VYPR

CVEs

31,788 total · page 238 of 636

  • CVE-2023-44152CriSep 27, 2023
    risk 0.59cvss 9.1epss 0.01

    Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.

  • CVE-2023-44023CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

  • CVE-2023-44022CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.

  • CVE-2023-44021CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the formSetClientState function.

  • CVE-2023-44020CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function.

  • CVE-2023-44019CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the mac parameter in the GetParentControlInfo function.

  • CVE-2023-44018CriSep 27, 2023
    risk 0.65cvss 9.8epss 0.15

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the domain parameter in the add_white_node function.

  • CVE-2023-44017CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function.

  • CVE-2023-44016CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.

  • CVE-2023-44015CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the schedEndTime parameter in the setSchedWifi function.

  • CVE-2023-44014CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain multiple stack overflows in the formSetMacFilterCfg function via the macFilterType and deviceList parameters.

  • CVE-2023-44013CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the list parameter in the fromSetIpMacBind function.

  • CVE-2023-43291CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.02

    Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.

  • CVE-2023-43234CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath and $filename parameters.

  • CVE-2023-43222CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.

  • CVE-2023-43216CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.

  • CVE-2023-43187CriSep 27, 2023
    risk 0.67cvss 9.8epss 0.45

    A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.

  • CVE-2023-43154CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account.

  • CVE-2023-42657CriSep 27, 2023
    risk 0.66cvss 9.9epss 0.17

    In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered.  An attacker could leverage this vulnerability to perform file operations (delete, rename, rmdir, mkdir) on files and folders outside of their authorized WS_FTP folder…

  • CVE-2023-40455CriSep 27, 2023
    risk 0.65cvss 10.0epss 0.01

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.

  • CVE-2023-40436CriSep 27, 2023
    risk 0.59cvss 9.1epss 0.01

    The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14. An attacker may be able to cause unexpected system termination or read kernel memory.

  • CVE-2023-40400CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.02

    This issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. A remote user may cause an unexpected app termination or arbitrary code execution.

  • CVE-2023-40044CriKEVSep 27, 2023
    risk 0.93cvss 10.0epss 0.90

    In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.

  • CVE-2023-3767CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An OS command injection vulnerability has been found on EasyPHP Webserver affecting version 14.1. This vulnerability could allow an attacker to get full access to the system by sending a specially crafted exploit to the /index.php?zone=settings parameter.

  • CVE-2023-38586CriSep 27, 2023
    risk 0.65cvss 10.0epss 0.01

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.

  • CVE-2023-35071CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection. This issue affects Logging Administration Panel: before 20230915 .

  • CVE-2021-38243CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    xunruicms up to v4.5.1 was discovered to contain a remote code execution (RCE) vulnerability in /index.php. This vulnerability allows attackers to execute arbitrary code via a crafted GET request.

  • CVE-2023-43457CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint.

  • CVE-2023-43644CriSep 25, 2023
    risk 0.52cvss 9.1epss 0.01

    Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-box. This affects all SOCKS5 inbounds with user authentication and an attacker may be able to bypass authentication. Users are…

  • CVE-2023-39640CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    UpLight cookiebanner before 1.5.1 was discovered to contain a SQL injection vulnerability via the component Hook::getHookModuleExecList().

  • CVE-2023-4521CriSep 25, 2023
    risk 0.67cvss 9.8epss 0.39

    The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue…

  • CVE-2023-4490CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.03

    The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

  • CVE-2023-43141CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.

  • CVE-2023-40163CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds write vulnerability exists in the allocate_buffer_for_jpeg_decoding functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2023-39453CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    A use-after-free vulnerability exists in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can deliver this file to trigger this vulnerability.

  • CVE-2023-35002CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2023-32653CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

  • CVE-2023-43131CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow.

  • CVE-2022-48605CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.00

    Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.

  • CVE-2023-41419CriSep 25, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.

  • CVE-2023-41297CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.00

    Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exploitation of this vulnerability may cause service hijacking.

  • CVE-2023-41296CriSep 25, 2023
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality.

  • CVE-2023-41294CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.00

    The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.

  • CVE-2023-39407CriSep 25, 2023
    risk 0.59cvss 9.1epss 0.00

    The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.

  • CVE-2023-43470CriSep 23, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in janobe Online Voting System v.1.0 allows a remote attacker to execute arbitrary code via the checklogin.php component.

  • CVE-2023-43469CriSep 23, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the ForPass.php component.

  • CVE-2023-43468CriSep 23, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the login.php component.

  • CVE-2023-43338CriSep 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr(). This vulnerability allows attackers to execute arbitrary code via a crafted input.

  • CVE-2023-43130CriSep 22, 2023
    risk 0.64cvss 9.8epss 0.02

    D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection.

  • CVE-2023-43129CriSep 22, 2023
    risk 0.64cvss 9.8epss 0.02

    D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of REMOTE_PORT parameters.