VYPR

CVEs

31,788 total · page 239 of 636

  • CVE-2023-40989CriSep 22, 2023
    risk 0.57cvss 9.8epss 0.02

    SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component.

  • CVE-2023-43270CriSep 22, 2023
    risk 0.64cvss 9.8epss 0.01

    dst-admin v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the userId parameter at /home/playerOperate.

  • CVE-2023-43144CriSep 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.

  • CVE-2023-43762CriSep 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend). This affects WithSecure Policy Manager 15 and Policy Manager Proxy 15.

  • CVE-2023-31719CriSep 22, 2023
    risk 0.66cvss 9.8epss 0.27

    FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.

  • CVE-2023-43128CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.02

    D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of HTTP_ST parameters.

  • CVE-2023-34576CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in updatepos.php in PrestaShop opartfaq through 1.0.3 allows remote attackers to run arbitrary SQL commands via unspedified vector.

  • CVE-2023-42810CriSep 21, 2023
    risk 0.57cvss 9.8epss 0.02

    systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter check in version 5.21.7. As a workaround, check or sanitize parameter strings that are passed to…

  • CVE-2023-42279CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Dreamer CMS v4.1.3 was discovered to contain a SQL injection vulnerability via the model-form-management-field form.

  • CVE-2023-34577CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Prestashop opartplannedpopup 1.4.11 and earlier allows remote attackers to run arbitrary SQL commands via OpartPlannedPopupModuleFrontController::prepareHook() method.

  • CVE-2023-43632CriSep 21, 2023
    risk 0.59cvss 9.0epss 0.01

    As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited functionality of the TPM to the clients. VTPM allows clients to execute tpm2-tools binaries from a list of hardcoded options” The communication…

  • CVE-2023-43242CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter removeRuleList in form2IPQoSTcDel.

  • CVE-2023-43241CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter TXPower and GuardInt in SetWLanRadioSecurity.

  • CVE-2023-43240CriSep 21, 2023
    risk 0.65cvss 9.8epss 0.12

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter sip_address in ipportFilter.

  • CVE-2023-43239CriSep 21, 2023
    risk 0.65cvss 9.8epss 0.12

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter flag_5G in showMACfilterMAC.

  • CVE-2023-43238CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter nvmacaddr in form2Dhcpip.cgi.

  • CVE-2023-43237CriSep 21, 2023
    risk 0.65cvss 9.8epss 0.12

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter macCloneMac in setMAC.

  • CVE-2023-43236CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter statuscheckpppoeuser in dir_setWanWifi.

  • CVE-2023-43235CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter StartTime and EndTime in SetWifiDownSettings.

  • CVE-2023-4291CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a remote code execution (RCE) vulnerability via manipulated parameters of the web interface without authentication. This could lead to a full compromise of the FDS101 device. …

  • CVE-2015-5467CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter.

  • CVE-2023-43135CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    There is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend management.

  • CVE-2023-39675CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.

  • CVE-2023-36109CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.02

    Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_raw component at /jerry-core/ecma/base/ecma-helpers-string.c.

  • CVE-2023-34575CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in PrestaShop opartsavecart through 2.0.7 allows remote attackers to run arbitrary SQL commands via OpartSaveCartDefaultModuleFrontController::initContent() and OpartSaveCartDefaultModuleFrontController::displayAjaxSendCartByEmail() methods.

  • CVE-2023-42322CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information.

  • CVE-2023-43134CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    There is an unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend management.

  • CVE-2023-43375CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonascita, annoscaddoc, giornonascita, giornoscaddoc, lingua_cli, mesenascita, and mesescaddoc parameters.

  • CVE-2023-43374CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.03

    Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/personalizza.php.

  • CVE-2023-43373CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.04

    Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.

  • CVE-2023-43371CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/creaprezzi.php.

  • CVE-2023-40619CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple places. An example is the functionality to manage tables in…

  • CVE-2023-5074CriSep 20, 2023
    risk 0.69cvss 9.8epss 0.68

    Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28

  • CVE-2023-2262CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited, a threat actor could potentially leverage this vulnerability to perform a remote code execution. To exploit this vulnerability, a threat actor would have to…

  • CVE-2023-42464CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.02

    A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When parsing Spotlight RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the…

  • CVE-2023-43207CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.02

    D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function config_upload_handler. This vulnerability allows attackers to execute arbitrary commands via the configRestore parameter.

  • CVE-2023-43206CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.02

    D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function web_cert_download_handler. This vulnerability allows attackers to execute arbitrary commands via the certDownload parameter.

  • CVE-2023-43204CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.02

    D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function sub_2EF50. This vulnerability allows attackers to execute arbitrary commands via the manual-time-string parameter.

  • CVE-2023-43203CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a stack overflow vulnerability in the function update_users.

  • CVE-2023-43202CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.02

    D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function pcap_download_handler. This vulnerability allows attackers to execute arbitrary commands via the update.device.packet-capture.tftp-file-name parameter.

  • CVE-2023-43201CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the hi_up parameter in the qos_ext.asp function.

  • CVE-2023-43200CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the id parameter in the yyxz.data function.

  • CVE-2023-43199CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the prev parameter in the H5/login.cgi function.

  • CVE-2023-43198CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the popupId parameter in the H5/hi_block.asp function.

  • CVE-2023-43197CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the fn parameter in the tgfile.asp function.

  • CVE-2023-43196CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the zn_jb parameter in the arp_sys.asp function.

  • CVE-2023-0118CriSep 20, 2023
    risk 0.59cvss 9.1epss 0.01

    An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on the underlying operating system.

  • CVE-2019-19450CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.04

    paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '<unichar code="' followed by arbitrary Python code, a similar issue to CVE-2019-17626.

  • CVE-2023-2163CriSep 20, 2023
    risk 0.00cvss 10.0epss 0.04

    Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape.

  • CVE-2023-4088CriSep 20, 2023
    risk 0.60cvss 9.3epss 0.00

    Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to execute a malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS)…