VYPR

CVEs

31,788 total · page 237 of 636

  • CVE-2023-5350CriOct 3, 2023
    risk 0.03cvss 9.1epss 0.02

    SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.

  • CVE-2022-47893CriOct 3, 2023
    risk 0.65cvss 10.0epss 0.01

    There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a firmware file containing a webshell, that could allow him to execute arbitrary code as root.

  • CVE-2023-3654CriOct 3, 2023
    risk 0.61cvss 9.4epss 0.00

    cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by a origin bypass via the host header in an HTTP request. This vulnerability can be triggered by an HTTP endpoint exposed to the network.

  • CVE-2023-3656CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by an unauthenticated remote code execution vulnerability. This vulnerability can be triggered by an HTTP endpoint exposed to the network.

  • CVE-2023-33028CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory corruption in WLAN Firmware while doing a memory copy of pmk cache.

  • CVE-2023-28540CriOct 3, 2023
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue in Data Modem due to improper authentication during TLS handshake.

  • CVE-2023-24855CriOct 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory corruption in Modem while processing security related configuration before AS Security Exchange.

  • CVE-2023-43980CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component disable_json.php.

  • CVE-2023-44011CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component.

  • CVE-2023-43893CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.02

    Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload.

  • CVE-2023-43892CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.02

    Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings. This vulnerability is exploited via a crafted payload.

  • CVE-2023-43891CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.02

    Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a crafted payload.

  • CVE-2023-44009CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.

  • CVE-2023-44008CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.

  • CVE-2023-4659CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.00

    Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE requests without any token…

  • CVE-2023-3744CriOct 2, 2023
    risk 0.64cvss 9.9epss 0.00

    Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter.

  • CVE-2023-20819CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.01

    In CDMA PPP protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: MOLY01068234; Issue ID:…

  • CVE-2023-5201CriSep 30, 2023
    risk 0.64cvss 9.9epss 0.01

    The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server. This requires the [php]…

  • CVE-2023-5227CriSep 30, 2023
    risk 0.57cvss 9.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

  • CVE-2023-43909CriSep 29, 2023
    risk 0.59cvss 9.1epss 0.01

    Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.

  • CVE-2023-5288CriSep 29, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may also reset the SIM and in the worst case upload a new firmware version to the device.

  • CVE-2023-43654CriSep 28, 2023
    risk 0.64cvss 10.0epss 0.35

    TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper input validation, enabling third parties to invoke remote HTTP download requests and write files to the disk. This issue could be taken advantage of to…

  • CVE-2023-44166CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-44164CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-44163CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-43739CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-5185CriSep 28, 2023
    risk 0.59cvss 9.1epss 0.01

    Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of profile/i.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

  • CVE-2023-5053CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.

  • CVE-2023-5004CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.

  • CVE-2023-43013CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.

  • CVE-2023-30415CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php.

  • CVE-2023-43869CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard56 function.

  • CVE-2023-44273CriSep 28, 2023
    risk 0.57cvss 9.8epss 0.01

    Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.

  • CVE-2023-38870CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'category_id' parameter is vulnerable to SQL Injection.

  • CVE-2023-41449CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.

  • CVE-2023-44080CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request to the branchList component.

  • CVE-2023-4523CriSep 27, 2023
    risk 0.61cvss 9.4epss 0.00

    Real Time Automation 460 Series products with versions prior to v8.9.8 are vulnerable to cross-site scripting, which could allow an attacker to run any JavaScript reference from the URL string. If this were to occur, the gateway's HTTP interface would redirect to the main page,…

  • CVE-2023-20252CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker to gain unauthorized access to the application as an arbitrary user. This vulnerability is due to improper…

  • CVE-2023-5183CriSep 27, 2023
    risk 0.64cvss 9.9epss 0.02

    Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoint. An attacker can leverage this…

  • CVE-2023-5176CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox <…

  • CVE-2023-5175CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepath, leading to a potentially exploitable crash. This vulnerability affects Firefox < 118.

  • CVE-2023-5174CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations…

  • CVE-2023-5172CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 118.

  • CVE-2023-5168CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This…

  • CVE-2023-4737CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hedef Tracking Admin Panel allows SQL Injection. This issue affects Admin Panel: before 1.2.

  • CVE-2023-44206CriSep 27, 2023
    risk 0.59cvss 9.1epss 0.01

    Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

  • CVE-2023-44172CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.

  • CVE-2023-44171CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.

  • CVE-2023-44170CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.

  • CVE-2023-44169CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.