VYPR

CVEs

31,788 total · page 258 of 636

  • CVE-2023-35839CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload.

  • CVE-2023-35813CriJun 17, 2023
    risk 0.71cvss 9.8epss 0.87

    Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.

  • CVE-2014-125106CriJun 17, 2023
    risk 0.57cvss 9.8epss 0.01

    Nanopb before 0.3.1 allows size_t overflows in pb_dec_bytes and pb_dec_string.

  • CVE-2023-35784CriJun 16, 2023
    risk 0.00cvss 9.8epss 0.01

    A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.

  • CVE-2023-34832CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4.

  • CVE-2023-34659CriJun 16, 2023
    risk 0.65cvss 9.8epss 0.12

    jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.

  • CVE-2023-25366CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.00

    In Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS, insecure SCPI interface discloses web password.

  • CVE-2023-34548CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter.

  • CVE-2022-48472CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution. Affected product versions include:BiSheng-WNM versions OTA-BiSheng-FW-2.0.0.211-beta,BiSheng-WNM FW 3.0.0.325,BiSheng-WNM FW 2.0.0.211.

  • CVE-2023-34157CriJun 16, 2023
    risk 0.65cvss 10.0epss 0.00

    Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.

  • CVE-2023-35708CriJun 16, 2023
    risk 0.71cvss 9.8epss 0.97

    In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain…

  • CVE-2023-32754CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    Thinking Software Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database.

  • CVE-2023-32753CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.

  • CVE-2023-32752CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    L7 Networks InstantScan IS-8000 & InstantQoS IQ-8000’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system…

  • CVE-2023-34800CriJun 15, 2023
    risk 0.66cvss 9.8epss 0.29

    D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.

  • CVE-2023-34852CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.

  • CVE-2023-31672CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    In the PrestaShop < 2.4.3 module "Length, weight or volume sell" (ailinear) there is a SQL injection vulnerability.

  • CVE-2023-2686CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack.

  • CVE-2023-29297CriJun 15, 2023
    risk 0.59cvss 9.1epss 0.01

    Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could lead to arbitrary code execution by an admin-privilege authenticated…

  • CVE-2023-21130CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0945CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.00

    In _PMRCreate of the PowerVR kernel driver, a missing bounds check means it is possible to overwrite heap memory via PhysmemNewRamBackedPMR. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-0701CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.00

    In PVRSRVBridgeSyncPrimOpCreate of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2023-34880CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to execute arbitrary code and perform a local file inclusion.

  • CVE-2023-34251CriJun 14, 2023
    risk 0.58cvss 9.9epss 0.02

    Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is possible by embedding malicious PHP code on the administrator screen by a user with page editing privileges. Version 1.7.42 contains…

  • CVE-2023-31746CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.03

    There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated attacker can exploit the vulnerability to execute system commands as the root user.

  • CVE-2023-30150CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php.

  • CVE-2023-1329CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.01

    A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products.

  • CVE-2023-31671CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via PostfinanceValidationModuleFrontController::postProcess().

  • CVE-2023-34095CriJun 14, 2023
    risk 0.00cvss 9.8epss 0.02

    cpdb-libs provides frontend and backend libraries for the Common Printing Dialog Backends (CPDB) project. In versions 1.0 through 2.0b4, cpdb-libs is vulnerable to buffer overflows via improper use of `scanf(3)`. cpdb-libs uses the `fscanf()` and `scanf()` functions to parse…

  • CVE-2023-25367CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.02

    Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS allows unfiltered user input resulting in Remote Code Execution (RCE) with SCPI interface or web server.

  • CVE-2023-34540CriJun 14, 2023
    risk 0.57cvss 9.8epss 0.02

    Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper (aka the JIRA API wrapper). This vulnerability allows attackers to execute arbitrary code via crafted input. As noted in the "releases/tag" reference,…

  • CVE-2023-34865CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.

  • CVE-2023-34756CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.

  • CVE-2023-34755CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.

  • CVE-2023-34754CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.03

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.

  • CVE-2023-34753CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.

  • CVE-2023-34752CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

  • CVE-2023-34751CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.

  • CVE-2023-34750CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.01

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit.

  • CVE-2023-34747CriJun 14, 2023
    risk 0.65cvss 9.8epss 0.20

    File upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload.

  • CVE-2023-32015CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

  • CVE-2023-32014CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

  • CVE-2023-29363CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

  • CVE-2023-29357CriKEVJun 14, 2023
    risk 0.93cvss 9.8epss 1.00

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

  • CVE-2023-24470CriJun 13, 2023
    risk 0.59cvss 9.1epss 0.01

    Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0.

  • CVE-2023-34944CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.

  • CVE-2023-29562CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-Link TL-WPA7510 (EU)_V2_190125 was discovered to contain a stack overflow via the operation parameter at /admin/locale.

  • CVE-2022-28550CriJun 13, 2023
    risk 0.00cvss 9.8epss 0.01

    Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhead does not check the boundary of the stack buffer. As a result, there will be a stack buffer…

  • CVE-2023-27836CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.02

    TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the devicePwd parameter in the function sub_ 40A80C.

  • CVE-2022-43684CriJun 13, 2023
    risk 0.64cvss 9.9epss 0.02

    ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to Patch 10 Hot Fix 8b * …