VYPR

CVEs

112,085 total · page 1110 of 2,242

  • CVE-2023-40013HigAug 14, 2023
    risk 0.39cvss 7.1epss 0.00

    SVG Loader is a javascript library that fetches SVGs using XMLHttpRequests and injects the SVG code in the tag's place. According to the docs, svg-loader will strip all JS code before injecting the SVG file for security reasons but the input sanitization logic is not sufficient…

  • CVE-2023-39829HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the wpapsk_crypto2_4g parameter in the fromSetWirelessRepeat function.

  • CVE-2023-39828HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function.

  • CVE-2023-39827HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRule function.

  • CVE-2023-21269HigAug 14, 2023
    risk 0.51cvss 7.8epss 0.00

    In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into PiP mode from the background due to BAL bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-21265HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.00

    In multiple locations, there are root CA certificates which need to be disabled. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-39908HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.00

    The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory.

  • CVE-2023-28483HigAug 14, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Tigergraph Enterprise 3.7.0. The GSQL query language provides users with the ability to write data to files on a remote TigerGraph server. The locations that a query is allowed to write to are configurable via the GSQL.FileOutputPolicy configuration…

  • CVE-2023-28481HigAug 14, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Tigergraph Enterprise 3.7.0. There is unsecured write access to SSH authorized keys file. Any code running as the tigergraph user is able to add their SSH public key into the authorised keys file. This allows an attacker to obtain password-less SSH key…

  • CVE-2023-38741HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of…

  • CVE-2023-38721HigAug 14, 2023
    risk 0.55cvss 8.4epss 0.00

    The IBM i 7.2, 7.3, 7.4, and 7.5 product Facsimile Support for i contains a local privilege escalation vulnerability. A malicious actor could gain access to a command line with elevated privileges allowing root access to the host operating system. IBM X-Force ID: 262173.

  • CVE-2023-0872HigAug 14, 2023
    risk 0.50cvss 8.2epss 0.03

    The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elevation of privilege. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer.…

  • CVE-2023-33013HigAug 14, 2023
    risk 0.57cvss 8.8epss 0.01

    A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)C0 could allow an authenticated attacker to execute some OS commands remotely by sending a crafted HTTP request.

  • CVE-2023-31041HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in SysPasswordDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. System password information could optionally be stored in cleartext, which might lead to possible information disclosure.

  • CVE-2023-30754HigAug 14, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AdFoxly AdFoxly – Ad Manager, AdSense Ads & Ads.Txt plugin <= 1.8.5 versions.

  • CVE-2023-30489HigAug 14, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Email Subscription Popup plugin <= 1.2.16 versions.

  • CVE-2023-28535HigAug 14, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paytm Paytm Payment Donation plugin <= 2.2.0 versions.

  • CVE-2023-30483HigAug 14, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Kiboko Labs Watu Quiz plugin <= 3.3.9.2 versions.

  • CVE-2023-30475HigAug 14, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Elliot Sowersby, RelyWP WooCommerce Affiliate Plugin – Coupon Affiliates plugin <= 5.4.5 versions.

  • CVE-2023-30188HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.02

    Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file.

  • CVE-2023-3160HigAug 14, 2023
    risk 0.51cvss 7.8epss 0.00

    The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having proper permissions.

  • CVE-2023-40303HigAug 14, 2023
    risk 0.51cvss 7.8epss 0.00

    GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before…

  • CVE-2023-3263HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass in the REST API due to the mishandling of special characters when parsing credentials.Successful exploitation allows the malicious agent to obtain a valid…

  • CVE-2023-40296HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    async-sockets-cpp through 0.3.1 has a stack-based buffer overflow in ReceiveFrom and Receive in udpsocket.hpp when processing malformed UDP packets.

  • CVE-2023-40295HigAug 14, 2023
    risk 0.57cvss 8.8epss 0.01

    libboron in Boron 2.0.8 has a heap-based buffer overflow in ur_strInitUtf8 at string.c.

  • CVE-2023-3261HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in the librta.so.0.0.0 library.Successful exploitation could cause denial of service or unexpected behavior with respect to all interactions relying on the targeted…

  • CVE-2023-3260HigAug 14, 2023
    risk 0.47cvss 7.2epss 0.01

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system.

  • CVE-2023-40283HigAug 14, 2023
    risk 0.00cvss 7.8epss 0.01

    An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.

  • CVE-2023-40274HigAug 14, 2023
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the "zola serve" command, allows directory traversal. The handle_request function, used by the server to process HTTP requests, does not account for sequences of…

  • CVE-2023-39406HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart.

  • CVE-2023-39404HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart.

  • CVE-2023-39397HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Input parameter verification vulnerability in the communication system. Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-39395HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Mismatch vulnerability in the serialization process in the communication system. Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-39394HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of API privilege escalation in the wifienhance module. Successful exploitation of this vulnerability may cause the arp list to be modified.

  • CVE-2023-39391HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of system file information leakage in the USB Service module. Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2023-39390HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart.

  • CVE-2023-39386HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause newly installed apps to fail to restart.

  • CVE-2023-39396HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-39393HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of insecure signatures in the ServiceWifiResources module. Successful exploitation of this vulnerability may cause ServiceWifiResources to be maliciously modified and overwritten.

  • CVE-2023-39392HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten.

  • CVE-2023-39389HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability.

  • CVE-2023-39388HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of input parameters being not strictly verified in the PMS module. Successful exploitation of this vulnerability may cause home screen unavailability.

  • CVE-2023-39384HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of incomplete permission verification in the input method module. Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2023-39383HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of input parameters being not strictly verified in the AMS module. Successful exploitation of this vulnerability may compromise apps' data security.

  • CVE-2023-39382HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Input verification vulnerability in the audio module. Successful exploitation of this vulnerability may cause virtual machines (VMs) to restart.

  • CVE-2023-39381HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Input verification vulnerability in the storage module. Successful exploitation of this vulnerability may cause the device to restart.

  • CVE-2023-39380HigAug 13, 2023
    risk 0.49cvss 7.5epss 0.00

    Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause audio devices to perform abnormally.

  • CVE-2023-4293HigAug 12, 2023
    risk 0.50cvss 8.8epss 0.01

    The Premium Packages - Sell Digital Products Securely plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.7.4 due to insufficient restriction on the 'wpdmpp_update_profile' function. This makes it possible for authenticated attackers,…

  • CVE-2023-22957HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the…

  • CVE-2023-22956HigAug 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information.