VYPR

CVEs

112,147 total · page 1108 of 2,243

  • CVE-2023-36787HigAug 21, 2023
    risk 0.57cvss 8.8epss 0.02

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2023-40352HigAug 21, 2023
    risk 0.47cvss 7.2epss 0.01

    McAfee Safe Connect before 2.16.1.126 may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs.

  • CVE-2023-3604HigAug 21, 2023
    risk 0.49cvss 7.5epss 0.01

    The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login page when accessing a crafted URL, bypassing the protection offered.

  • CVE-2023-39106HigAug 21, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in Nacos Group Nacos Spring Project v.1.1.1 and before allows a remote attacker to execute arbitrary code via the SnakeYamls Constructor() component.

  • CVE-2023-38976HigAug 21, 2023
    risk 0.42cvss 7.5epss 0.02

    An issue in weaviate v.1.20.0 allows a remote attacker to cause a denial of service via the handleUnbatchedGraphQLRequest function.

  • CVE-2023-38836HigAug 21, 2023
    risk 0.66cvss 8.8epss 0.69

    File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.

  • CVE-2023-40735HigAug 21, 2023
    risk 0.49cvss 7.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cavo – Connecting for a Safer World BUTTERFLY BUTTON (Architecture flaw) allows loss of plausible deniability and confidentiality.This issue affects BUTTERFLY BUTTON: As of 2023-08-21.

  • CVE-2023-38899HigAug 21, 2023
    risk 0.51cvss 7.8epss 0.00

    SQL injection vulnerability in berkaygediz O_Blog v.1.0 allows a local attacker to escalate privileges via the secure_file_priv component.

  • CVE-2022-46751HigAug 21, 2023
    risk 0.46cvss 8.2epss 0.02

    Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache Ivy.This issue affects any version of Apache Ivy prior to 2.5.2. When Apache Ivy prior to 2.5.2 parses XML files - either its own…

  • CVE-2023-39748HigAug 21, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in the component /userRpm/NetworkCfgRpm of TP-Link TL-WR1041N V2 allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

  • CVE-2023-39745HigAug 21, 2023
    risk 0.49cvss 7.5epss 0.01

    TP-Link TL-WR940N V2, TP-Link TL-WR941ND V5 and TP-Link TL-WR841N V8 were discovered to contain a buffer overflow via the component /userRpm/AccessCtrlAccessRulesRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

  • CVE-2023-39786HigAug 21, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sscanf function.

  • CVE-2023-39785HigAug 21, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the set_qosMib_list function.

  • CVE-2023-39784HigAug 21, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the list parameter in the save_virtualser_data function.

  • CVE-2023-37250HigAug 20, 2023
    risk 0.46cvss 7.0epss 0.00

    Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of…

  • CVE-2023-37369HigAug 20, 2023
    risk 0.49cvss 7.5epss 0.02

    In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.

  • CVE-2023-40711HigAug 20, 2023
    risk 0.49cvss 7.5epss 0.01

    Veilid before 0.1.9 does not check the size of uncompressed data during decompression upon an envelope receipt, which allows remote attackers to cause a denial of service (out-of-memory abort) via crafted packet data, as exploited in the wild in August 2023.

  • CVE-2023-2318HigAug 19, 2023
    risk 0.56cvss 8.6epss 0.00

    DOM-based XSS in src/muya/lib/contentState/pasteCtrl.js in MarkText 0.17.1 and before on Windows, Linux and macOS allows arbitrary JavaScript code to run in the context of MarkText main window. This vulnerability can be exploited if a user copies text from a malicious webpage…

  • CVE-2023-2317HigAug 19, 2023
    risk 0.56cvss 8.6epss 0.02

    DOM-based XSS in updater/update.html in Typora before 1.6.7 on Windows and Linux allows a crafted markdown file to run arbitrary JavaScript code in the context of Typora main window via loading typora://app/typemark/updater/update.html in tag. This vulnerability can be…

  • CVE-2023-2316HigAug 19, 2023
    risk 0.48cvss 7.4epss 0.01

    Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/". This vulnerability can be exploited if a user opens a malicious markdown file in…

  • CVE-2023-2110HigAug 19, 2023
    risk 0.53cvss 8.2epss 0.00

    Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/". This vulnerability can be exploited if a user opens a malicious…

  • CVE-2023-40175HigAug 18, 2023
    risk 0.41cvss 7.3epss 0.01

    Puma is a Ruby/Rack web server built for parallelism. Prior to versions 6.3.1 and 5.6.7, puma exhibited incorrect behavior when parsing chunked transfer encoding bodies and zero-length Content-Length headers in a way that allowed HTTP request smuggling. Severity of this issue is…

  • CVE-2023-40173HigAug 18, 2023
    risk 0.00cvss 7.5epss 0.01

    Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Prior to version 1.0.5 Social media skeleton did not properly salt passwords leaving user passwords susceptible to cracking should an attacker gain access to…

  • CVE-2023-38839HigAug 18, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via theID parameter in the fulldelete.php component.

  • CVE-2023-20212HigAug 18, 2023
    risk 0.49cvss 7.5epss 0.03

    A vulnerability in the AutoIt module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error in the memory management of an affected device. An attacker could…

  • CVE-2023-38890HigAug 18, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Shopping Portal Project 3.1 allows remote attackers to execute arbitrary SQL commands/queries via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the…

  • CVE-2023-4415HigAug 18, 2023
    risk 0.52cvss 7.3epss 0.56

    A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The manipulation leads to improper authentication. The attack may be launched remotely. The exploit has…

  • CVE-2023-32109HigAug 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ignazio Scimone Albo Pretorio On line plugin <= 4.6.3 versions.

  • CVE-2023-32108HigAug 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ignazio Scimone Albo Pretorio On line plugin <= 4.6.3 versions.

  • CVE-2023-30499HigAug 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions.

  • CVE-2023-32107HigAug 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.1.3 versions.

  • CVE-2023-32106HigAug 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Fahad Mahmood WP Docs plugin <= 1.9.9 versions.

  • CVE-2023-32105HigAug 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ollybach WPPizza – A Restaurant Plugin plugin <= 3.17.1 versions.

  • CVE-2023-31218HigAug 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.6 versions.

  • CVE-2023-31094HigAug 18, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Lauri Karisola / WP Trio Stock Sync for WooCommerce plugin <= 2.4.0 versions.

  • CVE-2023-40072HigAug 18, 2023
    risk 0.57cvss 8.8epss 0.02

    OS command injection vulnerability in ELECOM wireless LAN access point devices allows an authenticated user to execute an arbitrary OS command by sending a specially crafted request.

  • CVE-2023-39944HigAug 18, 2023
    risk 0.57cvss 8.8epss 0.01

    OS command injection vulnerability in WRC-F1167ACF all versions, and WRC-1750GHBK all versions allows an attacker who can access the product to execute an arbitrary OS command by sending a specially crafted request.

  • CVE-2023-39455HigAug 18, 2023
    risk 0.57cvss 8.8epss 0.01

    OS command injection vulnerability in ELECOM wireless LAN routers allows an authenticated user to execute an arbitrary OS command by sending a specially crafted request. Affected products and versions are as follows: WRC-600GHBK-A all versions, WRC-1467GHBK-A all versions,…

  • CVE-2023-39445HigAug 18, 2023
    risk 0.57cvss 8.8epss 0.01

    Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an unauthenticated attacker to execute arbitrary code by sending a specially crafted file to the product's certain management console.

  • CVE-2023-39416HigAug 18, 2023
    risk 0.47cvss 7.2epss 0.01

    Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote authenticated attacker with an administrative privilege to execute arbitrary OS commands.

  • CVE-2023-39415HigAug 18, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote unauthenticated attacker to log in to the product's Control Panel…

  • CVE-2023-38576HigAug 18, 2023
    risk 0.52cvss 8.0epss 0.00

    Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an authenticated user to execute arbitrary OS commands on a certain management console.

  • CVE-2023-38132HigAug 18, 2023
    risk 0.57cvss 8.8epss 0.00

    LAN-W451NGR all versions provided by LOGITEC CORPORATION contains an improper access control vulnerability, which allows an unauthenticated attacker to log in to telnet service.

  • CVE-2023-39669HigAug 18, 2023
    risk 0.49cvss 7.5epss 0.01

    D-Link DIR-880 A1_FW107WWb08 was discovered to contain a NULL pointer dereference in the function FUN_00010824.

  • CVE-2023-39125HigAug 18, 2023
    risk 0.49cvss 7.5epss 0.01

    NTSC-CRT 2.2.1 has an integer overflow and out-of-bounds write in loadBMP in bmp_rw.c because a file's width, height, and BPP are not validated. NOTE: the vendor's perspective is "this main application was not intended to be a well tested program, it's just something to…

  • CVE-2023-40168HigAug 17, 2023
    risk 0.00cvss 7.4epss 0.01

    TurboWarp is a desktop application that compiles scratch projects to JavaScript. TurboWarp Desktop versions prior to version 1.8.0 allowed a malicious project or custom extension to read arbitrary files from disk and upload them to a remote server. The only required user…

  • CVE-2023-36106HigAug 17, 2023
    risk 0.49cvss 7.5epss 0.01

    An incorrect access control vulnerability in powerjob 4.3.2 and earlier allows remote attackers to obtain sensitive information via the interface for querying via appId parameter to /container/list.

  • CVE-2023-31946HigAug 17, 2023
    risk 0.47cvss 7.2epss 0.01

    File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the artical.php.

  • CVE-2023-31945HigAug 17, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the id parameter at daily_expenditure_edit.php.

  • CVE-2023-31944HigAug 17, 2023
    risk 0.47cvss 7.2epss 0.01

    SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_edit.php.