VYPR

CVEs

31,788 total · page 254 of 636

  • CVE-2023-37702CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function.

  • CVE-2023-37701CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.

  • CVE-2023-37700CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 V2.0.1.6 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

  • CVE-2023-37277CriJul 10, 2023
    risk 0.55cvss 9.6epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The REST API allows executing all actions via POST requests and accepts `text/plain`, `multipart/form-data` or `application/www-form-urlencoded` as content types which can be…

  • CVE-2023-3077CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.06

    The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenticated users. This is only exploitable if the site owner elected to pay to get access to the…

  • CVE-2023-3076CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.02

    The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only exploitable if the site owner paid to access the plugin's pro features.

  • CVE-2023-3045CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tise Technology Parking Web Report allows SQL Injection. This issue affects Parking Web Report: before 2.1.

  • CVE-2023-37152CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.02

    Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.

  • CVE-2023-32254CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.03

    A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_TREE_DISCONNECT commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can…

  • CVE-2023-32250CriJul 10, 2023
    risk 0.59cvss 9.0epss 0.03

    A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the processing of SMB2_SESSION_SETUP commands. The issue results from the lack of proper locking when performing operations on an object. An attacker can…

  • CVE-2023-2852CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Softmed SelfPatron allows SQL Injection. This issue affects SelfPatron : before 2.0.

  • CVE-2023-2046CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yontem Informatics Vehicle Tracking System allows SQL Injection. This issue affects Vehicle Tracking System: before 8.

  • CVE-2021-4406CriJul 10, 2023
    risk 0.59cvss 9.1epss 0.01

    An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager * open the ITSM tab * add a webhook with the URL/service token value ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) * …

  • CVE-2021-42081CriJul 10, 2023
    risk 0.59cvss 9.1epss 0.01

    An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. POC http://<IP_ADDRESS>/qstorapi/storageSystemModify?storageSystem=&newName=quantastor&newDescription=;ls${IFS}-al&newLocation=4&newEnclosureLayoutId=5&newDnsServerList=;ls${IFS}-…

  • CVE-2023-37287CriJul 10, 2023
    risk 0.59cvss 9.1epss 0.01

    SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit this vulnerability to access system with regular user privilege to read application data, and execute submission and approval processes.

  • CVE-2023-37286CriJul 10, 2023
    risk 0.64cvss 9.8epss 0.01

    SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.

  • CVE-2023-37262CriJul 7, 2023
    risk 0.00cvss 9.6epss 0.01

    CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to versions 1.20.1-1.106.0, 1.19.4-1.106.0, 1.19.2-1.101.3, 1.18.2-1.101.3, and 1.16.5-1.101.3, if the cc-tweaked plugin is running on a Minecraft server hosted on a…

  • CVE-2023-37261CriJul 7, 2023
    risk 0.00cvss 9.6epss 0.01

    OpenComputers is a Minecraft mod that adds programmable computers and robots to the game. This issue affects every version of OpenComputers with the Internet Card feature enabled; that is, OpenComputers 1.2.0 until 1.8.3 in their most common, default configurations. If the…

  • CVE-2023-37173CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function.

  • CVE-2023-37172CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.

  • CVE-2023-37171CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.

  • CVE-2023-37170CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.

  • CVE-2022-4361CriJul 7, 2023
    risk 0.58cvss 10.0epss 0.01

    Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the…

  • CVE-2023-36994CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.01

    In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the server configuration and inject PHP code.

  • CVE-2023-36993CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.parameters and to take over accounts.

  • CVE-2021-32495CriJul 7, 2023
    risk 0.00cvss 10.0epss 0.01

    Radare2 has a use-after-free vulnerability in pyc parser's get_none_object function. Attacker can read freed memory afterwards. This will allow attackers to cause denial of service.

  • CVE-2021-32494CriJul 7, 2023
    risk 0.00cvss 10.0epss 0.01

    Radare2 has a division by zero vulnerability in Mach-O parser's rebase_buffer function. This allow attackers to create malicious inputs that can cause denial of service.

  • CVE-2021-33796CriJul 7, 2023
    risk 0.00cvss 10.0epss 0.01

    In MuJS before version 1.1.2, a use-after-free flaw in the regexp source property access may cause denial of service.

  • CVE-2023-27845CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop lekerawen_ocs before v.1.4.1 allow a remote attacker to gain privileges via the KerawenHelper::setCartOperationInfo, and KerawenHelper::resetCheckoutSessionData components.

  • CVE-2023-37149CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function.

  • CVE-2023-37148CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function.

  • CVE-2023-37146CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.

  • CVE-2023-37145CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.

  • CVE-2023-37144CriJul 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.

  • CVE-2023-35987CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.01

    PiiGAB M-Bus contains hard-coded credentials which it uses for authentication.

  • CVE-2023-29824CriJul 6, 2023
    risk 0.57cvss 9.8epss 0.01

    A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer indicate that this is not a security issue.

  • CVE-2023-36460CriJul 6, 2023
    risk 0.03cvss 9.9epss 0.40

    Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully crafted media files can cause Mastodon's media processing code to create arbitrary files at any…

  • CVE-2023-36459CriJul 6, 2023
    risk 0.00cvss 9.3epss 0.01

    Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 1.3 and prior to versions 3.5.9, 4.0.5, and 4.1.3, an attacker using carefully crafted oEmbed data can bypass the HTML sanitization performed by Mastodon and include arbitrary HTML in…

  • CVE-2023-34192CriKEVJul 6, 2023
    risk 0.77cvss 9.0epss 0.77

    Cross Site Scripting vulnerability in Zimbra ZCS v.8.8.15 allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

  • CVE-2023-30321CriJul 6, 2023
    risk 0.59cvss 9.0epss 0.01

    Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code.

  • CVE-2023-30320CriJul 6, 2023
    risk 0.59cvss 9.0epss 0.01

    Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code.

  • CVE-2023-30319CriJul 6, 2023
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code.

  • CVE-2023-29382CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component.

  • CVE-2023-29381CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate privileges and obtain sensitive information via the password and 2FA parameters.

  • CVE-2023-23902CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.02

    A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to remote code execution. An attacker can send a network request to trigger this vulnerability.

  • CVE-2023-36188CriJul 6, 2023
    risk 0.57cvss 9.8epss 0.02

    An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.

  • CVE-2020-22336CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in pdfcrack 0.17 thru 0.18, allows attackers to execute arbitrary code via a stack overflow in the MD5 function.

  • CVE-2023-37245CriJul 6, 2023
    risk 0.59cvss 9.1epss 0.00

    Buffer overflow vulnerability in the modem pinctrl module. Successful exploitation of this vulnerability may affect the integrity and availability of the modem.

  • CVE-2023-37242CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.00

    Vulnerability of commands from the modem being intercepted in the atcmdserver module. Attackers may exploit this vulnerability to rewrite the non-volatile random-access memory (NVRAM), or facilitate the exploitation of other vulnerabilities.

  • CVE-2023-37240CriJul 6, 2023
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of missing input length verification in the distributed file system. Successful exploitation of this vulnerability may cause out-of-bounds read.