VYPR

CVEs

31,788 total · page 232 of 636

  • CVE-2023-46543CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formWlSiteSurvey.

  • CVE-2023-46542CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formMeshUploadConfig.

  • CVE-2023-46541CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpv6Setup.

  • CVE-2023-46540CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formNtp.

  • CVE-2023-46539CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function registerRequestHandle.

  • CVE-2023-46538CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function chkResetVeriRegister.

  • CVE-2023-46537CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function getRegVeriRegister.

  • CVE-2023-46536CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function chkRegVeriRegister.

  • CVE-2023-46535CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function getResetVeriRegister.

  • CVE-2023-46534CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function modifyAccPwdRegister.

  • CVE-2023-46527CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 was discovered to contain a stack overflow via the function bindRequestHandle.

  • CVE-2023-46526CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function resetCloudPwdRegister.

  • CVE-2023-46525CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function loginRegister.

  • CVE-2023-46523CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function upgradeInfoRegister.

  • CVE-2023-46522CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-LINK device TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 were discovered to contain a stack overflow via the function deviceInfoRegister.

  • CVE-2023-46521CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function RegisterRegister.

  • CVE-2023-46520CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function uninstallPluginReqHandle.

  • CVE-2023-46518CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    Mercury A15 V1.0 20230818_1.0.3 was discovered to contain a command execution vulnerability via the component cloudDeviceTokenSuccCB.

  • CVE-2023-46373CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-Link TL-WDR7660 2.0.30 has a stack overflow vulnerability via the function deviceInfoJsonToBincauses.

  • CVE-2023-46371CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-Link device TL-WDR7660 2.0.30 and TL-WR886N 2.0.12 has a stack overflow vulnerability via the function upgradeInfoJsonToBin.

  • CVE-2023-46370CriOct 25, 2023
    risk 0.65cvss 9.8epss 0.18

    Tenda W18E V16.01.0.8(1576) has a command injection vulnerability via the hostName parameter in the formSetNetCheckTools function.

  • CVE-2023-46369CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W18E V16.01.0.8(1576) contains a stack overflow vulnerability via the portMirrorMirroredPorts parameter in the formSetNetCheckTools function.

  • CVE-2023-46358CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "Referral and Affiliation Program" (referralbyphone) version 3.5.1 and before from Snegurka for PrestaShop, a guest can perform SQL injection. Method `ReferralByPhoneDefaultModuleFrontController::ajaxProcessCartRuleValidate` has sensitive SQL calls that can be…

  • CVE-2023-46347CriOct 25, 2023
    risk 0.68cvss 9.8epss 0.50

    In the module "Step by Step products Pack" (ndk_steppingpack) version 1.5.6 and before from NDK Design for PrestaShop, a guest can perform SQL injection. The method `NdkSpack::getPacks()` has sensitive SQL calls that can be executed with a trivial http call and exploited to…

  • CVE-2023-46010CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.

  • CVE-2023-45554CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    File Upload vulnerability in zzzCMS v.2.1.9 allows a remote attacker to execute arbitrary code via modification of the imageext parameter from jpg, jpeg,gif, and png to jpg, jpeg,gif, png, pphphp.

  • CVE-2023-44794CriOct 25, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.

  • CVE-2023-37913CriOct 25, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 3.5-milestone-1 and prior to versions 14.10.8 and 15.3-rc-1, triggering the office converter with a specially crafted file name allows writing the…

  • CVE-2023-37912CriOct 25, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. Prior to version 14.10.6 of `org.xwiki.platform:xwiki-core-rendering-macro-footnotes` and `org.xwiki.platform:xwiki-rendering-macro-footnotes` and prior to version…

  • CVE-2023-37909CriOct 25, 2023
    risk 0.57cvss 9.9epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.1-rc-1 and prior to versions 14.10.8 and 15.3-rc-1, any user who can edit their own user profile can execute arbitrary script macros including Groovy…

  • CVE-2023-37908CriOct 25, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. The cleaning of attributes during XHTML rendering, introduced in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus cross-site scripting via…

  • CVE-2023-34048CriKEVOct 25, 2023
    risk 0.84cvss 9.8epss 0.99

    vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds write potentially leading to remote code execution.

  • CVE-2023-31581CriOct 25, 2023
    risk 0.57cvss 9.8epss 0.01

    Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.

  • CVE-2023-27262CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

  • CVE-2023-27260CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated SQL injection in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

  • CVE-2023-27255CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated SQL injection in the DeleteRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

  • CVE-2023-27254CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated SQL injection in the GetRoomChanges method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

  • CVE-2023-26584CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated SQL injection in the GetStudentInconsistencies method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

  • CVE-2023-26583CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated SQL injection in the GetCurrentPeriod method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

  • CVE-2023-26582CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated SQL injection in the GetExcursionDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

  • CVE-2023-26581CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated SQL injection in the GetVisitors method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

  • CVE-2023-26572CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated SQL injection in the GetExcursionList method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

  • CVE-2023-26569CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated SQL injection in the StudentPopupDetails_Timetable method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

  • CVE-2023-26568CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated SQL injection in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction or modification of all data by unauthenticated attackers.

  • CVE-2023-37635CriOct 23, 2023
    risk 0.64cvss 9.8epss 0.01

    UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.

  • CVE-2023-27152CriOct 23, 2023
    risk 0.64cvss 9.8epss 0.01

    DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.

  • CVE-2023-46322CriOct 23, 2023
    risk 0.00cvss 9.8epss 0.01

    iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characters may be outside the set of alphanumeric characters, dash, and period.

  • CVE-2023-46321CriOct 23, 2023
    risk 0.00cvss 9.8epss 0.01

    iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell metacharacters for a /usr/bin/man command line.

  • CVE-2023-46301CriOct 22, 2023
    risk 0.00cvss 9.8epss 0.01

    iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to upload.

  • CVE-2023-46300CriOct 22, 2023
    risk 0.00cvss 9.8epss 0.01

    iTerm2 before 3.4.20 allow (potentially remote) code execution because of mishandling of certain escape sequences related to tmux integration.