VYPR

CVEs

31,788 total · page 242 of 636

  • CVE-2021-36023CriSep 6, 2023
    risk 0.59cvss 9.1epss 0.02

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.

  • CVE-2023-41149CriSep 6, 2023
    risk 0.64cvss 9.8epss 0.01

    F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploited, an attacker who can access the product may execute an arbitrary OS command on the server where the product is running.

  • CVE-2023-4589CriSep 6, 2023
    risk 0.59cvss 9.1epss 0.00

    Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An attacker with an administrator account could perform software updates without proper integrity verification mechanisms. In this scenario, the update process…

  • CVE-2023-4634CriSep 6, 2023
    risk 0.73cvss 9.8epss 0.83

    The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the…

  • CVE-2023-4485CriSep 6, 2023
    risk 0.64cvss 9.8epss 0.01

    ARDEREG ​Sistema SCADA Central versions 2.203 and prior login page are vulnerable to an unauthenticated blind SQL injection attack. An attacker could manipulate the application's SQL query logic to extract sensitive information or perform unauthorized actions within the…

  • CVE-2023-41507CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters.

  • CVE-2023-4310CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote…

  • CVE-2023-41508CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.

  • CVE-2023-39361CriSep 5, 2023
    risk 0.71cvss 9.8epss 0.88

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an…

  • CVE-2023-41009CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header.

  • CVE-2023-39654CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    abupy up to v0.4.0 was discovered to contain a SQL injection vulnerability via the component abupy.MarketBu.ABuSymbol.search_to_symbol_dict.

  • CVE-2023-4531CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestav Software E-commerce Software allows SQL Injection. This issue affects E-commerce Software: before 20230901 .

  • CVE-2023-4178CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass. This issue affects Neutron Smart VMS: before b1130.1.0.1.

  • CVE-2023-4034CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection. This issue affects Smartrise Document Management System: before Hvl-2.0.

  • CVE-2023-3616CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mava Software Hotel Management System allows SQL Injection. This issue affects Hotel Management System: before 2.0.

  • CVE-2023-39681CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vulnerability is triggered via a crafted payload.

  • CVE-2023-35072CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proagent allows SQL Injection. This issue affects Proagent: before 20230904 .

  • CVE-2023-35068CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BMA Personnel Tracking System allows SQL Injection. This issue affects Personnel Tracking System: before 20230904.

  • CVE-2023-35065CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Osoft Paint Production Management allows SQL Injection. This issue affects Paint Production Management: before 2.1.

  • CVE-2017-9453CriSep 5, 2023
    risk 0.59cvss 9.0epss 0.01

    BMC Server Automation before 8.9.01 patch 1 allows Process Spawner command execution because of authentication bypass.

  • CVE-2023-3374CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Incomplete List of Disallowed Inputs vulnerability in Unisign Bookreen allows Privilege Escalation. This issue affects Bookreen: before 3.0.0.

  • CVE-2023-41012CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism.

  • CVE-2023-36361CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.

  • CVE-2023-40743CriSep 5, 2023
    risk 0.57cvss 9.8epss 0.03

    ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API…

  • CVE-2023-41910CriSep 5, 2023
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdp_decode in daemon/protocols/cdp.c.

  • CVE-2023-28581CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in WLAN Firmware while parsing receieved GTK Keys in GTK KDE.

  • CVE-2023-28562CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption while handling payloads from remote ESL.

  • CVE-2023-4614CriSep 4, 2023
    risk 0.64cvss 9.8epss 0.02

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/installation/setThumbnailRc endpoint. The issue results from…

  • CVE-2023-4613CriSep 4, 2023
    risk 0.64cvss 9.8epss 0.02

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/settings/upload endpoint. The issue results from the lack of…

  • CVE-2023-4744CriSep 4, 2023
    risk 0.64cvss 9.8epss 0.02

    A vulnerability was found in Tenda AC8 16.03.34.06_cn_TDC01. It has been declared as critical. Affected by this vulnerability is the function formSetDeviceName. The manipulation leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been…

  • CVE-2023-3703CriSep 3, 2023
    risk 0.65cvss 10.0epss 0.01

    Proscend Advice ICR Series routers FW version 1.76 - CWE-1392: Use of Default Credentials

  • CVE-2023-39979CriSep 2, 2023
    risk 0.64cvss 9.8epss 0.01

    There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values.  

  • CVE-2023-1523CriSep 1, 2023
    risk 0.00cvss 10.0epss 0.01

    Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the controlling terminal which could allow it to cause arbitrary commands to be executed outside of the snap sandbox after the snap exits. Graphical terminal emulators like xterm,…

  • CVE-2023-40980CriSep 1, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file.

  • CVE-2023-39631CriSep 1, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.

  • CVE-2023-36328CriSep 1, 2023
    risk 0.00cvss 9.8epss 0.01

    Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).

  • CVE-2023-36327CriSep 1, 2023
    risk 0.00cvss 9.8epss 0.01

    Integer Overflow vulnerability in RELIC before commit 421f2e91cf2ba42473d4d54daf24e295679e290e, allows attackers to execute arbitrary code and cause a denial of service in pos argument in bn_get_prime function.

  • CVE-2023-36326CriSep 1, 2023
    risk 0.00cvss 9.8epss 0.01

    Integer Overflow vulnerability in RELIC before commit 34580d840469361ba9b5f001361cad659687b9ab, allows attackers to execute arbitrary code, cause a denial of service, and escalate privileges when calling realloc function in bn_grow function.

  • CVE-2023-36187CriSep 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.

  • CVE-2023-36100CriSep 1, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain sensitive information via UserID parameter in api/User/ChangeUser.

  • CVE-2023-36076CriSep 1, 2023
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in smanga version 3.1.9 and earlier, allows remote attackers to execute arbitrary code and gain sensitive information via mediaId, mangaId, and userId parameters in php/history/add.php.

  • CVE-2020-22612CriSep 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Installer RCE on settings file write in MyBB before 1.8.22.

  • CVE-2023-41364CriSep 1, 2023
    risk 0.64cvss 9.8epss 0.01

    In tine through 2023.01.14.325, the sort parameter of the /index.php endpoint allows SQL Injection.

  • CVE-2023-4696CriSep 1, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Access Control in GitHub repository usememos/memos prior to 0.13.2.

  • CVE-2023-4299CriAug 31, 2023
    risk 0.59cvss 9.0epss 0.01

    Digi RealPort Protocol is vulnerable to a replay attack that may allow an attacker to bypass authentication to access connected equipment.

  • CVE-2023-41748CriAug 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203.

  • CVE-2023-41746CriAug 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Remote command execution due to improper input validation. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.23089.203.

  • CVE-2023-41637CriAug 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the Carica immagine function of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted HTML file.

  • CVE-2023-41636CriAug 31, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in the Data Richiesta dal parameter of GruppoSCAI RealGimm v1.1.37p38 allows attackers to access the database and execute arbitrary commands via a crafted SQL query.

  • CVE-2023-28801CriAug 31, 2023
    risk 0.62cvss 9.6epss 0.00

    An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affects Admin UI: from 6.2 before 6.2r.