VYPR

CVEs

31,788 total · page 256 of 636

  • CVE-2023-2982CriJun 29, 2023
    risk 0.60cvss 9.8epss 0.46

    The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 7.6.4. This is due to insufficient encryption on the user being supplied during a login validated through…

  • CVE-2023-34738CriJun 29, 2023
    risk 0.64cvss 9.8epss 0.01

    Chemex through 3.7.1 is vulnerable to arbitrary file upload.

  • CVE-2023-36475CriJun 28, 2023
    risk 0.57cvss 9.8epss 0.03

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker can use a prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. A patch is available in…

  • CVE-2023-32224CriJun 28, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DSL-224 firmware version 3.0.10 CWE-307: Improper Restriction of Excessive Authentication Attempts

  • CVE-2023-32222CriJun 28, 2023
    risk 0.64cvss 9.8epss 0.02

    D-Link DSL-G256DG version vBZ_1.00.27 web management interface allows authentication bypass via an unspecified method.

  • CVE-2023-33592CriJun 28, 2023
    risk 0.67cvss 9.8epss 0.04

    Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.

  • CVE-2021-25827CriJun 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-address.

  • CVE-2023-21066CriJun 28, 2023
    risk 0.64cvss 9.8epss 0.01

    In cd_CodeMsg of cd_codec.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2023-2625CriJun 28, 2023
    risk 0.59cvss 9.0epss 0.00

    A vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as the CoreTec 4, having any level of access VIEWER to ADMIN. To exploit the vulnerability the attacker can inject shell commands through a particular field of…

  • CVE-2023-20192CriJun 28, 2023
    risk 0.62cvss 9.6epss 0.01

    Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated attacker with Administrator-level read-only credentials to elevate their privileges to Administrator with read-write credentials on an…

  • CVE-2023-20105CriJun 28, 2023
    risk 0.62cvss 9.6epss 0.01

    A vulnerability in the change password functionality of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with Read-only credentials to elevate privileges to Administrator on an affected system. This…

  • CVE-2022-44276CriJun 28, 2023
    risk 0.64cvss 9.8epss 0.02

    In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.

  • CVE-2023-32623CriJun 28, 2023
    risk 0.59cvss 9.1epss 0.02

    Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to delete arbitrary files on the server.

  • CVE-2023-26134CriJun 28, 2023
    risk 0.57cvss 9.8epss 0.04

    Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails to sanitize its parameter commit, which later flows into a sensitive command execution API. As a result, attackers may inject…

  • CVE-2020-19902CriJun 27, 2023
    risk 0.64cvss 9.8epss 0.02

    Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter.

  • CVE-2023-3432CriJun 27, 2023
    risk 0.58cvss 10.0epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.

  • CVE-2023-2601CriJun 27, 2023
    risk 0.64cvss 9.8epss 0.02

    The wpbrutalai WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin via CSRF.

  • CVE-2023-2068CriJun 27, 2023
    risk 0.70cvss 9.8epss 0.40

    The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is…

  • CVE-2023-2032CriJun 27, 2023
    risk 0.64cvss 9.8epss 0.01

    The Custom 404 Pro WordPress plugin before 3.8.1 does not properly sanitize database inputs, leading to multiple SQL Injection vulnerabilities.

  • CVE-2023-30945CriJun 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A malicious attacker could read sensitive…

  • CVE-2023-32557CriJun 26, 2023
    risk 0.64cvss 9.8epss 0.01

    A path traversal vulnerability in the Trend Micro Apex One and Apex One as a Service could allow an unauthenticated attacker to upload an arbitrary file to the Management Server which could lead to remote code execution with system privileges.

  • CVE-2023-32521CriJun 26, 2023
    risk 0.65cvss 9.1epss 0.69

    A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated remote attacker to delete arbitrary files.

  • CVE-2023-33404CriJun 26, 2023
    risk 0.66cvss 9.8epss 0.26

    An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.

  • CVE-2021-31635CriJun 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.

  • CVE-2022-48336CriJun 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Widevine Trusted Application (TA) 5.0.0 through 7.1.1 has a PRDiagParseAndStoreData integer overflow and resultant buffer overflow.

  • CVE-2022-48335CriJun 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Widevine Trusted Application (TA) 5.0.0 through 7.1.1 has a PRDiagVerifyProvisioning integer overflow and resultant buffer overflow.

  • CVE-2022-48334CriJun 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys total_len+file_name_len integer overflow and resultant buffer overflow.

  • CVE-2022-48333CriJun 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_verify_keys prefix_len+feature_name_len integer overflow and resultant buffer overflow.

  • CVE-2022-48332CriJun 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_save_keys file_name_len integer overflow and resultant buffer overflow.

  • CVE-2022-48331CriJun 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Widevine Trusted Application (TA) 5.0.0 through 5.1.1 has a drm_save_keys feature_name_len integer overflow and resultant buffer overflow.

  • CVE-2023-30261CriJun 26, 2023
    risk 0.02cvss 9.8epss 0.32

    Command Injection vulnerability in OpenWB 1.6 and 1.7 allows remote attackers to run arbitrary commands via crafted GET request.

  • CVE-2023-36660CriJun 25, 2023
    risk 0.64cvss 9.8epss 0.01

    The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption.

  • CVE-2023-3197CriJun 24, 2023
    risk 0.57cvss 9.8epss 0.04

    The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This…

  • CVE-2023-1722CriJun 24, 2023
    risk 0.59cvss 9.1epss 0.00

    Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.

  • CVE-2023-1721CriJun 24, 2023
    risk 0.59cvss 9.1epss 0.01

    Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.

  • CVE-2023-35169CriJun 23, 2023
    risk 0.52cvss 9.0epss 0.03

    PHP-IMAP is a wrapper for common IMAP communication without the need to have the php-imap module installed / enabled. Prior to version 5.3.0, an unsanitized attachment filename allows any unauthenticated user to leverage a directory traversal vulnerability, which results in a…

  • CVE-2023-35162CriJun 23, 2023
    risk 0.56cvss 9.6epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the previewactions template to perform a XSS, e.g. by…

  • CVE-2023-35161CriJun 23, 2023
    risk 0.56cvss 9.6epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the DeleteApplication page to perform a XSS, e.g. by…

  • CVE-2023-35160CriJun 23, 2023
    risk 0.56cvss 9.6epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the resubmit template to perform a XSS, e.g. by using…

  • CVE-2023-35159CriJun 23, 2023
    risk 0.56cvss 9.6epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the deletespace template to perform a XSS, e.g. by…

  • CVE-2023-35158CriJun 23, 2023
    risk 0.56cvss 9.6epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the restore template to perform a XSS, e.g. by using…

  • CVE-2023-35156CriJun 23, 2023
    risk 0.56cvss 9.6epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the delete template to perform a XSS, e.g. by using…

  • CVE-2023-35153CriJun 23, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 5.4.4 and prior to versions 14.4.8, 14.10.4, and 15.0, a stored cross-site scripting vulnerability can be exploited by users with edit rights by adding a `AppWithinMinutes.FormFieldCategoryClass` class on a page and…

  • CVE-2023-32419CriJun 23, 2023
    risk 0.64cvss 9.8epss 0.01

    The issue was addressed with improved bounds checks. This issue is fixed in iOS 16.5 and iPadOS 16.5. A remote attacker may be able to cause arbitrary code execution.

  • CVE-2023-32412CriJun 23, 2023
    risk 0.64cvss 9.8epss 0.02

    A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. A remote attacker may be able to cause…

  • CVE-2023-32387CriJun 23, 2023
    risk 0.64cvss 9.8epss 0.02

    A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. A remote attacker may be able to cause unexpected app termination or arbitrary code execution.

  • CVE-2022-22630CriJun 23, 2023
    risk 0.64cvss 9.8epss 0.01

    A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.6.6, macOS Monterey 12.3, Security Update 2022-004 Catalina. A remote user may cause an unexpected app termination or arbitrary code execution

  • CVE-2023-35152CriJun 23, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 12.9-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.1, any logged in user can add dangerous content in their first name field and see it executed with programming rights. Leading to rights escalation. The…

  • CVE-2023-35150CriJun 23, 2023
    risk 0.64cvss 9.9epss 0.78

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0, any user with view rights on any document can execute code with programming rights, leading to…

  • CVE-2023-34465CriJun 23, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 11.8-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.2, `Mail.MailConfig` can be edited by any logged-in user by default. Consequently, they can change the mail obfuscation configuration and view and edit the mail…