VYPR

CVEs

31,788 total · page 240 of 636

  • CVE-2023-38888CriSep 20, 2023
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.

  • CVE-2023-42793CriKEVSep 19, 2023
    risk 0.93cvss 9.8epss 1.00

    In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

  • CVE-2022-47558CriSep 19, 2023
    risk 0.61cvss 9.4epss 0.01

    Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of this vulnerability can allow an attacker to modify critical files that could allow the creation of new users, delete or modify existing users, modify…

  • CVE-2022-47555CriSep 19, 2023
    risk 0.61cvss 9.3epss 0.01

    Operating system command injection in ekorCCP and ekorRCI, which could allow an authenticated attacker to execute commands, create new users with elevated privileges or set up a backdoor.

  • CVE-2023-0773CriSep 19, 2023
    risk 0.59cvss 9.1epss 0.01

    The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based management interface. A remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation…

  • CVE-2023-41387CriSep 19, 2023
    risk 0.59cvss 9.1epss 0.01

    A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if an app uses…

  • CVE-2022-28357CriSep 19, 2023
    risk 0.64cvss 9.8epss 0.01

    NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.

  • CVE-2021-26837CriSep 19, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information.

  • CVE-2023-42454CriSep 18, 2023
    risk 0.58cvss 10.0epss 0.01

    SQLpage is a SQL-only webapp builder. Someone using SQLpage versions prior to 0.11.1, whose SQLpage instance is exposed publicly, with a database connection string specified in the `sqlpage/sqlpage.json` configuration file (not in an environment variable), with the web_root is…

  • CVE-2023-41084CriSep 18, 2023
    risk 0.65cvss 10.0epss 0.01

    Session management within the web application is incorrect and allows attackers to steal session cookies to perform a multitude of actions that the web app allows on the device.

  • CVE-2023-33831CriSep 18, 2023
    risk 0.65cvss 9.8epss 0.14

    A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.

  • CVE-2023-42320CriSep 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service via the mac parameter in the GetParentControlInfo function.

  • CVE-2023-42359CriSep 18, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Exam Form Submission in PHP with Source Code v.1.0 allows a remote attacker to escalate privileges via the val-username parameter in /index.php.

  • CVE-2023-4994CriSep 16, 2023
    risk 0.64cvss 9.9epss 0.01

    The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server.

  • CVE-2023-42336CriSep 16, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the password parameter in the /etc/shadow.sample component.

  • CVE-2023-39612CriSep 16, 2023
    risk 0.00cvss 9.0epss 0.01

    A cross-site scripting (XSS) vulnerability in FileBrowser before v2.23.0 allows an authenticated attacker to escalate privileges to Administrator via user interaction with a crafted HTML file or URL.

  • CVE-2023-36735CriSep 15, 2023
    risk 0.63cvss 9.6epss 0.02

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2023-41887CriSep 15, 2023
    risk 0.60cvss 9.8epss 0.45

    OpenRefine is a powerful free, open source tool for working with messy data. Prior to version 3.7.5, a remote code execution vulnerability allows any unauthenticated user to execute code on the server. Version 3.7.5 has a patch for this issue.

  • CVE-2023-42398CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in controller.php.

  • CVE-2023-28614CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.02

    Freewill iFIS (aka SMART Trade) 20.01.01.04 allows OS Command Injection via shell metacharacters to a report page.

  • CVE-2023-4835CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CF Software Oil Management Software allows SQL Injection. This issue affects Oil Management Software: before 20230912 .

  • CVE-2023-4833CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Besttem Network Marketing Software allows SQL Injection. This issue affects Network Marketing Software: before 1.0.2309.6.

  • CVE-2023-4662CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion. This issue affects Saphira Connect: before 9.

  • CVE-2023-4661CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saphira Saphira Connect allows SQL Injection. This issue affects Saphira Connect: before 9.

  • CVE-2023-4831CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncode Ncep allows SQL Injection.This issue affects Ncep: before 20230914 .

  • CVE-2023-4670CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Innosa Probbys allows SQL Injection. This issue affects Probbys: before 2.

  • CVE-2023-4231CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cevik Informatics Online Payment System allows SQL Injection. This issue affects Online Payment System: before 4.09.

  • CVE-2023-4830CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tura Signalix allows SQL Injection. This issue affects Signalix: 7T_0228.

  • CVE-2023-4673CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sanalogy Turasistan allows SQL Injection. This issue affects Turasistan: before 20230911 .

  • CVE-2023-36659CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Long inputs were not properly processed, which allows remote attackers to cause a denial of service (loss of communication).

  • CVE-2023-36657CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Built-in features of Windows (desktop shortcuts, narrator) can be abused for privilege escalation.

  • CVE-2023-39643CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Bl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml::Xmlfeeds().

  • CVE-2023-39642CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Carts Guru cartsguru up to v2.4.2 was discovered to contain a SQL injection vulnerability via the component CartsGuruCatalogModuleFrontController::display().

  • CVE-2023-39641CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Active Design psaffiliate before v1.9.8 was discovered to contain a SQL injection vulnerability via the component PsaffiliateGetaffiliatesdetailsModuleFrontController::initContent().

  • CVE-2023-39639CriSep 15, 2023
    risk 0.64cvss 9.8epss 0.01

    LeoTheme leoblog up to v3.1.2 was discovered to contain a SQL injection vulnerability via the component LeoBlogBlog::getListBlogs.

  • CVE-2023-42405CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary code via the `sort` parameter to taskService.list(), bareMetalService.list(), and switchService.list().

  • CVE-2023-39638CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.03

    D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/cgibin.

  • CVE-2023-38912CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Super Store Finder PHP Script v.3.6 allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter.

  • CVE-2023-37756CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easily guess users' passwords via a bruteforce attack.

  • CVE-2023-4972CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Incorrect Use of Privileged APIs vulnerability in Yepas Digital Yepas allows Collect Data as Provided by Users. This issue affects Digital Yepas: before 1.0.1.

  • CVE-2023-4702CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Yepas Digital Yepas allows Authentication Bypass. This issue affects Digital Yepas: before 1.0.1.

  • CVE-2023-37755CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers can exploit this vulnerability to obtain…

  • CVE-2023-4766CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Movus allows SQL Injection. This issue affects Movus: before 20230913.

  • CVE-2023-4669CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass by Assumed-Immutable Data vulnerability in Exagate SYSGuard 3001 allows Authentication Bypass. This issue affects SYSGuard 3001: before 3.2.20.0.

  • CVE-2023-41011CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.02

    Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the shortcut_telnet.cg component.

  • CVE-2023-4832CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aceka Company Management allows SQL Injection. This issue affects Company Management: before 3072 .

  • CVE-2023-30909CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote authentication bypass issue exists in some OneView APIs.

  • CVE-2023-38204CriSep 14, 2023
    risk 0.69cvss 9.8epss 0.67

    Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

  • CVE-2023-41892CriSep 13, 2023
    risk 0.03cvss 10.0epss 0.93

    Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.

  • CVE-2023-39916CriSep 13, 2023
    risk 0.53cvss 9.3epss 0.01

    NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 as well as 0.14.0 up to and including 0.14.2 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content of responses received for…