VYPR

CVEs

112,166 total · page 1105 of 2,244

  • CVE-2023-39059HigAug 28, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter.

  • CVE-2020-24165HigAug 28, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS). Note: This is disputed as a bug and not a valid security issue by multiple third parties.

  • CVE-2023-35785HigAug 28, 2023
    risk 0.53cvss 8.1epss 0.02

    Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and…

  • CVE-2023-39810HigAug 28, 2023
    risk 0.51cvss 7.8epss 0.01

    An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.

  • CVE-2023-40590HigAug 28, 2023
    risk 0.44cvss 7.8epss 0.00

    GitPython is a python library used to interact with Git repositories. When resolving a program, Python/Windows look for the current working directory, and after that the PATH environment. GitPython defaults to use the `git` command, if a user runs GitPython from a repo has a…

  • CVE-2023-1997HigAug 28, 2023
    risk 0.57cvss 8.8epss 0.02

    An OS Command Injection vulnerability exists in SIMULIA 3DOrchestrate from Release 3DEXPERIENCE R2021x through Release 3DEXPERIENCE R2023x. A specially crafted HTTP request can lead to arbitrary command execution.

  • CVE-2023-40754HigAug 28, 2023
    risk 0.57cvss 8.8epss 0.01

    In PHPJabbers Car Rental Script 3.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.

  • CVE-2023-36481HigAug 28, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, and W920. Improper handling of PPP length parameter inconsistency can cause an infinite loop.

  • CVE-2023-34758HigAug 28, 2023
    risk 0.46cvss 8.1epss 0.01

    Sliver from v1.5.x to v1.5.39 has an improper cryptographic implementation, which allows attackers to execute a man-in-the-middle attack via intercepted and crafted responses.

  • CVE-2023-26095HigAug 28, 2023
    risk 0.49cvss 7.5epss 0.01

    ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet.

  • CVE-2023-40195HigAug 28, 2023
    risk 0.50cvss 8.8epss 0.01

    Deserialization of Untrusted Data, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Software Foundation Apache Airflow Spark Provider. When the Apache Spark provider is installed on an Airflow deployment, an Airflow user that is authorized to…

  • CVE-2023-27604HigAug 28, 2023
    risk 0.50cvss 8.8epss 0.01

    Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parameters with the connections, which makes it possible to implement RCE attacks via ‘sqoop import --connect’, obtain airflow server permissions, etc. The…

  • CVE-2023-38030HigAug 28, 2023
    risk 0.49cvss 7.5epss 0.01

    Saho’s attendance devices ADM100 and ADM-100FP have a vulnerability of missing authentication for critical functions. An unauthenticated remote attacker can execute system commands in partial website URLs to read sensitive device information without permissions.

  • CVE-2023-22877HigAug 28, 2023
    risk 0.46cvss 7.0epss 0.01

    IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 244368.

  • CVE-2022-43904HigAug 28, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of excessive authentication attempts. IBM X-Force ID: 240895.

  • CVE-2023-33852HigAug 27, 2023
    risk 0.49cvss 7.6epss 0.00

    IBM Security Guardium 11.4 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 257614.

  • CVE-2023-30435HigAug 27, 2023
    risk 0.58cvss 8.9epss 0.00

    IBM Security Guardium 11.3, 11.4, and 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…

  • CVE-2022-43907HigAug 27, 2023
    risk 0.47cvss 7.2epss 0.01

    IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 240901.

  • CVE-2023-36741HigAug 26, 2023
    risk 0.54cvss 8.3epss 0.02

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2023-41121HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP operations.

  • CVE-2023-39289HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to conduct an account enumeration attack due to improper configuration. A successful exploit could allow an attacker to access system…

  • CVE-2023-34723HigAug 25, 2023
    risk 0.52cvss 7.5epss 0.03

    An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information via /config/system.conf.

  • CVE-2023-40586HigAug 25, 2023
    risk 0.42cvss 7.5epss 0.01

    OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Due to the misuse of `log.Fatalf`, the application using coraza crashed after receiving crafted requests from attackers. The application will immediately crash after receiving a malicious…

  • CVE-2023-40585HigAug 25, 2023
    risk 0.00cvss 7.3epss 0.00

    ironic-image is a container image to run OpenStack Ironic as part of Metal³. Prior to version capm3-v1.4.3, if Ironic is not deployed with TLS and it does not have API and Conductor split into separate services, access to the API is not protected by any authentication. Ironic…

  • CVE-2023-40583HigAug 25, 2023
    risk 0.42cvss 7.5epss 0.01

    libp2p is a networking stack and library modularized out of The IPFS Project, and bundled separately for other tools to use. In go-libp2p, by using signed peer records a malicious actor can store an arbitrary amount of data in a remote node’s memory. This memory does not get…

  • CVE-2023-40580HigAug 25, 2023
    risk 0.00cvss 8.1epss 0.01

    Freighter is a Stellar chrome extension. It may be possible for a malicious website to access the recovery mnemonic phrase when the Freighter wallet is unlocked. This vulnerability impacts access control to the mnemonic recovery phrase. This issue was patched in version 5.3.1.

  • CVE-2023-40031HigAug 25, 2023
    risk 0.51cvss 7.8epss 0.00

    Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to arbitrary code execution. As of time of publication, no known patches are available in existing…

  • CVE-2023-37249HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    Infoblox NIOS through 8.5.1 has a faulty component that accepts malicious input without sanitization, resulting in shell access.

  • CVE-2023-36199HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in skalenetwork sgxwallet v.1.9.0 and below allows an attacker to cause a denial of service via the trustedGenerateEcdsaKey component.

  • CVE-2023-36198HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in skalenetwork sgxwallet v.1.9.0 allows an attacker to cause a denial of service via the trustedBlsSignMessage function.

  • CVE-2023-24621HigAug 25, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Esoteric YamlBeans through 1.15. It allows untrusted deserialisation to Java classes by default, where the data and class are controlled by the author of the YAML document being processed.

  • CVE-2021-27932HigAug 25, 2023
    risk 0.51cvss 7.8epss 0.00

    Stormshield Network Security (SNS) VPN SSL Client 2.1.0 through 2.8.0 has Insecure Permissions.

  • CVE-2019-13689HigAug 25, 2023
    risk 0.51cvss 7.8epss 0.00

    Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform arbitrary read/write via a malicious file. (Chromium security severity: Critical)

  • CVE-2023-40798HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability.

  • CVE-2023-40797HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting in a post-authentication stack overflow vulnerability.

  • CVE-2023-40796HigAug 25, 2023
    risk 0.51cvss 7.8epss 0.01

    Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.

  • CVE-2023-40915HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda AX3 v16.03.12.11 has a stack buffer overflow vulnerability detected at function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ssid parameter.

  • CVE-2023-40801HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    The sub_451784 function does not validate the parameters entered by the user, resulting in a stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn

  • CVE-2023-40800HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.01

    The compare_parentcontrol_time function does not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn.

  • CVE-2022-4452HigAug 25, 2023
    risk 0.57cvss 8.8epss 0.00

    Insufficient data validation in crosvm in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-32797HigAug 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution video carousel slider with lightbox plugin <= 1.0.22 versions.

  • CVE-2023-32603HigAug 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao Donations Made Easy – Smart Donations plugin <= 4.0.12 versions.

  • CVE-2023-32598HigAug 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in A. R. Jones Featured Image Pro Post Grid plugin <= 5.14 versions.

  • CVE-2023-3406HigAug 25, 2023
    risk 0.50cvss 7.7epss 0.01

    Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server

  • CVE-2023-32518HigAug 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ono Oogami WP Chinese Conversion plugin <= 1.1.16 versions.

  • CVE-2023-32756HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An unauthenticated remote attacker can exploit this vulnerability to read arbitrary system files, but can’t control system or disrupt service.

  • CVE-2023-41173HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    AdGuard DNS before 2.2 allows remote attackers to cause a denial of service via malformed UDP packets.

  • CVE-2023-40599HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Regular expression Denial-of-Service (ReDoS) exists in multiple add-ons for Mailform Pro CGI 4.3.1.3 and earlier, which allows a remote unauthenticated attacker to cause a denial-of-service condition. Affected add-ons are as follows: call/call.js, prefcodeadv/search.cgi,…

  • CVE-2023-40577HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Prometheus Alertmanager. This issue…

  • CVE-2023-40022HigAug 24, 2023
    risk 0.00cvss 7.8epss 0.00

    Rizin is a UNIX-like reverse engineering framework and command-line toolset. Versions 0.6.0 and prior are vulnerable to integer overflow in `consume_count` of `src/gnu_v2/cplus-dem.c`. The overflow check is valid logic but, is missing the modulus if the block once compiled. The…