VYPR

CVEs

31,788 total · page 253 of 636

  • CVE-2023-34136CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • CVE-2023-34132CriJul 13, 2023
    risk 0.67cvss 9.8epss 0.08

    Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • CVE-2023-37567CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.02

    Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port of the web management page. Affected products and versions are as follows:…

  • CVE-2023-34130CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.00

    SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • CVE-2023-34128CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • CVE-2023-34124CriJul 13, 2023
    risk 0.70cvss 9.8epss 0.45

    The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • CVE-2023-21250CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    In gatt_end_operation of gatt_utils.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-20918CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused deputy with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-33274CriJul 12, 2023
    risk 0.64cvss 9.8epss 0.01

    The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization. This vulnerability arises from a lack of proper…

  • CVE-2023-26564CriJul 12, 2023
    risk 0.64cvss 9.8epss 0.02

    The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As a result, an unauthenticated attacker can list files within a directory, download any file, or upload any file to any directory accessible by the web server.

  • CVE-2023-26563CriJul 12, 2023
    risk 0.64cvss 9.8epss 0.02

    The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an unauthenticated attacker can: - On Windows, list files in any directory, read any file, delete any file, upload any file to any directory accessible by the…

  • CVE-2023-37629CriJul 12, 2023
    risk 0.68cvss 9.8epss 0.23

    Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig.php."

  • CVE-2023-37628CriJul 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Piggery Management System 1.0 is vulnerable to SQL Injection.

  • CVE-2023-29300CriKEVJul 12, 2023
    risk 0.90cvss 9.8epss 1.00

    Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

  • CVE-2023-37627CriJul 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Code-projects Online Restaurant Management System 1.0 is vulnerable to SQL Injection. Through SQL injection, an attacker can bypass the admin panel and view order records, add items, delete items etc.

  • CVE-2023-3595CriJul 12, 2023
    risk 0.64cvss 9.8epss 0.05

    Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through maliciously crafted CIP messages. This includes…

  • CVE-2023-33668CriJul 12, 2023
    risk 0.64cvss 9.8epss 0.01

    DigiExam up to v14.0.2 lacks integrity checks for native modules, allowing attackers to access PII and takeover accounts on shared computers.

  • CVE-2023-37582CriJul 12, 2023
    risk 0.71cvss 9.8epss 0.90

    The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this…

  • CVE-2023-30429CriJul 12, 2023
    risk 0.62cvss 9.6epss 0.01

    Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. When a client connects to the Pulsar Function Worker via the Pulsar Proxy where the Pulsar Proxy uses mTLS authentication to…

  • CVE-2023-24492CriJul 11, 2023
    risk 0.62cvss 9.6epss 0.01

    A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts.

  • CVE-2023-36825CriJul 11, 2023
    risk 0.55cvss 9.6epss 0.01

    Orchid is a Laravel package that allows application development of back-office applications, admin/user panels, and dashboards. A vulnerability present starting in version 14.0.0-alpha4 and prior to version 14.5.0 is related to the deserialization of untrusted data from the…

  • CVE-2023-35367CriJul 11, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2023-35366CriJul 11, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2023-35365CriJul 11, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2023-33150CriJul 11, 2023
    risk 0.63cvss 9.6epss 0.02

    Microsoft Office Security Feature Bypass Vulnerability

  • CVE-2023-32057CriJul 11, 2023
    risk 0.64cvss 9.8epss 0.02

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-26861CriJul 11, 2023
    risk 0.00cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop vivawallet v.1.7.10 and before allows a remote attacker to gain privileges via the vivawallet() module.

  • CVE-2023-37659CriJul 11, 2023
    risk 0.57cvss 9.8epss 0.02

    xalpha v0.11.4 is vulnerable to Remote Command Execution (RCE).

  • CVE-2023-37656CriJul 11, 2023
    risk 0.64cvss 9.8epss 0.02

    WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload.

  • CVE-2023-2746CriJul 11, 2023
    risk 0.62cvss 9.6epss 0.01

    The Rockwell Automation Enhanced HIM software contains an API that the application uses that is not protected sufficiently and uses incorrect Cross-Origin Resource Sharing (CORS) settings and, as a result, is vulnerable to a Cross Site Request Forgery (CSRF) attack. To exploit…

  • CVE-2023-34561CriJul 11, 2023
    risk 0.64cvss 9.8epss 0.02

    A buffer overflow in the level parsing code of RobTop Games AB Geometry Dash v2.113 allows attackers to execute arbitrary code via entering a Geometry Dash level.

  • CVE-2023-36755CriJul 11, 2023
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),…

  • CVE-2023-36754CriJul 11, 2023
    risk 0.59cvss 9.1epss 0.02

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),…

  • CVE-2023-36753CriJul 11, 2023
    risk 0.59cvss 9.1epss 0.02

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),…

  • CVE-2023-36752CriJul 11, 2023
    risk 0.59cvss 9.1epss 0.02

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),…

  • CVE-2023-36751CriJul 11, 2023
    risk 0.59cvss 9.1epss 0.02

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),…

  • CVE-2023-36750CriJul 11, 2023
    risk 0.59cvss 9.1epss 0.02

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0),…

  • CVE-2023-29130CriJul 11, 2023
    risk 0.64cvss 9.9epss 0.01

    A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of improper access controls in the configuration files that leads to privilege escalation. An attacker could gain admin access with this vulnerability leading to complete…

  • CVE-2023-31191CriJul 11, 2023
    risk 0.60cvss 9.3epss 0.00

    DroneScout ds230 Remote ID receiver from BlueMark Innovations is affected by an information loss vulnerability through traffic injection. An attacker can exploit this vulnerability by injecting, on carefully selected channels, high power spoofed Open Drone ID (ODID) messages…

  • CVE-2023-36922CriJul 11, 2023
    risk 0.59cvss 9.1epss 0.01

    Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension.  On successful exploitation, the…

  • CVE-2023-24489CriKEVJul 10, 2023
    risk 0.83cvss 9.8epss 0.94

    A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.

  • CVE-2023-34347CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    ​Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contains classes that cannot be deserialized, which could allow an attack to remotely execute arbitrary code.

  • CVE-2023-37712CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23, F1202 V1.2.0.20(408), and FH1202 V1.2.0.20(408) were discovered to contain a stack overflow in the page parameter in the fromSetIpBind function.

  • CVE-2023-37711CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the deviceId parameter in the saveParentControlInfo function.

  • CVE-2023-37710CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23 and AC10 V15.03.06.47 were discovered to contain a stack overflow in the wpapsk_crypto parameter in the fromSetWirelessRepeat function.

  • CVE-2023-37707CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function.

  • CVE-2023-37706CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the entrys parameter in the fromAddressNat function.

  • CVE-2023-37705CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the page parameter in the fromAddressNat function.

  • CVE-2023-37704CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.

  • CVE-2023-37703CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.