VYPR

CVEs

31,788 total · page 250 of 636

  • CVE-2023-36089CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass vulnerability in D-Link DIR-645 firmware version 1.03 allows remote attackers to gain escalated privileges via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

  • CVE-2023-34842CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.

  • CVE-2023-34644CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.02

    Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series business VPN routers EG_3.0(1)B11P216, EAP and RAP series wireless access points…

  • CVE-2023-34635CriJul 31, 2023
    risk 0.67cvss 9.8epss 0.04

    Wifi Soft Unibox Administration 3.0 and 3.1 is vulnerable to SQL Injection. The vulnerability occurs because of not validating or sanitizing the user input in the username field of the login page.

  • CVE-2020-21662CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in yunyecms 2.0.2 allows remote attackers to run arbitrary SQL commands via XFF.

  • CVE-2023-37647CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.

  • CVE-2023-35861CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.02

    A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.

  • CVE-2023-4006CriJul 31, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Neutralization of Formula Elements in a CSV File in GitHub repository thorsten/phpmyfaq prior to 3.1.16.

  • CVE-2023-4005CriJul 31, 2023
    risk 0.00cvss 9.8epss 0.00

    Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.

  • CVE-2023-37214CriJul 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.

  • CVE-2023-32227CriJul 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Synel SYnergy Fingerprint Terminals - CWE-798: Use of Hard-coded Credentials

  • CVE-2023-32225CriJul 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type -  A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.

  • CVE-2022-4924CriJul 29, 2023
    risk 0.62cvss 9.6epss 0.01

    Use after free in WebRTC in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-4920CriJul 29, 2023
    risk 0.62cvss 9.6epss 0.01

    Heap buffer overflow in Blink in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-39023CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compass.core.executor.DefaultExecutorManager.configure. This vulnerability is exploited via passing an unchecked argument.

  • CVE-2023-39022CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. This vulnerability is exploited via passing an unchecked argument.

  • CVE-2023-39021CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply. This vulnerability is exploited via passing an unchecked argument.

  • CVE-2023-39020CriJul 28, 2023
    risk 0.57cvss 9.8epss 0.01

    stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument.

  • CVE-2023-39018CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple third parties because there are no…

  • CVE-2023-39017CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple parties because it is…

  • CVE-2023-39016CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLManager.createPool. This vulnerability is exploited via passing an unchecked argument.

  • CVE-2023-39015CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    webmagic-extension v0.9.0 and below was discovered to contain a code injection vulnerability via the component us.codecraft.webmagic.downloader.PhantomJSDownloader.

  • CVE-2023-39013CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Duke v1.2 and below was discovered to contain a code injection vulnerability via the component no.priv.garshol.duke.server.CommonJTimer.init.

  • CVE-2023-39010CriJul 28, 2023
    risk 0.57cvss 9.8epss 0.01

    BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability is exploited by loading a crafted camera calibration file.

  • CVE-2023-38992CriJul 28, 2023
    risk 0.62cvss 9.8epss 0.72

    jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.

  • CVE-2023-37754CriJul 28, 2023
    risk 0.66cvss 9.8epss 0.27

    PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail.

  • CVE-2023-38604CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in watchOS 9.6, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute…

  • CVE-2023-38598CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.6, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary…

  • CVE-2023-37285CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, macOS Big Sur 11.7.9, macOS Monterey 12.6.8, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2023-36495CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.6, macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2023-34425CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    The issue was addressed with improved memory handling. This issue is fixed in watchOS 9.6, macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, macOS Big Sur 11.7.9, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2023-33745CriJul 27, 2023
    risk 0.64cvss 9.8epss 0.01

    TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Privilege Management: from the shell available after an adb connection, simply entering the su command provides root access (without requiring a password).

  • CVE-2023-33744CriJul 27, 2023
    risk 0.64cvss 9.8epss 0.01

    TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.

  • CVE-2023-33743CriJul 27, 2023
    risk 0.64cvss 9.8epss 0.01

    TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Access Control; specifically, Android Debug Bridge (adb) is available.

  • CVE-2023-3975CriJul 27, 2023
    risk 0.00cvss 9.8epss 0.02

    OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0.

  • CVE-2023-3974CriJul 27, 2023
    risk 0.00cvss 9.8epss 0.01

    OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0.

  • CVE-2023-3956CriJul 27, 2023
    risk 0.57cvss 9.8epss 0.01

    The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiver' function in versions up to, and including, 0.0.9.18. This makes it possible for unauthenticated…

  • CVE-2023-31465CriJul 26, 2023
    risk 0.67cvss 9.8epss 0.44

    An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from…

  • CVE-2023-33308CriJul 26, 2023
    risk 0.64cvss 9.8epss 0.02

    A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted…

  • CVE-2023-26859CriJul 26, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privileges via the ajaxOrderTracking.php component.

  • CVE-2023-38673CriJul 26, 2023
    risk 0.56cvss 9.6epss 0.02

    PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.

  • CVE-2023-38647CriJul 26, 2023
    risk 0.57cvss 9.8epss 0.02

    An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoader. This unbounded deserialization can likely lead to remote code…

  • CVE-2023-37677CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the component admin_editor.php.

  • CVE-2023-34798CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2022-46898CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal via the "restore SQL data" filename. The Vocera Report Console contains a websocket function that allows for the restoration of the database from a ZIP archive that expects…

  • CVE-2023-35982CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-35981CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-35980CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-37895CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.03

    Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-beanutils", which contains a class that…

  • CVE-2023-35088CriJul 25, 2023
    risk 0.57cvss 9.8epss 0.02

    Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.  In the toAuditCkSql method, the groupId, streamId, auditId, and dt are…