VYPR

CVEs

31,788 total · page 257 of 636

  • CVE-2023-34464CriJun 23, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.2.1 until versions 14.4.8, 14.10.5, and 15.1RC1 of org.xwiki.platform:xwiki-platform-web and any version prior to 14.4.8, 14.10.5, and 15.1.RC1 of…

  • CVE-2023-30258CriJun 23, 2023
    risk 0.10cvss 9.8epss 0.94

    Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.

  • CVE-2023-33299CriJun 23, 2023
    risk 0.66cvss 9.8epss 0.24

    A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server communication port. Note FortiNAC versions 8.x…

  • CVE-2023-3128CriJun 22, 2023
    risk 0.61cvss 9.4epss 0.04

    Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.

  • CVE-2023-36355CriJun 22, 2023
    risk 0.70cvss 9.9epss 0.32

    TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipStart parameter at /userRpm/WanDynamicIpV6CfgRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.

  • CVE-2023-32571CriJun 22, 2023
    risk 0.66cvss 9.8epss 0.35

    Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods including Where, Select, OrderBy is parsed.

  • CVE-2023-2989CriJun 22, 2023
    risk 0.59cvss 9.1epss 0.01

    Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of bounds memory read in their administration server, which can allow an attacker to crash the service or bypass authentication if successfully exploited

  • CVE-2023-3326CriJun 22, 2023
    risk 0.64cvss 9.8epss 0.01

    pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) from the Kerberos KDC (Key Distribution Center) over the network, as a way to verify the password. However, if a keytab is not provisioned on the system, pam_krb5…

  • CVE-2023-2611CriJun 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a password that cannot be changed by users.

  • CVE-2023-36097CriJun 22, 2023
    risk 0.64cvss 9.8epss 0.01

    funadmin v3.3.2 and v3.3.3 are vulnerable to Insecure file upload via the plugins install.

  • CVE-2023-34939CriJun 22, 2023
    risk 0.64cvss 9.8epss 0.05

    Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ashx.

  • CVE-2023-29711CriJun 22, 2023
    risk 0.69cvss 9.8epss 0.70

    An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via crafted GET request.

  • CVE-2023-34601CriJun 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Jeesite before commit 10742d3 was discovered to contain a SQL injection vulnerability via the component ${businessTable} at /act/ActDao.xml.

  • CVE-2023-29931CriJun 22, 2023
    risk 0.57cvss 9.8epss 0.01

    laravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.

  • CVE-2023-3110CriJun 21, 2023
    risk 0.62cvss 9.6epss 0.00

    Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.

  • CVE-2023-0972CriJun 21, 2023
    risk 0.62cvss 9.6epss 0.00

    Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.

  • CVE-2023-0971CriJun 21, 2023
    risk 0.62cvss 9.6epss 0.00

    A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.

  • CVE-2023-33584CriJun 21, 2023
    risk 0.68cvss 9.8epss 0.14

    Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields…

  • CVE-2023-34340CriJun 21, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 contains a defect in the user authentication process that may succeed when invalid credentials are provided. Users are advised to…

  • CVE-2023-34563CriJun 20, 2023
    risk 0.65cvss 9.8epss 0.14

    netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication.

  • CVE-2023-35885CriJun 20, 2023
    risk 0.70cvss 9.8epss 0.75

    CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.

  • CVE-2023-35166CriJun 20, 2023
    risk 0.62cvss 9.9epss 0.63

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension. This has been patched in XWiki 15.1-rc-1 and 14.10.5.

  • CVE-2023-34600CriJun 20, 2023
    risk 0.66cvss 9.8epss 0.24

    Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.

  • CVE-2023-34541CriJun 20, 2023
    risk 0.57cvss 9.8epss 0.01

    Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.

  • CVE-2020-21489CriJun 20, 2023
    risk 0.57cvss 9.8epss 0.01

    File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component.

  • CVE-2020-21474CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter.

  • CVE-2020-21174CriJun 20, 2023
    risk 0.57cvss 9.8epss 0.01

    File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.

  • CVE-2020-20735CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.

  • CVE-2020-20718CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.

  • CVE-2020-20703CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.02

    Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.

  • CVE-2020-20413CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.

  • CVE-2023-35854CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.06

    Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is…

  • CVE-2023-34159CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.00

    Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerability may lead to privilege escalation, which affects availability and confidentiality.

  • CVE-2023-31411CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. The lack of authentication in the API allows the attacker to potentially compromise the functionality of the EventCam App.

  • CVE-2023-31410CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.00

    A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK EventCam App. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive…

  • CVE-2023-2907CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marksoft allows SQL Injection. This issue affects Marksoft: through Mobile:v.7.1.7 ; Login:1.4 ; API:20230605.

  • CVE-2023-27992CriKEVJun 19, 2023
    risk 0.82cvss 9.8epss 0.84

    The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to…

  • CVE-2023-34417CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 114.

  • CVE-2023-34416CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox…

  • CVE-2023-29542CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox and Thunderbird on…

  • CVE-2023-29534CriJun 19, 2023
    risk 0.52cvss 9.1epss 0.01

    Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This…

  • CVE-2023-25736CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affects Firefox < 110.

  • CVE-2019-25136CriJun 19, 2023
    risk 0.65cvss 10.0epss 0.01

    A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox escape. This vulnerability affects Firefox < 70.

  • CVE-2023-32216CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…

  • CVE-2023-29531CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects…

  • CVE-2023-27396CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON products that implement FINS protocol contain following…

  • CVE-2023-35857CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    In Siren Investigate before 13.2.2, session keys remain active even after logging out.

  • CVE-2023-35856CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow in Nintendo Mario Kart Wii RMCP01, RMCE01, RMCJ01, and RMCK01 can be exploited by a game client to execute arbitrary code on a client's machine via a crafted packet.

  • CVE-2023-35855CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying the lservercfgfile console variable.

  • CVE-2023-35853CriJun 19, 2023
    risk 0.00cvss 9.8epss 0.01

    In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.