VYPR

CVEs

31,788 total · page 247 of 636

  • CVE-2023-3452CriAug 12, 2023
    risk 0.57cvss 9.8epss 0.06

    The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers to include and execute arbitrary remote code on the server, provided that allow_url_include is…

  • CVE-2021-28411CriAug 11, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi version 3.4.0, allows remote attackers to escalate privileges.

  • CVE-2021-27523CriAug 11, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in open-falcon dashboard version 0.2.0, allows remote attackers to gain, modify, and delete sensitive information via crafted POST request to register interface.

  • CVE-2021-26505CriAug 11, 2023
    risk 0.57cvss 9.8epss 0.01

    Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils.extend function.

  • CVE-2020-36082CriAug 11, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.

  • CVE-2020-36034CriAug 11, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.

  • CVE-2020-27544CriAug 11, 2023
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in FoldingAtHome Client Advanced Control GUI before commit 9b619ae64443997948a36dda01b420578de1af77, allows remote attackers to execute arbitrary code via crafted payload to function parse_message in file Connection.py.

  • CVE-2020-27514CriAug 11, 2023
    risk 0.59cvss 9.1epss 0.01

    Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbitrary files and cause a denial of service (DoS).

  • CVE-2023-40267CriAug 11, 2023
    risk 0.57cvss 9.8epss 0.01

    GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

  • CVE-2023-40260CriAug 11, 2023
    risk 0.59cvss 9.1epss 0.01

    EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first factor (username and password) is known, because the first factor is sufficient to change an account's email address, and the product would then send MFA codes…

  • CVE-2023-3824CriAug 11, 2023
    risk 0.62cvss 9.4epss 0.08

    In PHP version 8.0.* before 8.0.30,  8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or RCE.

  • CVE-2023-40256CriAug 11, 2023
    risk 0.64cvss 9.8epss 0.00

    A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service. This was caused by improper validation of the client certificate due to misconfiguration of the RabbitMQ service. Exploiting…

  • CVE-2023-39806CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.01

    iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.

  • CVE-2023-39805CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.01

    iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.

  • CVE-2023-32565CriAug 10, 2023
    risk 0.59cvss 9.1epss 0.02

    An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1.

  • CVE-2023-32564CriAug 10, 2023
    risk 0.67cvss 9.8epss 0.37

    An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.

  • CVE-2023-32563CriAug 10, 2023
    risk 0.71cvss 9.8epss 0.90

    An unauthenticated attacker could achieve the code execution through a RemoteControl server.

  • CVE-2023-32562CriAug 10, 2023
    risk 0.67cvss 9.8epss 0.38

    An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1.

  • CVE-2023-32560CriAug 10, 2023
    risk 0.75cvss 9.8epss 0.99

    An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for finding and reporting. Fixed in version 6.4.1.

  • CVE-2023-38034CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.01

    A command injection vulnerability in the DHCP Client function of all UniFi Access Points and Switches, excluding the Switch Flex Mini, could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.53 and earlier) All UniFi Switches…

  • CVE-2023-35085CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.01

    An integer overflow vulnerability in all UniFi Access Points and Switches, excluding the Switch Flex Mini, with SNMP Monitoring and default settings enabled could allow a Remote Code Execution (RCE). Affected Products: All UniFi Access Points (Version 6.5.50 and earlier) All…

  • CVE-2023-32567CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.02

    Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236

  • CVE-2023-32566CriAug 10, 2023
    risk 0.59cvss 9.1epss 0.02

    An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1.

  • CVE-2023-36311CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.01

    There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in PHPJabbers Document Creator v1.0.

  • CVE-2023-39776CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.01

    A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-37734CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.01

    EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow.

  • CVE-2023-37069CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Code-Projects Online Hospital Management System V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the login id and password…

  • CVE-2023-33242CriAug 9, 2023
    risk 0.62cvss 9.6epss 0.01

    Crypto wallets implementing the Lindell17 TSS protocol might allow an attacker to extract the full ECDSA private key by exfiltrating a single bit in every signature attempt (256 in total) because of not adhering to the paper's security proof's assumption regarding handling…

  • CVE-2023-33241CriAug 9, 2023
    risk 0.62cvss 9.6epss 0.01

    Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a full ECDSA private key by injecting a malicious pallier key and cheating in the range proof. Depending on the Beta parameters chosen in the protocol implementation, the attack might…

  • CVE-2023-37068CriAug 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username…

  • CVE-2023-33468CriAug 9, 2023
    risk 0.59cvss 9.1epss 0.01

    KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly…

  • CVE-2023-39008CriAug 9, 2023
    risk 0.00cvss 9.8epss 0.03

    A command injection vulnerability in the component /api/cron/settings/setJob/ of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands.

  • CVE-2023-39007CriAug 9, 2023
    risk 0.00cvss 9.6epss 0.02

    /ui/cron/item/open in the Cron component of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows XSS via openAction in app/controllers/OPNsense/Cron/ItemController.php.

  • CVE-2023-39004CriAug 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.

  • CVE-2023-39001CriAug 9, 2023
    risk 0.00cvss 9.8epss 0.03

    A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary commands via a crafted backup configuration file.

  • CVE-2023-39969CriAug 9, 2023
    risk 0.00cvss 9.0epss 0.00

    uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Version 1.0.9 of uthenticode hashed the entire file rather than hashing sections by virtual address, in violation of the Authenticode specification. As a result, an attacker…

  • CVE-2023-34545CriAug 9, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in CSZCMS 1.3.0 allows remote attackers to run arbitrary SQL commands via p parameter or the search URL.

  • CVE-2023-3632CriAug 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Use of Hard-coded Cryptographic Key vulnerability in Sifir Bes Education and Informatics Kunduz - Homework Helper App allows Authentication Abuse, Authentication Bypass. This issue affects Kunduz - Homework Helper App: before 6.2.3.

  • CVE-2023-38208CriAug 9, 2023
    risk 0.59cvss 9.1epss 0.02

    Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead to arbitrary code execution by an…

  • CVE-2023-33934CriAug 9, 2023
    risk 0.59cvss 9.1epss 0.01

    Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: through 9.2.1.

  • CVE-2023-39213CriAug 8, 2023
    risk 0.63cvss 9.6epss 0.01

    Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an escalation of privilege via network access.

  • CVE-2023-40042CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setStaticDhcpConfig in /lib/cste_modules/lan.so. Attackers can send crafted data in an MQTT packet, via the comment parameter, to control the return address and execute code.

  • CVE-2023-40041CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK T10_v2 5.9c.5061_B20200511 has a stack-based buffer overflow in setWiFiWpsConfig in /lib/cste_modules/wps.so. Attackers can send crafted data in an MQTT packet, via the pin parameter, to control the return address and execute code.

  • CVE-2023-39216CriAug 8, 2023
    risk 0.62cvss 9.6epss 0.01

    Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.

  • CVE-2023-36911CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.02

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-36910CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.02

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-36534CriAug 8, 2023
    risk 0.61cvss 9.3epss 0.01

    Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.

  • CVE-2023-35385CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.02

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-21709CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.02

    Microsoft Exchange Server Elevation of Privilege Vulnerability

  • CVE-2023-20586CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.01

    A potential vulnerability was reported in Radeon™ Software Crimson ReLive Edition which may allow escalation of privilege. Radeon™ Software Crimson ReLive Edition falls outside of the security support lifecycle and AMD does not plan to release any mitigations