VYPR

CVEs

31,788 total · page 236 of 636

  • CVE-2023-44467CriOct 9, 2023
    risk 0.57cvss 9.8epss 0.01

    langchain_experimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the CVE-2023-36258 fix and execute arbitrary code via __import__ in Python code, which is not prohibited by pal_chain/base.py.

  • CVE-2023-5365CriOct 9, 2023
    risk 0.64cvss 9.8epss 0.01

    HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure.

  • CVE-2023-44393CriOct 9, 2023
    risk 0.00cvss 9.3epss 0.01

    Piwigo is an open source photo gallery application. Prior to version 14.0.0beta4, a reflected cross-site scripting (XSS) vulnerability is in the` /admin.php?page=plugins&tab=new&installstatus=ok&plugin_id=[here]` page. This vulnerability can be exploited by an attacker to inject…

  • CVE-2023-45199CriOct 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.

  • CVE-2023-45311CriOct 6, 2023
    risk 0.57cvss 9.8epss 0.02

    fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was…

  • CVE-2023-45239CriOct 6, 2023
    risk 0.00cvss 9.8epss 0.02

    A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled, allows an attacker who can control the username, rem-addr, or NAC address sent to tac_plus to inject shell commands and gain remote code execution on the…

  • CVE-2023-44807CriOct 6, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the cancelPing function.

  • CVE-2023-38703CriOct 6, 2023
    risk 0.00cvss 9.8epss 0.01

    PJSIP is a free and open source multimedia communication library written in C with high level API in C, C++, Java, C#, and Python languages. SRTP is a higher level media transport which is stacked upon a lower level media transport such as UDP and ICE. Currently a higher level…

  • CVE-2023-36465CriOct 6, 2023
    risk 0.52cvss 9.1epss 0.01

    Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to…

  • CVE-2023-4530CriOct 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Turna Advertising Administration Panel allows SQL Injection. This issue affects Advertising Administration Panel: before 1.1.

  • CVE-2023-43269CriOct 5, 2023
    risk 0.64cvss 9.8epss 0.01

    pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability.

  • CVE-2023-44024CriOct 5, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in KnowBand Module One Page Checkout, Social Login & Mailchimp (supercheckout) v.8.0.3 and before allows a remote attacker to execute arbitrary code via a crafted request to the updateCheckoutBehaviour function in the supercheckout.php component.

  • CVE-2023-43983CriOct 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Presto Changeo attributegrid up to 2.0.3 was discovered to contain a SQL injection vulnerability via the component disable_json.php.

  • CVE-2023-43981CriOct 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_folder.php.

  • CVE-2023-40920CriOct 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Prixan prixanconnect up to v1.62 was discovered to contain a SQL injection vulnerability via the component CartsGuruCatalogModuleFrontController::importProducts().

  • CVE-2023-32485CriOct 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability and escalate privileges up to the highest administration level. This is a critical severity vulnerability…

  • CVE-2023-2306CriOct 5, 2023
    risk 0.65cvss 10.0epss 0.00

    Qognify NiceVision versions 3.1 and prior are vulnerable to exposing sensitive information using hard-coded credentials. With these credentials an attacker can retrieve information about the cameras, user information, and modify database records.

  • CVE-2023-35803CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.02

    IQ Engine before 10.6r2 on Extreme Network AP devices has a Buffer Overflow.

  • CVE-2023-41094CriOct 4, 2023
    risk 0.65cvss 10.0epss 0.01

    TouchLink packets processed after timeout or out of range due to Operation on a Resource after Expiration and Missing Release of Resource after Effective Lifetime may allow a device to be added outside of valid TouchLink range or pairing duration This issue affects Ember ZNet…

  • CVE-2023-36619CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.04

    Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of administrative scripts by unauthenticated users.

  • CVE-2023-42809CriOct 4, 2023
    risk 0.55cvss 9.6epss 0.01

    Redisson is a Java Redis client that uses the Netty framework. Prior to version 3.22.0, some of the messages received from the Redis server contain Java objects that the client deserializes without further validation. Attackers that manage to trick clients into communicating…

  • CVE-2023-5399CriOct 4, 2023
    risk 0.67cvss 9.8epss 0.39

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on the personal computer running C-Bus when using the File Command.

  • CVE-2023-5391CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.

  • CVE-2023-38701CriOct 4, 2023
    risk 0.59cvss 9.1epss 0.01

    Hydra is the layer-two scalability solution for Cardano. Users of the Hydra head protocol send the UTxOs they wish to commit into the Hydra head first to the `commit` validator, where they remain until they are either collected into the `head` validator or the protocol…

  • CVE-2023-5402CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-269: Improper Privilege Management vulnerability exists that could cause a remote code execution when the transfer command is used over the network.

  • CVE-2023-20101CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the presence of static…

  • CVE-2022-36276CriOct 4, 2023
    risk 0.64cvss 9.9epss 0.01

    TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The exploitation of this vulnerability might allow a remote attacker to directly interact with the database.

  • CVE-2023-22515CriKEVOct 4, 2023
    risk 0.93cvss 9.8epss 0.99

    Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluence administrator accounts…

  • CVE-2023-4494CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow vulnerability in Easy Chat Server 3.1 version. An attacker could send an excessively long username string to the register.ghp file asking for the name via a GET request resulting in arbitrary code execution on the remote machine.

  • CVE-2023-4491CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow vulnerability in Easy Address Book Web Server 1.6 version. The exploitation of this vulnerability could allow an attacker to send a very long username string to /searchbook.ghp, asking for the name via a POST request, resulting in arbitrary code execution on the…

  • CVE-2023-4037CriOct 4, 2023
    risk 0.64cvss 9.9epss 0.00

    Blind SQL injection vulnerability in the Conacwin 3.7.1.2 web interface, the exploitation of which could allow a local attacker to obtain sensitive data stored in the database by sending a specially crafted SQL query to the xml parameter.

  • CVE-2023-44208CriOct 4, 2023
    risk 0.59cvss 9.1epss 0.00

    Sensitive information disclosure and manipulation due to missing authorization. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575.

  • CVE-2023-3038CriOct 4, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the rows parameter of the jsonGrid route and extract all the information stored in the application.

  • CVE-2023-3701CriOct 4, 2023
    risk 0.64cvss 9.9epss 0.01

    Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerability, an authenticated non privileged user could access/modify stored resources of other users. It could also be possible to access and modify the source and…

  • CVE-2023-39647CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper neutralization of SQL parameter in Theme Volty CMS Category Product module for PrestaShop. In the module “Theme Volty CMS Category Product” (tvcmscategoryproduct) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected…

  • CVE-2023-39651CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper neutralization of SQL parameter in Theme Volty CMS BrandList module for PrestaShop In the module “Theme Volty CMS BrandList” (tvcmsbrandlist) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

  • CVE-2023-39649CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper neutralization of SQL parameter in Theme Volty CMS Category Slider module for PrestaShop. In the module “Theme Volty CMS Category Slider” (tvcmscategoryslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected…

  • CVE-2023-39648CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module “Theme Volty CMS Testimonial” (tvcmstestimonial) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

  • CVE-2023-39646CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper neutralization of SQL parameter in Theme Volty CMS Category Chain Slider module for PrestaShop. In the module “Theme Volty CMS Category Chain Slide"(tvcmscategorychainslider) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in…

  • CVE-2023-44974CriOct 3, 2023
    risk 0.65cvss 9.8epss 0.19

    An arbitrary file upload vulnerability in the component /admin/plugin.php of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2023-44973CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /content/templates/ of Emlog Pro v2.2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2023-39645CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper neutralization of SQL parameter in Theme Volty CMS Payment Icon module for PrestaShop. In the module “Theme Volty CMS Payment Icon” (tvcmspaymenticon) up to version 4.0.1 from Theme Volty for PrestaShop, a guest can perform SQL injection in affected versions.

  • CVE-2023-33273CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS command injection (blind).

  • CVE-2023-33272CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS command injection (blind).

  • CVE-2023-33271CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in DTS Monitoring 3.57.0. The parameter common_name within the SSL Certificate check function is vulnerable to OS command injection (blind).

  • CVE-2023-33270CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the Curl check function is vulnerable to OS command injection (blind).

  • CVE-2023-33269CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in DTS Monitoring 3.57.0. The parameter options within the WGET check function is vulnerable to OS command injection (blind).

  • CVE-2023-33268CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in DTS Monitoring 3.57.0. The parameter port within the SSL Certificate check function is vulnerable to OS command injection (blind).

  • CVE-2023-40830CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 v15.03.05.19 is vulnerable to Buffer Overflow as the Index parameter does not verify the length.

  • CVE-2023-32670CriOct 3, 2023
    risk 0.59cvss 9.0epss 0.00

    Cross-Site Scripting vulnerability in BuddyBoss 2.2.9 version , which could allow a local attacker with basic privileges to execute a malicious payload through the "[name]=image.jpg" parameter, allowing to assign a persistent javascript payload that would be triggered when…