VYPR

CVEs

112,081 total · page 1112 of 2,242

  • CVE-2023-28129HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.00

    DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.

  • CVE-2023-39966HigAug 10, 2023
    risk 0.49cvss 7.5epss 0.01

    1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, an arbitrary file write vulnerability could lead to direct control of the server. In the `api/v1/file.go` file, there is a function called `SaveContentthat,It `recieves JSON data…

  • CVE-2023-39964HigAug 10, 2023
    risk 0.49cvss 7.5epss 0.01

    1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, arbitrary file reads allow an attacker to read arbitrary important configuration files on the server. In the `api/v1/file.go` file, there is a function called `LoadFromFile`,…

  • CVE-2023-39963HigAug 10, 2023
    risk 0.00cvss 8.1epss 0.00

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 20.0.0 and prior to versions 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, a missing password confirmation allowed an attacker, after…

  • CVE-2023-39962HigAug 10, 2023
    risk 0.00cvss 7.7epss 0.01

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 19.0.0 and prior to versions 19.0.13.10, 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, a malicious user could delete any personal or…

  • CVE-2023-39957HigAug 10, 2023
    risk 0.00cvss 7.8epss 0.00

    Nextcloud Talk Android allows users to place video and audio calls through Nextcloud on Android. Prior to version 17.0.0, an unprotected intend allowed malicious third party apps to trick the Talk Android app into writing files outside of its intended cache directory. Nextcloud…

  • CVE-2022-47636HigAug 10, 2023
    risk 0.54cvss 7.8epss 0.01

    A DLL hijacking vulnerability has been discovered in OutSystems Service Studio 11 11.53.30 build 61739. When a user open a .oml file (OutSystems Modeling Language), the application will load the following DLLs from the same directory av_libGLESv2.dll, libcef.DLL, user32.dll, and…

  • CVE-2023-38830HigAug 10, 2023
    risk 0.49cvss 7.5epss 0.01

    An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module.

  • CVE-2023-37543HigAug 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php. This is a different vulnerability than CVE-2019-16723.

  • CVE-2023-38246HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…

  • CVE-2023-38234HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.02

    Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…

  • CVE-2023-38233HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.02

    Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in…

  • CVE-2023-38231HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.02

    Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in…

  • CVE-2023-38229HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.02

    Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in…

  • CVE-2023-38228HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.02

    Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2023-38227HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.02

    Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2023-38226HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.02

    Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user…

  • CVE-2023-38225HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.03

    Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2023-38224HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.03

    Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2023-38223HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.02

    Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Access of Uninitialized Pointer that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in…

  • CVE-2023-38222HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.02

    Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a…

  • CVE-2023-29320HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.05

    Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Violation of Secure Design Principles vulnerability that could result in arbitrary code execution in the context of the current user by bypassing the API blacklisting…

  • CVE-2023-39314HigAug 10, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Teplitsa of social technologies Leyka plugin <= 3.30.2 versions.

  • CVE-2023-28779HigAug 10, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Vladimir Statsenko Terms descriptions plugin <= 3.4.4 versions.

  • CVE-2023-30481HigAug 10, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Alexey Golubnichenko AGP Font Awesome Collection plugin <= 3.2.4 versions.

  • CVE-2023-37988HigAug 10, 2023
    risk 0.46cvss 7.1epss 0.01

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Creative Solutions Contact Form Generator plugin <= 2.5.5 versions.

  • CVE-2023-26311HigAug 10, 2023
    risk 0.48cvss 7.4epss 0.01

    A remote code execution vulnerability in the webview component of OPPO Store app.

  • CVE-2023-31209HigAug 10, 2023
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users.

  • CVE-2023-26309HigAug 10, 2023
    risk 0.48cvss 7.4epss 0.01

    A remote code execution vulnerability in the webview component of OnePlus Store app.

  • CVE-2023-4277HigAug 10, 2023
    risk 0.57cvss 8.8epss 0.00

    The Realia plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.0. This is due to missing nonce validation on the 'process_change_profile_form' function. This makes it possible for unauthenticated attackers to change user email…

  • CVE-2023-4276HigAug 10, 2023
    risk 0.57cvss 8.8epss 0.00

    The Absolute Privacy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. This is due to missing nonce validation on the 'abpr_profileShortcode' function. This makes it possible for unauthenticated attackers to change user email…

  • CVE-2023-30699HigAug 10, 2023
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.

  • CVE-2023-30691HigAug 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.

  • CVE-2023-30680HigAug 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.

  • CVE-2023-30679HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-36673HigAug 9, 2023
    risk 0.47cvss 7.3epss 0.01

    An issue was discovered in Avira Phantom VPN through 2.23.1 for macOS. The VPN client insecurely configures the operating system such that all IP traffic to the VPN server's IP address is sent in plaintext outside the VPN tunnel, even if this traffic is not generated by the VPN…

  • CVE-2023-38348HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.00

    A CSRF issue was discovered in LWsystems Benno MailArchiv 2.10.1.

  • CVE-2023-33469HigAug 9, 2023
    risk 0.51cvss 7.8epss 0.00

    In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 can be exploited to achieve local code execution at the root level.

  • CVE-2023-39005HigAug 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.

  • CVE-2023-39003HigAug 9, 2023
    risk 0.49cvss 7.5epss 0.01

    OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.

  • CVE-2023-38997HigAug 9, 2023
    risk 0.00cvss 7.2epss 0.01

    A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands as root via a crafted ZIP archive.

  • CVE-2022-48604HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48603HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48602HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48601HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “network print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48600HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48599HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “reporter events type” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48598HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “reporter events type date” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the…

  • CVE-2022-48597HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “ticket event report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48596HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “ticket queue watchers” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.