VYPR

CVEs

31,789 total · page 226 of 636

  • CVE-2023-45377CriNov 22, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "Chronopost Official" (chronopost) for PrestaShop, a guest can perform SQL injection. The script PHP `cancelSkybill.php` own a sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

  • CVE-2023-2449CriNov 22, 2023
    risk 0.64cvss 9.8epss 0.01

    The UserPro plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 5.1.1. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function (userpro_process_form). The…

  • CVE-2023-2437CriNov 22, 2023
    risk 0.64cvss 9.8epss 0.07

    The UserPro plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.1. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated attackers…

  • CVE-2023-2889CriNov 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veon Computer Service Tracking Software allows SQL Injection. This issue affects Service Tracking Software: before crm 2.0.

  • CVE-2023-5047CriNov 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DRD Fleet Leasing DRDrive allows SQL Injection. This issue affects DRDrive: before 20231006.

  • CVE-2023-37924CriNov 22, 2023
    risk 0.57cvss 9.8epss 0.07

    Apache Software Foundation Apache Submarine has an SQL injection vulnerability when a user logs in. This issue can result in unauthorized login. Now we have fixed this issue and now user must have the correct login to access workbench. This issue affects Apache Submarine: from…

  • CVE-2023-6248CriNov 21, 2023
    risk 0.65cvss 10.0epss 0.01

    The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to execute code on any Syrus4 device connected to the cloud service. The MQTT server also leaks the location, video and diagnostic data…

  • CVE-2023-49105CriNov 21, 2023
    risk 0.65cvss 9.8epss 0.11

    An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted…

  • CVE-2023-49103CriKEVNov 21, 2023
    risk 0.86cvss 10.0epss 0.78

    An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo).…

  • CVE-2023-49060CriNov 21, 2023
    risk 0.64cvss 9.8epss 0.01

    An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability affects Firefox for iOS < 120.

  • CVE-2023-4149CriNov 21, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the web-based management allows an unauthenticated remote attacker to inject arbitrary system commands and gain full system control. Those commands are executed with root privileges. The vulnerability is located in the user request handling of the web-based…

  • CVE-2023-42770CriNov 21, 2023
    risk 0.65cvss 10.0epss 0.01

    Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same message is received over TCP/IP the RTU will simply accept the message with no authentication challenge.

  • CVE-2023-6144CriNov 21, 2023
    risk 0.59cvss 9.1epss 0.00

    Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any user's session just by knowing their username.

  • CVE-2023-40151CriNov 21, 2023
    risk 0.65cvss 10.0epss 0.01

    When user authentication is not enabled the shell can execute commands with the highest privileges. Red Lion SixTRAK and VersaTRAK Series RTUs with authenticated users enabled (UDR-A) any Sixnet UDR message will meet an authentication challenge over UDP/IP. When the same…

  • CVE-2023-48310CriNov 20, 2023
    risk 0.00cvss 9.1epss 0.01

    TestingPlatform is a testing platform for Internet Security Standards. Prior to version 2.1.1, user input is not filtered correctly. Nmap options are accepted. In this particular case, the option to create log files is accepted in addition to a host name (and even without). A…

  • CVE-2023-48176CriNov 20, 2023
    risk 0.64cvss 9.8epss 0.01

    An Insecure Permissions issue in WebsiteGuide v.0.2 allows a remote attacker to gain escalated privileges via crafted jwt (JSON web token).

  • CVE-2023-46990CriNov 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function.

  • CVE-2023-38823CriNov 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in Tenda Ac19 v.1.0, AC18, AC9 v.1.0, AC6 v.2.0 and v.1.0 allows a remote attacker to execute arbitrary code via the formSetCfm function in bin/httpd.

  • CVE-2023-5652CriNov 20, 2023
    risk 0.69cvss 9.8epss 0.64

    The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks, as well as does not escape user input before using it in a SQL statement of a function hooked to admin_init, allowing unauthenticated users to perform SQL injections

  • CVE-2023-5640CriNov 20, 2023
    risk 0.64cvss 9.8epss 0.01

    The Article Analytics WordPress plugin does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection vulnerability.

  • CVE-2023-5340CriNov 20, 2023
    risk 0.64cvss 9.8epss 0.01

    The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticated users, allowing them to perform PHP Object Injection when a suitable gadget is present on the blog.

  • CVE-2023-38880CriNov 20, 2023
    risk 0.64cvss 9.8epss 0.01

    The Community Edition version 9.0 of OS4ED's openSIS Classic has a broken access control vulnerability in the database backup functionality. Whenever an admin generates a database backup, the backup is stored in the web root while the file name has a format of…

  • CVE-2023-48292CriNov 20, 2023
    risk 0.60cvss 9.6epss 0.23

    The XWiki Admin Tools Application provides tools to help the administration of XWiki. Starting in version 4.4 and prior to version 4.5.1, a cross site request forgery vulnerability in the admin tool for executing shell commands on the server allows an attacker to execute…

  • CVE-2023-48240CriNov 20, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents and not display a difference for an actually unchanged image. For this, XWiki requests all embedded images on the server side. These requests are also sent for…

  • CVE-2023-35762CriNov 20, 2023
    risk 0.64cvss 9.9epss 0.02

    Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to operating system (OS) command injection, which could allow remote code execution.

  • CVE-2023-29155CriNov 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Versions of INEA ME RTU firmware 3.36b and prior do not require authentication to the "root" account on the host system of the device. This could allow an attacker to obtain admin-level access to the host system.

  • CVE-2023-46302CriNov 20, 2023
    risk 0.57cvss 9.8epss 0.02

    Apache Software Foundation Apache Submarine has a bug when serializing against yaml. The bug is caused by snakeyaml https://nvd.nist.gov/vuln/detail/CVE-2022-1471 . Apache Submarine uses JAXRS to define REST endpoints. In order to handle YAML requests (using application/yaml…

  • CVE-2022-46337CriNov 20, 2023
    risk 0.64cvss 9.8epss 0.01

    A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this could let an attacker fill up the disk by creating junk Derby databases. In LDAP-authenticated Derby installations, this could also allow the attacker to…

  • CVE-2023-46700CriNov 20, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary SQL command by sending a crafted request, and obtain or alter information…

  • CVE-2023-48028CriNov 18, 2023
    risk 0.64cvss 9.8epss 0.01

    kodbox 1.46.01 has a security flaw that enables user enumeration. This problem is present on the login page, where an attacker can identify valid users based on varying response messages, potentially paving the way for a brute force attack.

  • CVE-2023-43177CriNov 18, 2023
    risk 0.73cvss 9.8epss 0.82

    CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.

  • CVE-2023-44353CriNov 17, 2023
    risk 0.70cvss 9.8epss 0.80

    Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

  • CVE-2023-44351CriNov 17, 2023
    risk 0.68cvss 9.8epss 0.50

    Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

  • CVE-2023-44350CriNov 17, 2023
    risk 0.69cvss 9.8epss 0.65

    Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

  • CVE-2023-44324CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Adobe FrameMaker Publishing Server versions 2022 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An unauthenticated attacker can abuse this vulnerability to access the API and leak default admin's password.…

  • CVE-2023-47797CriNov 17, 2023
    risk 0.62cvss 9.6epss 0.01

    Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.

  • CVE-2023-41101CriNov 17, 2023
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not validate the length of the query string of GET requests. This leads to a stack-based buffer overflow in versions 9.x and earlier, and to a heap-based buffer…

  • CVE-2023-38316CriNov 17, 2023
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests. Affected OpenNDS Captive Portal before version 10.1.2…

  • CVE-2023-48659CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.

  • CVE-2023-48658CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.

  • CVE-2023-48657CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.

  • CVE-2023-48656CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.

  • CVE-2023-48655CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.

  • CVE-2023-48648CriNov 17, 2023
    risk 0.57cvss 9.8epss 0.01

    Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by default. Excessive permissions can…

  • CVE-2023-48031CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attacker can bypass security restrictions and upload a .bat file by manipulating the file's magic bytes to masquerade as an allowed type. This can enable the…

  • CVE-2023-45387CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 5.0.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection via `exportProduct::_addDataToDb().`

  • CVE-2023-48078CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in add.php in Simple CRUD Functionality v1.0 allows attackers to run arbitrary SQL commands via the 'title' parameter.

  • CVE-2023-6014CriNov 16, 2023
    risk 0.57cvss 9.8epss 0.01

    An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.

  • CVE-2023-6019CriNov 16, 2023
    risk 0.73cvss 9.8epss 0.75

    A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here:…

  • CVE-2023-6018CriNov 16, 2023
    risk 0.61cvss 9.8epss 0.48

    An attacker can overwrite any file on the server hosting MLflow without any authentication.