VYPR

CVEs

112,078 total · page 1113 of 2,242

  • CVE-2022-48592HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the vendor_country parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being…

  • CVE-2022-48591HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the vendor_state parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being…

  • CVE-2022-48590HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “admin dynamic app mib errors” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the…

  • CVE-2022-48589HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “reporting job editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48588HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “schedule editor decoupled” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the…

  • CVE-2022-48587HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “schedule editor” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48586HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48585HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

  • CVE-2022-48584HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating…

  • CVE-2022-48583HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A command injection vulnerability exists in the dashboard scheduler feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

  • CVE-2022-48582HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A command injection vulnerability exists in the ticket report generate feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

  • CVE-2022-48581HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

  • CVE-2022-48580HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

  • CVE-2023-3518HigAug 9, 2023
    risk 0.48cvss 7.4epss 0.00

    HashiCorp Consul and Consul Enterprise 1.16.0 when using JWT Auth for service mesh incorrectly allows/denies access regardless of service identities. Fixed in 1.16.1.

  • CVE-2023-33953HigAug 9, 2023
    risk 0.49cvss 7.5epss 0.00

    gRPC contains a vulnerability that allows hpack table accounting errors could lead to unwanted disconnects between clients and servers in exceptional cases/ Three vectors were found that allow the following DOS attacks: - Unbounded memory buffering in the HPACK parser -…

  • CVE-2023-32782HigAug 9, 2023
    risk 0.51cvss 7.2epss 0.52

    A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The severity…

  • CVE-2023-32781HigAug 9, 2023
    risk 0.51cvss 7.2epss 0.12

    A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debug option to write new files that could potentially get executed by the EXE/Script sensor. The…

  • CVE-2023-31452HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) token bypass was identified in PRTG 23.2.84.1566 and earlier versions that allows remote attackers to perform actions with the permissions of a victim user, provided the victim user has an active session and is induced to trigger the malicious…

  • CVE-2023-38212HigAug 9, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Dimension version 3.4.9 is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2023-38211HigAug 9, 2023
    risk 0.51cvss 7.8epss 0.00

    Adobe Dimension version 3.4.9 is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2023-23574HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the alerts_count component, allows an authenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application. Authenticated users may be able…

  • CVE-2023-22378HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the sorting parameter, allows an authenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application. Authenticated users may be able to…

  • CVE-2023-38207HigAug 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by a XML Injection (aka Blind XPath Injection) vulnerability that could lead in minor arbitrary file system read. Exploitation of this issue does not require user…

  • CVE-2023-24477HigAug 9, 2023
    risk 0.46cvss 7.0epss 0.00

    In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session.

  • CVE-2023-37864HigAug 9, 2023
    risk 0.47cvss 7.2epss 0.00

    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.

  • CVE-2023-37863HigAug 9, 2023
    risk 0.47cvss 7.2epss 0.01

    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.

  • CVE-2023-37862HigAug 9, 2023
    risk 0.53cvss 8.2epss 0.00

    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service.

  • CVE-2023-37861HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a certificate to the device.

  • CVE-2023-37860HigAug 9, 2023
    risk 0.49cvss 7.5epss 0.01

    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon.

  • CVE-2023-37859HigAug 9, 2023
    risk 0.47cvss 7.2epss 0.01

    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privileges allowing a remote attacker with knowledge of the SNMPv2 r/w community string to execute system commands as root.

  • CVE-2023-26310HigAug 9, 2023
    risk 0.48cvss 7.4epss 0.01

    There is a command injection problem in the old version of the mobile phone backup app.

  • CVE-2022-47185HigAug 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.

  • CVE-2023-2905HigAug 9, 2023
    risk 0.00cvss 8.8epss 0.01

    Due to a failure in validating the length of a provided MQTT_CMD_PUBLISH parsed message with a variable length header, Cesanta Mongoose, an embeddable web server, version 7.10 is susceptible to a heap-based buffer overflow vulnerability in the default configuration. Version…

  • CVE-2023-4243HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and above to execute…

  • CVE-2023-4239HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated attackers, with minimal permissions such as…

  • CVE-2023-39910HigAug 9, 2023
    risk 0.49cvss 7.5epss 0.01

    The cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6.0 is weak, aka the Milk Sad issue. The use of an mt19937 Mersenne Twister PRNG restricts the internal entropy to 32 bits regardless of settings. This allows remote attackers to…

  • CVE-2023-39214HigAug 8, 2023
    risk 0.49cvss 7.6epss 0.01

    Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.

  • CVE-2023-39212HigAug 8, 2023
    risk 0.51cvss 7.9epss 0.00

    Untrusted search path in Zoom Rooms for Windows before version 5.15.5 may allow an authenticated user to enable a denial of service via local access.

  • CVE-2023-39211HigAug 8, 2023
    risk 0.57cvss 8.8epss 0.00

    Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via local access.

  • CVE-2023-39086HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.00

    ASUS RT-AC66U B1 3.0.0.4.286_51665 was discovered to transmit sensitive information in cleartext.

  • CVE-2023-36344HigAug 8, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code via not restricting the search path for required DLLs and not verifying the signature.

  • CVE-2023-39533HigAug 8, 2023
    risk 0.42cvss 7.5epss 0.01

    go-libp2p is the Go implementation of the libp2p Networking Stack. Prior to versions 0.27.8, 0.28.2, and 0.29.1 malicious peer can use large RSA keys to run a resource exhaustion attack & force a node to spend time doing signature verification of the large key. This…

  • CVE-2023-38180HigKEVAug 8, 2023
    risk 0.62cvss 7.5epss 0.15

    .NET and Visual Studio Denial of Service Vulnerability

  • CVE-2023-36899HigAug 8, 2023
    risk 0.63cvss 8.8epss 0.74

    ASP.NET Elevation of Privilege Vulnerability

  • CVE-2023-36873HigAug 8, 2023
    risk 0.48cvss 7.4epss 0.01

    .NET Framework Spoofing Vulnerability

  • CVE-2023-38186HigAug 8, 2023
    risk 0.57cvss 8.8epss 0.01

    Windows Mobile Device Management Elevation of Privilege Vulnerability

  • CVE-2023-38185HigAug 8, 2023
    risk 0.57cvss 8.8epss 0.03

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2023-38184HigAug 8, 2023
    risk 0.49cvss 7.5epss 0.01

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

  • CVE-2023-38182HigAug 8, 2023
    risk 0.53cvss 8.0epss 0.11

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2023-38181HigAug 8, 2023
    risk 0.59cvss 8.8epss 0.17

    Microsoft Exchange Server Spoofing Vulnerability