VYPR

CVEs

31,788 total · page 244 of 636

  • CVE-2023-40760CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40759CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40758CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40757CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40756CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40749CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.03

    PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.

  • CVE-2023-40748CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.03

    PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.

  • CVE-2023-38029CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or…

  • CVE-2023-38028CriAug 28, 2023
    risk 0.59cvss 9.1epss 0.01

    Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication to read system information and operate user's data, but can’t control system or disrupt service.

  • CVE-2023-38027CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute command injection attack to perform arbitrary system commands or disrupt service.

  • CVE-2023-38026CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

  • CVE-2023-38025CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute command injection attack to arbitrary system commands or disrupt service.

  • CVE-2023-38024CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An remote unauthenticated attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

  • CVE-2023-40571CriAug 25, 2023
    risk 0.64cvss 9.8epss 0.01

    weblogic-framework is a tool for detecting weblogic vulnerabilities. Versions 0.2.3 and prior do not verify the returned data packets, and there is a deserialization vulnerability which may lead to remote code execution. When weblogic-framework gets the command echo, it directly…

  • CVE-2019-13690CriAug 25, 2023
    risk 0.62cvss 9.6epss 0.00

    Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

  • CVE-2023-40799CriAug 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 Vv16.03.07.45_cn is vulnerable to Buffer Overflow via sub_450A4C function.

  • CVE-2023-32757CriAug 25, 2023
    risk 0.64cvss 9.8epss 0.01

    e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.

  • CVE-2023-39699CriAug 25, 2023
    risk 0.64cvss 9.8epss 0.01

    IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. This vulnerability allows attackers to include or execute files from the local file system of the targeted server.

  • CVE-2023-4420CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.00

    A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive…

  • CVE-2023-4419CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device.

  • CVE-2023-40904CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg.

  • CVE-2023-40902CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list and bindnum at /goform/SetIpMacBind.

  • CVE-2023-40901CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at url /goform/setMacFilterCfg.

  • CVE-2023-40900CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList.

  • CVE-2023-40899CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg.

  • CVE-2023-40898CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter timeZone at /goform/SetSysTimeCfg.

  • CVE-2023-40897CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter mac at /goform/GetParentControlInfo.

  • CVE-2023-40896CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list and bindnum at /goform/SetIpMacBind.

  • CVE-2023-40895CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg.

  • CVE-2023-40894CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetStaticRouteCfg.

  • CVE-2023-40893CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.

  • CVE-2023-40892CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter schedStartTime and schedEndTime at /goform/openSchedWifi.

  • CVE-2023-40891CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter firewallEn at /goform/SetFirewallCfg.

  • CVE-2023-39834CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.02

    PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.

  • CVE-2023-40573CriAug 24, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki supports scheduled jobs that contain Groovy scripts. Currently, the job checks the content author of the job for programming right. However, modifying or adding a job…

  • CVE-2023-40572CriAug 24, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The create action is vulnerable to a CSRF attack, allowing script and thus remote code execution when targeting a user with script/programming right, thus compromising the…

  • CVE-2023-41028CriAug 23, 2023
    risk 0.59cvss 9.0epss 0.01

    A stack-based buffer overflow exists in Juplink RX4-1500, a WiFi router, in versions 1.0.2 through 1.0.5. An authenticated attacker can exploit this vulnerability to achieve code execution as root.

  • CVE-2023-40177CriAug 23, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can use the content field of their user profile page to execute arbitrary scripts with programming rights, thus effectively performing rights escalation.…

  • CVE-2023-40176CriAug 23, 2023
    risk 0.58cvss 9.0epss 0.79

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can exploit a stored XSS through their user profile by setting the payload as the value of the time zone user preference. Even though the time zone is…

  • CVE-2023-4041CriAug 23, 2023
    risk 0.64cvss 9.8epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader on ARM (Firmware Update File Parser modules) allows Code Injection, Authentication Bypass.This…

  • CVE-2023-4404CriAug 23, 2023
    risk 0.64cvss 9.8epss 0.01

    The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insufficient restriction on the 'update_core_user' function. This makes it possible for unauthenticated attackers to specify their user…

  • CVE-2020-24113CriAug 22, 2023
    risk 0.59cvss 9.1epss 0.01

    Directory Traversal vulnerability in Contacts File Upload Interface in Yealink W60B version 77.83.0.85, allows attackers to gain sensitive information and cause a denial of service (DoS).

  • CVE-2023-36281CriAug 22, 2023
    risk 0.57cvss 9.8epss 0.03

    An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ or a template.

  • CVE-2022-48565CriAug 22, 2023
    risk 0.64cvss 9.8epss 0.04

    An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.

  • CVE-2022-48522CriAug 22, 2023
    risk 0.64cvss 9.8epss 0.02

    In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.

  • CVE-2022-48174CriAug 22, 2023
    risk 0.64cvss 9.8epss 0.03

    There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.

  • CVE-2022-45611CriAug 22, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via capture of user login information.

  • CVE-2022-36648CriAug 22, 2023
    risk 0.65cvss 10.0epss 0.01

    The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers to crash the host qemu and potentially execute code on the host via execute a malformed program in the guest OS. Note: This has been…

  • CVE-2021-33390CriAug 22, 2023
    risk 0.64cvss 9.8epss 0.01

    dpic 2021.04.10 has a use-after-free in thedeletestringbox() function in dpic.y. A different vulnerablility than CVE-2021-32421.

  • CVE-2021-33388CriAug 22, 2023
    risk 0.64cvss 9.8epss 0.01

    dpic 2021.04.10 has a Heap Buffer Overflow in themakevar() function in dpic.y