VYPR

CVEs

8,116 total · page 14 of 163

  • CVE-2024-5827CriJun 28, 2024
    risk 0.67cvss 9.8epss 0.40

    Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can inject malicious SQL training data and generate corresponding queries to write arbitrary files on the victim's file system, such as backdoor.php with contents `<?php system($_GET[0]); ?>`. This can lead to command execution or the creation of backdoors.

  • CVE-2024-27173CriJun 14, 2024
    risk 0.67cvss 9.8epss 0.45

    Remote Command program allows an attacker to get Remote Code Execution by overwriting existing Python files containing executable code. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.

  • CVE-2024-27972CriApr 3, 2024
    risk 0.67cvss 9.9epss 0.38

    Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.This issue affects WP Fusion Lite: from n/a through <= 3.41.24.

  • CVE-2023-3277CriNov 3, 2023
    risk 0.67cvss 9.8epss 0.47

    The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's email address.

  • CVE-2022-44588CriDec 15, 2022
    risk 0.67cvss 9.9epss 0.35

    Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.

  • CVE-2017-17875CriDec 27, 2017
    risk 0.67cvss 9.8epss 0.01

    The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.

  • CVE-2017-17873CriDec 27, 2017
    risk 0.67cvss 9.8epss 0.01

    Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.

  • CVE-2017-17872CriDec 27, 2017
    risk 0.67cvss 9.8epss 0.01

    The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.

  • CVE-2017-17871CriDec 27, 2017
    risk 0.67cvss 9.8epss 0.01

    The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.

  • CVE-2017-17870CriDec 27, 2017
    risk 0.67cvss 9.8epss 0.03

    The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.

  • CVE-2017-17761CriDec 19, 2017
    risk 0.67cvss 9.8epss 0.05

    An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) unauthenticated user to run arbitrary commands. This binary requires the "system" XML element for specifying the command. For example, a <system>id</system> command results in a <system_ack>ok</system_ack> response.

  • CVE-2017-17721CriDec 18, 2017
    risk 0.67cvss 9.8epss 0.07

    CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter.

  • CVE-2017-17651CriDec 18, 2017
    risk 0.67cvss 9.8epss 0.03

    Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.

  • CVE-2017-17645CriDec 18, 2017
    risk 0.67cvss 9.8epss 0.03

    Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.

  • CVE-2017-17643CriDec 18, 2017
    risk 0.67cvss 9.8epss 0.02

    FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.

  • CVE-2017-17648CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.01

    Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter.

  • CVE-2017-17642CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.

  • CVE-2017-17641CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.

  • CVE-2017-17640CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.

  • CVE-2017-17639CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.

  • CVE-2017-17638CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.

  • CVE-2017-17637CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.

  • CVE-2017-17636CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.

  • CVE-2017-17635CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter.

  • CVE-2017-17634CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.

  • CVE-2017-17633CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter.

  • CVE-2017-17632CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.

  • CVE-2017-17631CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.

  • CVE-2017-17630CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Yoga Class Script 1.0 has SQL Injection via the /list city parameter.

  • CVE-2017-17629CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter.

  • CVE-2017-17628CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.

  • CVE-2017-17627CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.

  • CVE-2017-17626CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.

  • CVE-2017-17625CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.02

    Professional Service Script 1.0 has SQL Injection via the service-list city parameter.

  • CVE-2017-17624CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.

  • CVE-2017-17623CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.

  • CVE-2017-17622CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.04

    Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.

  • CVE-2017-17621CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.04

    Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.

  • CVE-2017-17620CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.

  • CVE-2017-17619CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.04

    Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.

  • CVE-2017-17618CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.

  • CVE-2017-17617CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.

  • CVE-2017-17616CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Event Search Script 1.0 has SQL Injection via the /event-list city parameter.

  • CVE-2017-17614CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Food Order Script 1.0 has SQL Injection via the /list city parameter.

  • CVE-2017-17613CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter.

  • CVE-2017-17612CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.04

    Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.

  • CVE-2017-17611CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Doctor Search Script 1.0 has SQL Injection via the /list city parameter.

  • CVE-2017-17610CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.

  • CVE-2017-17609CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.

  • CVE-2017-17608CriDec 13, 2017
    risk 0.67cvss 9.8epss 0.03

    Child Care Script 1.0 has SQL Injection via the /list city parameter.