.01

    An improper error handling vulnerability in the component ErroreNonGestito.aspx of GruppoSCAI RealGimm 1.1.37p38 allows attackers to obtain sensitive technical information via a crafted SQL query.

  • CVE-2023-41638HigAug 31, 2023
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the Gestione Documentale module of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-41738HigAug 31, 2023
    risk 0.47cvss 7.2epss 0.01

    Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Domain Functionality in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

  • CVE-2023-20900HigAug 31, 2023
    risk 0.46cvss 7.1epss 0.01

    A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine…

  • CVE-2023-3677HigAug 31, 2023
    risk 0.50cvss 8.8epss 0.01

    The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to SQL Injection via the pageId parameter in versions up to, and including, 1.2.89 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. …

  • CVE-2023-3636HigAug 31, 2023
    risk 0.50cvss 8.8epss 0.01

    The WP Project Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.6.4 due to insufficient restriction on the 'save_users_map_name' function. This makes it possible for authenticated attackers, with minimal permissions such as a…

  • CVE-2023-2229HigAug 31, 2023
    risk 0.57cvss 8.8epss 0.01

    The Quick Post Duplicator for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…

  • CVE-2023-2188HigAug 31, 2023
    risk 0.47cvss 7.2epss 0.01

    The Colibri Page Builder for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.0.227 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

  • CVE-2023-31424HigAug 31, 2023
    risk 0.53cvss 8.1epss 0.01

    Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a allows remote unauthenticated users to bypass web authentication and authorization.

  • CVE-2023-3489HigAug 31, 2023
    risk 0.56cvss 8.6epss 0.00

    The firmwaredownload command on Brocade Fabric OS v9.2.0 could log the FTP/SFTP/SCP server password in clear text in the SupportSave file when performing a downgrade from Fabric OS v9.2.0 to any earlier version of Fabric OS.

  • CVE-2023-39139HigAug 30, 2023
    risk 0.44cvss 7.8epss 0.00

    An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.

  • CVE-2023-39138HigAug 30, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in ZIPFoundation v0.9.16 allows attackers to execute a path traversal via extracting a crafted zip file.

  • CVE-2023-39137HigAug 30, 2023
    risk 0.44cvss 7.8epss 0.00

    An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.

  • CVE-2023-39135HigAug 30, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in Zip Swift v2.1.2 allows attackers to execute a path traversal attack via a crafted zip entry.

  • CVE-2023-41039HigAug 30, 2023
    risk 0.47cvss 8.3epss 0.01

    RestrictedPython is a restricted execution environment for Python to run untrusted code. Python's "format" functionality allows someone controlling the format string to "read" all objects accessible through recursive attribute lookup and subscription from objects he can access.…

  • CVE-2023-4571HigAug 30, 2023
    risk 0.56cvss 8.6epss 0.00

    In Splunk IT Service Intelligence (ITSI) versions below below 4.13.3, 4.15.3, or 4.17.1, a malicious actor can inject American National Standards Institute (ANSI) escape codes into Splunk ITSI log files that, when a vulnerable terminal application reads them, can run malicious…

  • CVE-2023-40598HigAug 30, 2023
    risk 0.55cvss 8.5epss 0.01

    In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The attacker can use this internal function to insert code into the Splunk platform installation directory. From there, a user can…

  • CVE-2023-40597HigAug 30, 2023
    risk 0.51cvss 7.8epss 0.00

    In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.