VYPR

CVEs

31,788 total · page 233 of 636

  • CVE-2023-37824CriOct 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Sitolog sitologapplicationconnect v7.8.a and before was discovered to contain a SQL injection vulnerability via the component /activate_hook.php.

  • CVE-2023-5414CriOct 20, 2023
    risk 0.59cvss 9.1epss 0.01

    The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive…

  • CVE-2023-4488CriOct 20, 2023
    risk 0.64cvss 9.8epss 0.01

    The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via the editor-view.php file. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code…

  • CVE-2020-36706CriOct 20, 2023
    risk 0.64cvss 9.8epss 0.02

    The Simple:Press – WordPress Forum Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ~/admin/resources/jscript/ajaxupload/sf-uploader.php file in versions up to, and including, 6.6.0. This makes it possible for attackers to…

  • CVE-2023-34051CriOct 20, 2023
    risk 0.67cvss 9.8epss 0.45

    VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.

  • CVE-2023-30131CriOct 19, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege, and cause other unspecified impacts via unauthenticated API calls.

  • CVE-2023-45376CriOct 19, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "Carousels Pack - Instagram, Products, Brands, Supplier" (hicarouselspack) for PrestaShop up to version 1.5.0 from HiPresta for PrestaShop, a guest can perform SQL injection via HiCpProductGetter::getViewedProduct().`

  • CVE-2023-43492CriOct 19, 2023
    risk 0.64cvss 9.8epss 0.01

    In Weintek's cMT3000 HMI Web CGI device, the cgi-bin codesys.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.

  • CVE-2023-38584CriOct 19, 2023
    risk 0.64cvss 9.8epss 0.01

    In Weintek's cMT3000 HMI Web CGI device, the cgi-bin command_wb.cgi contains a stack-based buffer overflow, which could allow an anonymous attacker to hijack control flow and bypass login authentication.

  • CVE-2022-42150CriOct 19, 2023
    risk 0.65cvss 10.0epss 0.01

    TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configuration could cause Container Escape.

  • CVE-2023-45992CriOct 19, 2023
    risk 0.62cvss 9.6epss 0.01

    A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack,…

  • CVE-2023-45381CriOct 19, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "Creative Popup" (creativepopup) up to version 1.6.9 from WebshopWorks for PrestaShop, a guest can perform SQL injection via `cp_download_popup().`

  • CVE-2023-43986CriOct 19, 2023
    risk 0.64cvss 9.8epss 0.01

    DM Concept configurator before v4.9.4 was discovered to contain a SQL injection vulnerability via the component ConfiguratorAttachment::getAttachmentByToken.

  • CVE-2023-45278CriOct 19, 2023
    risk 0.59cvss 9.1epss 0.02

    Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request.

  • CVE-2022-47583CriOct 19, 2023
    risk 0.64cvss 9.8epss 0.01

    Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal.

  • CVE-2023-46042CriOct 19, 2023
    risk 0.66cvss 9.8epss 0.23

    An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a crafted payload to the phpinfo().

  • CVE-2023-45384CriOct 19, 2023
    risk 0.64cvss 9.8epss 0.01

    KnowBand supercheckout > 5.0.7 and < 6.0.7 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the module "Module One Page Checkout, Social Login & Mailchimp" (supercheckout), a guest can upload files with extensions .php

  • CVE-2023-45379CriOct 19, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "Rotator Img" (posrotatorimg) in versions at least up to 1.1 from PosThemes for PrestaShop, a guest can perform SQL injection.

  • CVE-2022-37830CriOct 19, 2023
    risk 0.62cvss 9.6epss 0.01

    Interway a.s WebJET CMS 8.6.896 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2022-26941CriOct 19, 2023
    risk 0.62cvss 9.6epss 0.00

    A format string vulnerability exists in Motorola MTM5000 series firmware AT command handler for the AT+CTGL command. An attacker-controllable string is improperly handled, allowing for a write-anything-anywhere scenario. This can be leveraged to obtain arbitrary code execution…

  • CVE-2023-5241CriOct 19, 2023
    risk 0.63cvss 9.6epss 0.02

    The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload_pagetraining_file function. This allows subscriber-level attackers to append "<?php" to any existing file on the server resulting…

  • CVE-2023-5212CriOct 19, 2023
    risk 0.63cvss 9.6epss 0.02

    The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This makes it possible for authenticated attackers with subscriber privileges to delete arbitrary files on the server, which makes it…

  • CVE-2023-5204CriOct 19, 2023
    risk 0.64cvss 9.8epss 0.07

    The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…

  • CVE-2023-37502CriOct 18, 2023
    risk 0.59cvss 9.0epss 0.00

    HCL Compass is vulnerable to lack of file upload security.  An attacker could upload files containing active code that can be executed by the server or by a user's web browser.

  • CVE-2023-45146CriOct 18, 2023
    risk 0.59cvss 9.0epss 0.01

    XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization mechanism. When such a configuration is used, attackers may be able to connect to the server and provide malicious serialized…

  • CVE-2023-45911CriOct 18, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user without a password.

  • CVE-2023-5642CriOct 18, 2023
    risk 0.65cvss 9.8epss 0.17

    Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to the snmpmon.ini file, which contains sensitive information.

  • CVE-2023-46007CriOct 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_staff.php.

  • CVE-2023-46006CriOct 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_user.php.

  • CVE-2023-46005CriOct 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_branch.php.

  • CVE-2023-39332CriOct 18, 2023
    risk 0.64cvss 9.8epss 0.02

    Various `node:fs` functions allow specifying paths as either strings or `Uint8Array` objects. In Node.js environments, the `Buffer` class extends the `Uint8Array` class. Node.js prevents path traversal through strings (see CVE-2023-30584) and `Buffer` objects (see…

  • CVE-2023-38545CriOct 18, 2023
    risk 0.70cvss 9.8epss 0.78

    This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255…

  • CVE-2023-35084CriOct 18, 2023
    risk 0.64cvss 9.8epss 0.03

    Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions, which could allow an attacker to execute commands remotely.

  • CVE-2023-41630CriOct 17, 2023
    risk 0.64cvss 9.8epss 0.01

    eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the Gii code generator component.

  • CVE-2023-22089CriOct 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to…

  • CVE-2023-22072CriOct 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle…

  • CVE-2023-22069CriOct 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to…

  • CVE-2023-45952CriOct 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component ajax_link.php of lylme_spage v1.7.0 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-45951CriOct 17, 2023
    risk 0.64cvss 9.8epss 0.01

    lylme_spage v1.7.0 was discovered to contain a SQL injection vulnerability via the $userip parameter at function.php.

  • CVE-2023-27133CriOct 17, 2023
    risk 0.64cvss 9.8epss 0.01

    TSplus Remote Work 16.0.0.0 has weak permissions for .exe, .js, and .html files under the %PROGRAMFILES(X86)%\TSplus-RemoteWork\Clients\www folder. This may enable privilege escalation if a different local user modifies a file. NOTE: CVE-2023-31067 and CVE-2023-31068 are only…

  • CVE-2023-27132CriOct 17, 2023
    risk 0.64cvss 9.8epss 0.01

    TSplus Remote Work 16.0.0.0 places a cleartext password on the "var pass" line of the HTML source code for the secure single sign-on web portal. NOTE: CVE-2023-31069 is only about the TSplus Remote Access product, not the TSplus Remote Work product.

  • CVE-2023-42627CriOct 17, 2023
    risk 0.63cvss 9.6epss 0.02

    Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay DXP 7.3 update 33 and earlier, and 7.4 before update 92 allow remote attackers to inject arbitrary web script or HTML via a crafted payload…

  • CVE-2023-42628CriOct 17, 2023
    risk 0.59cvss 9.0epss 0.02

    Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83 through 102, 7.1 fix pack 28 and earlier, 7.2 fix pack 20 and earlier, 7.3 update 33 and earlier, and 7.4 before update 88 allows remote…

  • CVE-2023-44311CriOct 17, 2023
    risk 0.55cvss 9.6epss 0.00

    Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.89, and Liferay DXP 7.4 update 41 through update 89 allow remote attackers to inject arbitrary web…

  • CVE-2023-44310CriOct 17, 2023
    risk 0.52cvss 9.0epss 0.00

    Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before update 79 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into…

  • CVE-2023-44309CriOct 17, 2023
    risk 0.52cvss 9.0epss 0.00

    Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, and Liferay DXP 7.4 before update 54 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into any non-HTML…

  • CVE-2023-42629CriOct 17, 2023
    risk 0.52cvss 9.0epss 0.02

    Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Vocabulary's…

  • CVE-2023-42497CriOct 17, 2023
    risk 0.62cvss 9.6epss 0.00

    Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_translation_web_internal_por…

  • CVE-2023-44694CriOct 17, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /log/mailrecvview.php.

  • CVE-2023-44693CriOct 17, 2023
    risk 0.65cvss 9.8epss 0.13

    D-Link Online behavior audit gateway DAR-7000 V31R02B1413C is vulnerable to SQL Injection via /importexport.php.