VYPR

CVEs

31,788 total · page 229 of 636

  • CVE-2023-23369CriNov 3, 2023
    risk 0.60cvss 9.0epss 0.15

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: Multimedia Console…

  • CVE-2023-23368CriNov 3, 2023
    risk 0.65cvss 9.8epss 0.19

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2376 build…

  • CVE-2023-46980CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter.

  • CVE-2023-46404CriNov 3, 2023
    risk 0.65cvss 9.9epss 0.02

    PCRS <= 3.11 (d0de1e) “Questions” page and “Code editor” page are vulnerable to remote code execution (RCE) by escaping Python sandboxing.

  • CVE-2023-3961CriNov 3, 2023
    risk 0.59cvss 9.1epss 0.02

    A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services like SAMR LSA or SPOOLSS,…

  • CVE-2023-25960CriNov 3, 2023
    risk 0.65cvss 10.0epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zendrop Zendrop – Global Dropshipping zendrop-dropshipping-and-fulfillment allows SQL Injection.This issue affects Zendrop – Global Dropshipping: from n/a through 1.0.0.

  • CVE-2023-3277CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.03

    The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as…

  • CVE-2023-46846CriNov 3, 2023
    risk 0.61cvss 9.3epss 0.05

    SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems.

  • CVE-2023-41355CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of…

  • CVE-2023-41351CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log…

  • CVE-2023-46817CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unserialize() PHP function. This can be exploited by remote, unauthenticated attackers to inject arbitrary…

  • CVE-2023-43982CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Bon Presta boninstagramcarousel between v5.2.1 to v7.0.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at insta_parser.php. This vulnerability allows attackers to use the vulnerable website as proxy to attack other websites or exfiltrate…

  • CVE-2023-38965CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.

  • CVE-2023-36621CriNov 3, 2023
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in the Boomerang Parental Control application through 13.83 for Android. The child can use Safe Mode to remove all restrictions temporarily or uninstall the application without the parents noticing.

  • CVE-2023-46954CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Relativity ODA LLC RelativityOne v.12.1.537.3 Patch 2 and earlier allows a remote attacker to execute arbitrary code via the name parameter.

  • CVE-2023-46958CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file.

  • CVE-2023-42299CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_subimage_data function.

  • CVE-2023-31579CriNov 2, 2023
    risk 0.57cvss 9.8epss 0.01

    Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.

  • CVE-2023-45347CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_verified' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45346CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_role' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45345CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_deleted' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45338CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the routers/add-ticket.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45344CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_balance' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45343CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'ticket_id' parameter of the routers/ticket-message.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45342CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'phone' parameter of the routers/register-router.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45341CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_price' parameter of the routers/menu-router.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45340CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'phone' parameter of the routers/details-router.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45336CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the routers/router.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45334CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'status' parameter of the routers/edit-orders.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45325CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'address' parameter of the routers/add-users.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45323CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'name' parameter of the routers/add-item.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-42802CriNov 2, 2023
    risk 0.65cvss 10.0epss 0.01

    GLPI is a free asset and IT management software package. Starting in version 10.0.7 and prior to version 10.0.10, an unverified object instantiation allows one to upload malicious PHP files to unwanted directories. Depending on web server configuration and available system…

  • CVE-2023-47204CriNov 2, 2023
    risk 0.57cvss 9.8epss 0.01

    Unsafe YAML deserialization in yaml.Loader in transmute-core before 1.13.5 allows attackers to execute arbitrary Python code.

  • CVE-2023-45019CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'category' parameter of the category.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45018CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the includes/login.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45015CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'date' parameter of the bus_info.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45012CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'user_email' parameter of the bus_info.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45111CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Examination System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'email' parameter of the feed.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-44025CriNov 1, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in addify Addifyfreegifts v.1.0.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the getrulebyid function in the AddifyfreegiftsModel.php component.

  • CVE-2023-39281CriNov 1, 2023
    risk 0.64cvss 9.8epss 0.00

    A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrary code execution during the DXE phase.

  • CVE-2023-46482CriNov 1, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.

  • CVE-2023-5766CriNov 1, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from another windows user session on the same host via a specially crafted TCP packet.

  • CVE-2023-5765CriNov 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to bypass permissions via data source switching.

  • CVE-2023-20048CriNov 1, 2023
    risk 0.66cvss 9.9epss 0.16

    A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by the FMC Software.…

  • CVE-2023-1720CriNov 1, 2023
    risk 0.62cvss 9.6epss 0.01

    Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via uploading a crafted…

  • CVE-2023-1717CriNov 1, 2023
    risk 0.62cvss 9.6epss 0.01

    Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 allows remote attackers to execute arbitrary JavaScript code in the victim’s browser, and possibly execute arbitrary PHP code on the server if the victim has…

  • CVE-2023-1716CriNov 1, 2023
    risk 0.59cvss 9.0epss 0.01

    Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege.

  • CVE-2023-1715CriNov 1, 2023
    risk 0.59cvss 9.0epss 0.01

    A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass XSS sanitisation via placing HTML tags at the begining of the payload.

  • CVE-2023-46485CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi.cgi component.

  • CVE-2023-46484CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg function.