VYPR

CVEs

112,147 total · page 1106 of 2,243

  • CVE-2023-40035HigAug 23, 2023
    risk 0.40cvss 7.2epss 0.02

    Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code execution. This vulnerability can lead to malicious control of vulnerable systems and data exfiltrations. Although the…

  • CVE-2023-20200HigAug 23, 2023
    risk 0.50cvss 7.7epss 0.01

    A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could allow an authenticated, remote attacker to cause a denial of…

  • CVE-2023-20169HigAug 23, 2023
    risk 0.48cvss 7.4epss 0.00

    A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco NX-OS Software for the Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the IS-IS…

  • CVE-2023-20168HigAug 23, 2023
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in TACACS+ and RADIUS remote authentication for Cisco NX-OS Software could allow an unauthenticated, local attacker to cause an affected device to unexpectedly reload. This vulnerability is due to incorrect input validation when processing an authentication…

  • CVE-2023-38831HigKEVAug 23, 2023
    risk 0.80cvss 7.8epss 0.98

    RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the…

  • CVE-2023-40273HigAug 23, 2023
    risk 0.45cvss 8.0epss 0.01

    The session fixation vulnerability allowed the authenticated user to continue accessing Airflow webserver even after the password of the user has been reset by the admin - up until the expiry of the session of the user. Other than manually cleaning the session database (for…

  • CVE-2023-37379HigAug 23, 2023
    risk 0.46cvss 8.1epss 0.01

    Apache Airflow, in versions prior to 2.7.0, contains a security vulnerability that can be exploited by an authenticated user possessing Connection edit privileges. This vulnerability allows the user to access connection information and exploit the test connection feature by…

  • CVE-2023-32509HigAug 23, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rolf van Gelder Order Your Posts Manually plugin <= 2.2.5 versions.

  • CVE-2023-32300HigAug 23, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Yoast Yoast SEO: Local plugin <= 14.8 versions.

  • CVE-2023-28994HigAug 23, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in UX-themes Flatsome plugin <= 3.16.8 versions.

  • CVE-2023-32499HigAug 23, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Tony Zeoli, Tony Hayes Radio Station by netmix® – Manage and play your Show Schedule in WordPress! plugin <= 2.4.0.9 versions.

  • CVE-2023-32236HigAug 23, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin <= 1.1.8 versions.

  • CVE-2023-3899HigAug 23, 2023
    risk 0.51cvss 7.8epss 0.00

    A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the registration. By using the…

  • CVE-2023-41105HigAug 23, 2023
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security…

  • CVE-2023-40144HigAug 23, 2023
    risk 0.57cvss 8.8epss 0.02

    OS command injection vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H,…

  • CVE-2023-40158HigAug 23, 2023
    risk 0.57cvss 8.8epss 0.01

    Hidden functionality vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H,…

  • CVE-2023-38585HigAug 23, 2023
    risk 0.57cvss 8.8epss 0.01

    Improper authentication vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H,…

  • CVE-2023-3495HigAug 23, 2023
    risk 0.51cvss 7.8epss 0.00

    ** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerability in Hitachi EH-VIEW (KeypadDesigner) allows local attackers to potentially execute arbitray code on affected EH-VIEW installations. User interaction is required to exploit the vulnerabilities in that the user must…

  • CVE-2023-39986HigAug 23, 2023
    risk 0.51cvss 7.8epss 0.00

    ** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Read vulnerability in Hitachi EH-VIEW (Designer) allows local attackers to potentially disclose information on affected EH-VIEW installations. User interaction is required to exploit the vulnerabilities in that the user must open a…

  • CVE-2023-39985HigAug 23, 2023
    risk 0.51cvss 7.8epss 0.00

    ** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerability in Hitachi EH-VIEW (Designer) allows local attackers to potentially execute arbitray code on affected EH-VIEW installations. User interaction is required to exploit the vulnerabilities in that the user must open a…

  • CVE-2023-39984HigAug 23, 2023
    risk 0.51cvss 7.8epss 0.00

    ** UNSUPPORTED WHEN ASSIGNED ** Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Hitachi EH-VIEW (KeypadDesigner) allows local attackers to potentially disclose information and execute arbitray code on affected EH-VIEW installations. User…

  • CVE-2023-4431HigAug 23, 2023
    risk 0.53cvss 8.1epss 0.01

    Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-4430HigAug 23, 2023
    risk 0.58cvss 8.8epss 0.09

    Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-4429HigAug 23, 2023
    risk 0.57cvss 8.8epss 0.01

    Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-4428HigAug 23, 2023
    risk 0.54cvss 8.1epss 0.11

    Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-4427HigAug 23, 2023
    risk 0.55cvss 8.1epss 0.34

    Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-39026HigAug 22, 2023
    risk 0.53cvss 7.5epss 0.11

    Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.

  • CVE-2023-33850HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain…

  • CVE-2023-4475HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.00

    An Arbitrary File Movement vulnerability was found in ASUSTOR Data Master (ADM) allows an attacker to exploit the file renaming feature to move files to unintended directories. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and…

  • CVE-2023-3699HigAug 22, 2023
    risk 0.57cvss 8.7epss 0.00

    An Improper Privilege Management vulnerability was found in ASUSTOR Data Master (ADM) allows an unprivileged local users to modify the storage devices configuration. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.

  • CVE-2023-39141HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.03

    webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.

  • CVE-2023-37428HigAug 22, 2023
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying…

  • CVE-2023-37427HigAug 22, 2023
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability allows an attacker to execute arbitrary…

  • CVE-2023-37426HigAug 22, 2023
    risk 0.48cvss 7.4epss 0.00

    EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate…

  • CVE-2023-37425HigAug 22, 2023
    risk 0.52cvss 8.0epss 0.00

    A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows…

  • CVE-2023-37424HigAug 22, 2023
    risk 0.53cvss 8.1epss 0.01

    A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful…

  • CVE-2023-37423HigAug 22, 2023
    risk 0.53cvss 8.1epss 0.00

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker…

  • CVE-2023-37422HigAug 22, 2023
    risk 0.53cvss 8.1epss 0.00

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker…

  • CVE-2023-37421HigAug 22, 2023
    risk 0.53cvss 8.1epss 0.00

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker…

  • CVE-2023-34853HigAug 22, 2023
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.

  • CVE-2023-23564HigAug 22, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to execute commands.

  • CVE-2022-48571HigAug 22, 2023
    risk 0.00cvss 7.5epss 0.01

    memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.

  • CVE-2022-48570HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation. Function FixedSizeAllocatorWithCleanup could write to memory outside of the allocation if the allocated memory was not 16-byte aligned. NOTE: this issue exists because the CVE-2019-14318 fix was…

  • CVE-2022-48560HigAug 22, 2023
    risk 0.49cvss 7.5epss 0.02

    A use-after-free exists in Python through 3.9 via heappushpop in heapq.

  • CVE-2022-48541HigAug 22, 2023
    risk 0.46cvss 7.1epss 0.01

    A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -help" command.

  • CVE-2022-47696HigAug 22, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function compare_symbols.

  • CVE-2022-47695HigAug 22, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function bfd_mach_o_get_synthetic_symtab in match-o.c.

  • CVE-2022-47673HigAug 22, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Binutils addr2line before 2.39.3, function parse_module contains multiple out of bound reads which may cause a denial of service or other unspecified impacts.

  • CVE-2022-47069HigAug 22, 2023
    risk 0.51cvss 7.8epss 0.00

    p7zip 16.02 was discovered to contain a heap-buffer-overflow vulnerability via the function NArchive::NZip::CInArchive::FindCd(bool) at CPP/7zip/Archive/Zip/ZipIn.cpp. NOTE: the Supplier has found that this is not a buffer overflow; at most an out-of-bounds read can occur.

  • CVE-2022-45703HigAug 22, 2023
    risk 0.51cvss 7.8epss 0.01

    Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c.