VYPR

CVEs

31,788 total · page 230 of 636

  • CVE-2023-46249CriOct 31, 2023
    risk 0.00cvss 9.6epss 0.01

    authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin user without any authentication. authentik uses a blueprint…

  • CVE-2023-46248CriOct 31, 2023
    risk 0.59cvss 9.0epss 0.01

    Cody is an artificial intelligence (AI) coding assistant. The Cody AI VSCode extension versions 0.10.0 through 0.14.0 are vulnerable to Remote Code Execution under certain conditions. An attacker in control of a malicious repository could modify the Cody configuration file…

  • CVE-2023-46993CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable parameter, which can lead to command injection.

  • CVE-2023-42425CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud connection components.

  • CVE-2023-40050CriOct 31, 2023
    risk 0.64cvss 9.9epss 0.01

    Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.

  • CVE-2023-22518CriKEVOct 31, 2023
    risk 0.93cvss 9.8epss 1.00

    All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an…

  • CVE-2023-5360CriOct 31, 2023
    risk 0.73cvss 9.8epss 0.82

    The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

  • CVE-2023-46979CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the setLedCfg function.

  • CVE-2023-46977CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.09

    TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the function loginAuth.

  • CVE-2023-46976CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFile function.

  • CVE-2023-43139CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in franfinance before v.2.0.27 allows a remote attacker to execute arbitrary code via the validation.php, and controllers/front/validation.php components.

  • CVE-2023-36263CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.00

    Prestashop opartlimitquantity 1.4.5 and before is vulnerable to SQL Injection. OpartlimitquantityAlertlimitModuleFrontController::displayAjaxPushAlertMessage()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

  • CVE-2023-47174CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.

  • CVE-2023-46356CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection. The method `SearchApiCsv::getProducts()` has sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.

  • CVE-2023-45378CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "PrestaBlog" (prestablog) version 4.4.7 and before from HDclic for PrestaShop, a guest can perform SQL injection. The script ajax slider_positions.php has a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.

  • CVE-2023-27846CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop themevolty v.4.0.8 and before allow a remote attacker to gain privileges via the tvcmsblog, tvcmsvideotab, tvcmswishlist, tvcmsbrandlist, tvcmscategorychainslider, tvcmscategoryproduct, tvcmscategoryslider, tvcmspaymenticon,…

  • CVE-2023-5865CriOct 31, 2023
    risk 0.57cvss 9.8epss 0.01

    Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

  • CVE-2023-46502CriOct 30, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuilderFactory.

  • CVE-2023-43792CriOct 30, 2023
    risk 0.64cvss 9.8epss 0.01

    baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.

  • CVE-2023-47104CriOct 30, 2023
    risk 0.64cvss 9.8epss 0.01

    tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, which only considered single and double…

  • CVE-2023-5843CriOct 30, 2023
    risk 0.52cvss 9.0epss 0.02

    The Ads by datafeedr.com plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.3 via the 'dfads_ajax_load_ads' function. This allows unauthenticated attackers to execute code on the server. The parameters of the callable function are…

  • CVE-2023-5199CriOct 30, 2023
    risk 0.64cvss 9.9epss 0.01

    The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to include local file and…

  • CVE-2023-5832CriOct 30, 2023
    risk 0.00cvss 9.1epss 0.01

    Improper Input Validation in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.

  • CVE-2023-45797CriOct 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A Buffer overflow vulnerability in DreamSecurity MagicLine4NX versions 1.0.0.1 to 1.0.0.26 allows an attacker to remotely execute code.

  • CVE-2021-33635CriOct 29, 2023
    risk 0.64cvss 9.8epss 0.01

    When malicious images are pulled by isula pull, attackers can execute arbitrary code.

  • CVE-2023-5838CriOct 29, 2023
    risk 0.00cvss 9.8epss 0.01

    Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.

  • CVE-2023-46570CriOct 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h.

  • CVE-2023-46569CriOct 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h.

  • CVE-2023-46510CriOct 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in ZIONCOM (Hong Kong) Technology Limited A7000R v.4.1cu.4154 allows an attacker to execute arbitrary code via the cig-bin/cstecgi.cgi to the settings/setPasswordCfg function.

  • CVE-2023-46509CriOct 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.

  • CVE-2023-46853CriOct 27, 2023
    risk 0.00cvss 9.8epss 0.01

    In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.

  • CVE-2023-46604CriKEVOct 27, 2023
    risk 0.22cvss 10.0epss 1.00

    The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the…

  • CVE-2023-5807CriOct 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TRtek Software Education Portal allows SQL Injection. This issue affects Education Portal: before 3.2023.29.

  • CVE-2023-5820CriOct 27, 2023
    risk 0.62cvss 9.6epss 0.00

    The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files…

  • CVE-2023-45499CriOct 27, 2023
    risk 0.67cvss 9.8epss 0.08

    VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.

  • CVE-2023-45498CriOct 27, 2023
    risk 0.68cvss 9.8epss 0.20

    VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability.

  • CVE-2023-42406CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in D-Link Online behavior audit gateway DAR-7000 V31R02B1413C allows a remote attacker to obtain sensitive information and execute arbitrary code via the editrole.php component.

  • CVE-2018-17879CriOct 26, 2023
    risk 0.65cvss 9.8epss 0.22

    An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. There are several injection points in various scripts.

  • CVE-2018-17878CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in certain ABUS TVIP cameras allows attackers to gain control of the program via crafted string sent to sprintf() function.

  • CVE-2018-17558CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.03

    Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM.1.6.18, TVIP10050 LM.1.6.18, TVIP11550 MG.1.6.03, TVIP21050 MG.1.6.03, and…

  • CVE-2023-46747CriKEVOct 26, 2023
    risk 0.92cvss 9.8epss 0.97

    Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of…

  • CVE-2023-46665CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative privileges.

  • CVE-2023-39726CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.

  • CVE-2023-5754CriOct 26, 2023
    risk 0.59cvss 9.1epss 0.00

    Sielco PolyEco1000 uses a weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.

  • CVE-2023-46661CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.

  • CVE-2023-44267CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'lnm' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-46435CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Packers and Movers Management System v1.0 is vulnerable to SQL Injection via mpms/?p=services/view_service&id.

  • CVE-2023-43208CriKEVOct 26, 2023
    risk 0.91cvss 9.8epss 0.83

    NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.

  • CVE-2023-42769CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.

  • CVE-2023-45869CriOct 26, 2023
    risk 0.59cvss 9.0epss 0.01

    ILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a highly privileged account accesses an XSS payload. The injected commands are executed via the exec() function in the execQuoted() method of the ilUtil class…