VYPR

CVEs

31,788 total · page 255 of 636

  • CVE-2022-48513CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.00

    Vulnerability of identity verification being bypassed in the Gallery module. Successful exploitation of this vulnerability may cause out-of-bounds access.

  • CVE-2022-48512CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.00

    Use After Free (UAF) vulnerability in the Vdecoderservice service. Successful exploitation of this vulnerability may cause the image decoding feature to perform abnormally.

  • CVE-2022-48511CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.00

    Use After Free (UAF) vulnerability in the audio PCM driver module under special conditions. Successful exploitation of this vulnerability may cause audio features to perform abnormally.

  • CVE-2022-48510CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.00

    Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability will cause unauthorized operations.

  • CVE-2021-46894CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.00

    Use After Free (UAF) vulnerability in the uinput module.Successful exploitation of this vulnerability may lead to kernel privilege escalation.

  • CVE-2022-46080CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.03

    Nexxt Nebula 1200-AC 15.03.06.60 allows authentication bypass and command execution by using the HTTPD service to enable TELNET.

  • CVE-2020-25969CriJul 5, 2023
    risk 0.64cvss 9.8epss 0.01

    gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest().

  • CVE-2023-36934CriJul 5, 2023
    risk 0.67cvss 9.1epss 0.95

    In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated…

  • CVE-2023-36665CriJul 5, 2023
    risk 0.57cvss 9.8epss 0.02

    "protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.prototype by adding and overwriting its data…

  • CVE-2023-3455CriJul 5, 2023
    risk 0.59cvss 9.1epss 0.00

    Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity.

  • CVE-2021-46891CriJul 5, 2023
    risk 0.64cvss 9.8epss 0.00

    Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

  • CVE-2021-46890CriJul 5, 2023
    risk 0.64cvss 9.8epss 0.00

    Vulnerability of incomplete read and write permission verification in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

  • CVE-2023-3460CriJul 4, 2023
    risk 0.65cvss 9.8epss 0.72

    The Ultimate Member WordPress plugin before 2.6.7 does not prevent visitors from creating user accounts with arbitrary capabilities, effectively allowing attackers to create administrator accounts at will. This is actively being exploited in the wild.

  • CVE-2023-36258CriJul 3, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, exec, or eval can be used.

  • CVE-2020-22597CriJul 3, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Jerrscript- project Jerryscrip v. 2.3.0 allows a remote attacker to execute arbitrary code via the ecma_builtin_array_prototype_object_slice parameter.

  • CVE-2020-22153CriJul 3, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.

  • CVE-2020-22151CriJul 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.

  • CVE-2023-26258CriJul 3, 2023
    risk 0.67cvss 9.8epss 0.38

    Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be…

  • CVE-2023-35797CriJul 3, 2023
    risk 0.57cvss 9.8epss 0.03

    Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Hive Provider. This issue affects Apache Airflow Apache Hive Provider: before 6.1.1. Before version 6.1.1 it was possible to bypass the security check to RCE via principal parameter. For this…

  • CVE-2023-31997CriJul 1, 2023
    risk 0.59cvss 9.0epss 0.00

    UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2) hosting the UniFi Network application. "Applicable Cloud Keys" include the…

  • CVE-2023-28365CriJul 1, 2023
    risk 0.59cvss 9.1epss 0.01

    A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious commands on the host device being restored.

  • CVE-2023-28324CriJul 1, 2023
    risk 0.68cvss 9.8epss 0.13

    A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.

  • CVE-2023-28323CriJul 1, 2023
    risk 0.64cvss 9.8epss 0.03

    A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities to escalate privileges on the machine…

  • CVE-2023-22814CriJul 1, 2023
    risk 0.65cvss 10.0epss 0.01

    An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This issue affects My Cloud OS 5 devices: before 5.26.202.

  • CVE-2023-36812CriJun 30, 2023
    risk 0.61cvss 9.8epss 0.17

    OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writing user-controlled input to Gnuplot configuration file and running Gnuplot with the generated configuration. This issue has been…

  • CVE-2023-3490CriJun 30, 2023
    risk 0.00cvss 9.8epss 0.01

    SQL Injection in GitHub repository fossbilling/fossbilling prior to 0.5.3.

  • CVE-2023-31543CriJun 30, 2023
    risk 0.57cvss 9.8epss 0.01

    A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the chosen repository server.

  • CVE-2023-36477CriJun 30, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights can edit all pages in the `CKEditor' space. This makes it possible to perform a variety of harmful actions, such as removing technical documents,…

  • CVE-2023-37303CriJun 30, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In certain situations, an attempt to block a user fails after a temporary browser hang and a DBQueryDisconnectedError error message.

  • CVE-2023-35175CriJun 30, 2023
    risk 0.64cvss 9.8epss 0.02

    Certain HP LaserJet Pro print products are potentially vulnerable to Potential Remote Code Execution and/or Elevation of Privilege via Server-Side Request Forgery (SSRF) using the Web Service Eventing model.

  • CVE-2023-3249CriJun 30, 2023
    risk 0.64cvss 9.8epss 0.01

    The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possible for authenticated…

  • CVE-2023-2834CriJun 30, 2023
    risk 0.57cvss 9.8epss 0.02

    The BookIt plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.3.7. This is due to insufficient verification on the user being supplied during booking an appointment through the plugin. This makes it possible for unauthenticated…

  • CVE-2020-18432CriJun 30, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in SEMCMS PHP 3.7 allows remote attackers to upload arbitrary files and gain escalated privileges.

  • CVE-2023-36470CriJun 29, 2023
    risk 0.58cvss 9.9epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By either creating a new or editing an existing document with an icon set, an attacker can inject XWiki syntax and Velocity code that is executed with programming rights and…

  • CVE-2023-36469CriJun 29, 2023
    risk 0.64cvss 9.9epss 0.82

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile and notification settings can execute arbitrary script macros including Groovy and Python macros that allow remote code execution…

  • CVE-2023-36468CriJun 29, 2023
    risk 0.57cvss 9.9epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an XWiki installation is upgraded and that upgrade contains a fix for a bug in a document, just a new version of that document is added. In some cases, it's still…

  • CVE-2023-36471CriJun 29, 2023
    risk 0.52cvss 9.0epss 0.01

    Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML tags. In the context of XWiki, this allows an attacker without script right to either create forms that can…

  • CVE-2022-44720CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Weblib Ucopia before 6.0.13. OS Command Injection injection can occur, related to chroot.

  • CVE-2023-33190CriJun 29, 2023
    risk 0.57cvss 9.9epss 0.01

    Sealos is an open source cloud operating system distribution based on the Kubernetes kernel. In versions of Sealos prior to 4.2.1-rc4 an improper configuration of role based access control (RBAC) permissions resulted in an attacker being able to obtain cluster control…

  • CVE-2023-36487CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.

  • CVE-2023-35830CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.04r2-Jellyfish and TCG-4lite Connectivity Module DeploymentPackage_v3.04r2-Jellyfish allow an attacker to gain full remote access with root privileges without…

  • CVE-2023-31222CriJun 29, 2023
    risk 0.66cvss 9.8epss 0.28

    Deserialization of untrusted data in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact a healthcare delivery organization’s Paceart Optima system cardiac device causing data to be…

  • CVE-2023-26616CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in SetParentsControlInfo.

  • CVE-2023-26613CriJun 29, 2023
    risk 0.66cvss 9.8epss 0.31

    An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system commands via a crafted GET request to EXCU_SHELL.

  • CVE-2023-26612CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field in SetParentsControlInfo.

  • CVE-2023-34849CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.03

    An unauthorized command injection vulnerability exists in the ActionLogin function of the webman.lua file in Ikuai router OS through 3.7.1.

  • CVE-2023-34844CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Play With Docker < 0.0.2 has an insecure CAP_SYS_ADMIN privileged mode causing the docker container to escape.

  • CVE-2023-34598CriJun 29, 2023
    risk 0.67cvss 9.8epss 0.47

    Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation folder in the server's response.

  • CVE-2023-34735CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Property Cloud Platform Management Center 1.0 is vulnerable to error-based SQL injection.

  • CVE-2023-34487CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    itsourcecode Online Hotel Management System Project In PHP v1.0.0 is vulnerable to SQL Injection. SQL injection points exist in the login password input box. This vulnerability can be exploited through time-based blind injection.