VYPR

CVEs

31,788 total · page 243 of 636

  • CVE-2023-3162CriAug 31, 2023
    risk 0.57cvss 9.8epss 0.01

    The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verification on the user being supplied during a Stripe checkout through the plugin. This allows…

  • CVE-2023-31714CriAug 30, 2023
    risk 0.03cvss 9.8epss 0.03

    Chitor-CMS before v1.1.2 was discovered to contain multiple SQL injection vulnerabilities.

  • CVE-2023-40582CriAug 30, 2023
    risk 0.57cvss 9.8epss 0.01

    find-exec is a utility to discover available shell commands. Versions prior to 1.0.3 did not properly escape user input and are vulnerable to Command Injection via an attacker controlled parameter. As a result, attackers may run malicious shell commands in the context of the…

  • CVE-2023-40848CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via the function "sub_7D858."

  • CVE-2023-40847CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via the function "initIpAddrInfo." In the function, it reads in a user-provided parameter, and the variable is passed to the function without any length check.

  • CVE-2023-40845CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'sub_34FD0.' In the function, it reads user provided parameters and passes variables to the function without any length checks.

  • CVE-2023-40844CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function 'formWifiBasicSet.'

  • CVE-2023-40843CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "sub_73004."

  • CVE-2023-40842CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tengda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "R7WebsSecurityHandler."

  • CVE-2023-40841CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "add_white_node,"

  • CVE-2023-40840CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function "fromGetWirelessRepeat."

  • CVE-2023-40839CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_ADF3C' contains a command execution vulnerability. In the "formSetIptv" function, obtaining the "list" and "vlanId" fields, unfiltered passing these two fields as parameters to the "sub_ADF3C" function to execute…

  • CVE-2023-40838CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_3A1D0' contains a command execution vulnerability.

  • CVE-2023-40837CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin function 'sub_ADD50' contains a command execution vulnerability. In the "formSetIptv" function, obtaining the "list" and "vlanId" fields, unfiltered passing these two fields as parameters to the "sub_ADD50" function to execute…

  • CVE-2023-41563CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter mac at url /goform/GetParentControlInfo.

  • CVE-2023-41562CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter time at url /goform/PowerSaveSet.

  • CVE-2023-41561CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter startIp and endIp at url /goform/SetPptpServerCfg.

  • CVE-2023-41560CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0 V15.03.06.42_multi was discovered to contain a stack overflow via parameter firewallEn at url /goform/SetFirewallCfg.

  • CVE-2023-41559CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter page at url /goform/NatStaticSetting.

  • CVE-2023-41558CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter timeZone at url /goform/SetSysTimeCfg.

  • CVE-2023-41557CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44 and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter entrys and mitInterface at url /goform/addressNat.

  • CVE-2023-41556CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter list at url /goform/SetIpMacBind.

  • CVE-2023-41555CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter security_5g at url /goform/WifiBasicSet.

  • CVE-2023-41554CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0 V15.03.06.42_multi was discovered to contain a stack overflow via parameter wpapsk_crypto at url /goform/WifiExtraSet.

  • CVE-2023-41553CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter list at url /goform/SetStaticRouteCfg.

  • CVE-2023-41552CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44 and Tenda AC9 V3.0 V15.03.06.42_multi were discovered to contain a stack overflow via parameter ssid at url /goform/fast_setting_wifi_set.

  • CVE-2023-4596CriAug 30, 2023
    risk 0.58cvss 9.8epss 0.13

    The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated…

  • CVE-2023-41265CriKEVAug 29, 2023
    risk 0.87cvss 9.6epss 0.84

    An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their…

  • CVE-2020-18912CriAug 29, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php.

  • CVE-2021-3262CriAug 29, 2023
    risk 0.64cvss 9.8epss 0.01

    TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body parameters from end users without sanitizing using server-side logic. It was possible to inject custom SQL commands into the "Student Busing…

  • CVE-2023-34039CriAug 29, 2023
    risk 0.72cvss 9.8epss 0.64

    Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for…

  • CVE-2023-40890CriAug 29, 2023
    risk 0.64cvss 9.8epss 0.02

    A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR…

  • CVE-2023-40889CriAug 29, 2023
    risk 0.64cvss 9.8epss 0.02

    A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or…

  • CVE-2023-40787CriAug 29, 2023
    risk 0.65cvss 9.8epss 0.19

    In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection.

  • CVE-2023-23770CriAug 29, 2023
    risk 0.61cvss 9.4epss 0.00

    Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.

  • CVE-2023-41361CriAug 29, 2023
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.

  • CVE-2023-41360CriAug 29, 2023
    risk 0.00cvss 9.1epss 0.01

    An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.

  • CVE-2023-41359CriAug 29, 2023
    risk 0.00cvss 9.1epss 0.01

    An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.

  • CVE-2023-39650CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.04

    Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.

  • CVE-2023-39652CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    theme volty tvcmsvideotab up to v4.0.0 was discovered to contain a SQL injection vulnerability via the component TvcmsVideoTabConfirmDeleteModuleFrontController::run().

  • CVE-2023-41109CriAug 28, 2023
    risk 0.69cvss 9.8epss 0.64

    SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection.

  • CVE-2023-39560CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.04

    ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.

  • CVE-2023-40846CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function sub_90998.

  • CVE-2023-40767CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40766CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40765CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40764CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40763CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40762CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40761CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Yacht Listing Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.