VYPR

CVEs

31,788 total · page 241 of 636

  • CVE-2023-3935CriSep 13, 2023
    risk 0.64cvss 9.8epss 0.02

    A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.

  • CVE-2023-39073CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a crafted request.

  • CVE-2023-41331CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    SOFARPC is a Java RPC framework. Versions prior to 5.11.0 are vulnerable to remote command execution. Through a carefully crafted payload, an attacker can achieve JNDI injection or system command execution. In the default configuration of the SOFARPC framework, a blacklist is…

  • CVE-2023-3710CriSep 12, 2023
    risk 0.70cvss 9.9epss 0.33

    Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the respective printers to version MR19.5…

  • CVE-2023-4501CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0…

  • CVE-2023-40784CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php.

  • CVE-2023-40834CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated attackers to gain access to the application via a brute force attack to the password parameter.

  • CVE-2023-2071CriSep 12, 2023
    risk 0.65cvss 9.8epss 0.11

    Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets.  The device has the functionality, through a CIP class, to…

  • CVE-2023-39150CriSep 12, 2023
    risk 0.00cvss 9.8epss 0.01

    ConEmu before commit 230724 does not sanitize title responses correctly for control characters, potentially leading to arbitrary code execution. This is related to an incomplete fix for CVE-2022-46387.

  • CVE-2023-39637CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis.

  • CVE-2022-24093CriSep 12, 2023
    risk 0.59cvss 9.1epss 0.01

    Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability. Exploitation of this issue does not require user interaction and could result in a post-authentication arbitrary code execution.

  • CVE-2023-40622CriSep 12, 2023
    risk 0.64cvss 9.9epss 0.01

    SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On successful exploitation, the attacker can completely compromise…

  • CVE-2023-40309CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could…

  • CVE-2023-39069CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentication mechanism.

  • CVE-2023-4897CriSep 11, 2023
    risk 0.00cvss 9.8epss 0.01

    Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.

  • CVE-2023-35681CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40946CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    Schoolmate 1.3 is vulnerable to SQL Injection in the variable $username from SESSION in ValidateLogin.php.

  • CVE-2023-40945CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php.

  • CVE-2023-40944CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    Schoolmate 1.3 is vulnerable to SQL Injection in the variable $schoolname from Database at ~\header.php.

  • CVE-2023-40150CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    Softneta MedDream PACS does not perform an authentication check and performs some dangerous functionality, which could result in unauthenticated remote code execution.0

  • CVE-2023-41256CriSep 11, 2023
    risk 0.59cvss 9.1epss 0.01

    Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 are vulnerable to authentication bypass that could allow an unauthorized attacker to obtain user access.

  • CVE-2023-31069CriSep 11, 2023
    risk 0.67cvss 9.8epss 0.02

    An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page.

  • CVE-2023-31068CriSep 11, 2023
    risk 0.67cvss 9.8epss 0.03

    An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes.

  • CVE-2023-31067CriSep 11, 2023
    risk 0.67cvss 9.8epss 0.03

    An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www.

  • CVE-2020-19559CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() parameter.

  • CVE-2020-19320CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the curTime parameter on login.

  • CVE-2020-19319CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login.

  • CVE-2023-30058CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    novel-plus 3.6.2 is vulnerable to SQL Injection.

  • CVE-2023-36140CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.00

    In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.

  • CVE-2023-42471CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to…

  • CVE-2023-42470CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.02

    The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execution is enabled in the WebView, and…

  • CVE-2023-40039CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame.

  • CVE-2023-42277CriSep 8, 2023
    risk 0.57cvss 9.8epss 0.01

    hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath.

  • CVE-2023-42276CriSep 8, 2023
    risk 0.57cvss 9.8epss 0.01

    hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray.

  • CVE-2023-42268CriSep 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show.

  • CVE-2023-39320CriSep 8, 2023
    risk 0.64cvss 9.8epss 0.01

    The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as…

  • CVE-2023-41615CriSep 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page via the username and password fields.

  • CVE-2023-37759CriSep 8, 2023
    risk 0.67cvss 9.8epss 0.04

    Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an Admin account via a crafted POST request.

  • CVE-2021-27715CriSep 8, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MoFi Network MOFI4500-4GXeLTE-V2 3.5.6-xnet-5052 allows attackers to bypass the authentication and execute arbitrary code via crafted HTTP request.

  • CVE-2023-40029CriSep 7, 2023
    risk 0.57cvss 9.9epss 0.01

    Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. As a result, the full secret body is stored in`kubectl.kubernetes.io/last-applied-configuration` annotation. pull request #7139…

  • CVE-2023-30908CriSep 7, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote authentication bypass issue exists in a OneView API.

  • CVE-2023-40942CriSep 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0BR_V15.03.06.42_multi_TD01 was discovered stack overflow via parameter 'firewall_value' at url /goform/SetFirewallCfg.

  • CVE-2023-39424CriSep 7, 2023
    risk 0.64cvss 9.9epss 0.01

    A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication…

  • CVE-2023-39420CriSep 7, 2023
    risk 0.64cvss 9.9epss 0.01

    The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an…

  • CVE-2023-40397CriSep 6, 2023
    risk 0.64cvss 9.8epss 0.02

    The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able to cause arbitrary javascript code execution.

  • CVE-2023-39967CriSep 6, 2023
    risk 0.65cvss 10.0epss 0.01

    WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the request might be forwarded to an arbitrary service reachable from WireMock’s instance. There are 3 identified potential attack…

  • CVE-2020-10131CriSep 6, 2023
    risk 0.64cvss 9.8epss 0.01

    SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.

  • CVE-2023-41330CriSep 6, 2023
    risk 0.57cvss 9.8epss 0.02

    knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. ## Issue On March 17th the vulnerability CVE-2023-28115 was disclosed, allowing an attacker to gain remote code execution through PHAR deserialization. Version 1.4.2…

  • CVE-2023-20238CriSep 6, 2023
    risk 0.66cvss 10.0epss 0.15

    A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an affected system. This…

  • CVE-2023-0925CriSep 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 by default) and two RMI interfaces (listening on a single, dynamically assigned TCP high port). Port 2099 serves as a Java…