VYPR

CVEs

31,788 total · page 259 of 636

  • CVE-2023-3224CriJun 13, 2023
    risk 0.61cvss 9.8epss 0.59

    Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.

  • CVE-2023-34249CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    benjjvi/PyBB is an open source bulletin board. Prior to commit dcaeccd37198ecd3e41ea766d1099354b60d69c2, benjjvi/PyBB is vulnerable to SQL Injection. This vulnerability has been fixed as of commit dcaeccd37198ecd3e41ea766d1099354b60d69c2. As a workaround, a user may be able to…

  • CVE-2023-31541CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.

  • CVE-2023-27837CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.02

    TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the key parameter in the function sub_ 40A774.

  • CVE-2023-35064CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Satos Satos Mobile allows SQL Injection through SOAP Parameter Tampering. This issue affects Satos Mobile: before 20230607.

  • CVE-2023-3050CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Reliance on Cookies without Validation and Integrity Checking in a Security Decision vulnerability in TMT Lockcell allows Privilege Abuse, Authentication Bypass. This issue affects Lockcell: before 15.

  • CVE-2023-3049CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.04

    Unrestricted Upload of File with Dangerous Type vulnerability in TMT Lockcell allows Command Injection. This issue affects Lockcell: before 15.

  • CVE-2023-3048CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authentication Bypass. This issue affects Lockcell: before 15.

  • CVE-2023-3047CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.02

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TMT Lockcell allows SQL Injection. This issue affects Lockcell: before 15.

  • CVE-2023-30766CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Hidden functionality issue exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS command may be executed on the product or the device settings may be altered. Affected products and versions are as follows: KB-AHR04D versions prior to…

  • CVE-2023-30764CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.02

    OS command injection vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS command may be executed on the product or the device settings may be altered. Affected products and versions are as follows: KB-AHR04D versions…

  • CVE-2023-30762CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper authentication vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS command may be executed on the product or the device settings may be altered. Affected products and versions are as follows: KB-AHR04D versions…

  • CVE-2023-29129CriJun 13, 2023
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.4.0), Mendix SAML (Mendix 8…

  • CVE-2023-27997CriKEVJun 13, 2023
    risk 0.89cvss 9.8epss 0.86

    A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all…

  • CVE-2023-25910CriJun 13, 2023
    risk 0.65cvss 10.0epss 0.01

    A vulnerability has been identified in SIMATIC PCS 7 (All versions < V9.1 SP2 UC04), SIMATIC S7-PM (All versions < V5.7 SP1 HF1), SIMATIC S7-PM (All versions < V5.7 SP2 HF1), SIMATIC STEP 7 V5 (All versions < V5.7). The affected product contains a database management system that…

  • CVE-2023-2278CriJun 13, 2023
    risk 0.57cvss 9.8epss 0.02

    The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any…

  • CVE-2023-32674CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to buffer overflow.

  • CVE-2023-32673CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are potentially vulnerable to elevation of privilege.

  • CVE-2023-26295CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.02

    Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

  • CVE-2023-27716CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in freakchicken kafkaUI-lite 1.2.11 allows attackers on the same network to gain escalated privileges for the nodes running on it.

  • CVE-2023-33626CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a stack overflow via the gena.cgi binary.

  • CVE-2023-33625CriJun 12, 2023
    risk 0.69cvss 9.8epss 0.33

    D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxmldbc_system() function.

  • CVE-2023-1899CriJun 12, 2023
    risk 0.61cvss 9.4epss 0.00

    Atlas Copco Power Focus 6000 web server is not a secure connection by default, which could allow an attacker to gain sensitive information by monitoring network traffic between user and controller.

  • CVE-2023-1898CriJun 12, 2023
    risk 0.61cvss 9.4epss 0.01

    Atlas Copco Power Focus 6000 web server uses a small amount of session ID numbers. An attacker could enter a session ID number to retrieve data for an active user’s session.

  • CVE-2023-1897CriJun 12, 2023
    risk 0.61cvss 9.4epss 0.00

    Atlas Copco Power Focus 6000 web server does not sanitize the login information stored by the authenticated user’s browser, which could allow an attacker with access to the user’s computer to gain credential information of the controller.

  • CVE-2022-36331CriJun 12, 2023
    risk 0.65cvss 10.0epss 0.01

    Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and…

  • CVE-2023-35042CriJun 12, 2023
    risk 0.67cvss 9.8epss 0.43

    GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023. NOTE: the vendor states that they are unable to reproduce this…

  • CVE-2023-34581CriJun 12, 2023
    risk 0.67cvss 9.8epss 0.03

    Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2

  • CVE-2023-35036CriJun 12, 2023
    risk 0.60cvss 9.1epss 0.13

    In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilities have been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain…

  • CVE-2023-35034CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow remote code execution by unauthenticated users, aka OSFOURK-24033.

  • CVE-2023-25911CriJun 11, 2023
    risk 0.65cvss 9.9epss 0.02

    The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web application parameters.

  • CVE-2023-22585CriJun 11, 2023
    risk 0.59cvss 9.0epss 0.01

    The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting in the title parameter.

  • CVE-2023-22583CriJun 11, 2023
    risk 0.65cvss 10.0epss 0.01

    The Danfoss AK-EM100 web forms allow for SQL injection in the login forms.

  • CVE-2023-22582CriJun 11, 2023
    risk 0.59cvss 9.0epss 0.01

    The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting.

  • CVE-2023-34364CriJun 9, 2023
    risk 0.64cvss 9.8epss 0.02

    A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. An overly large value for certain options of a connection string may overrun the buffer allocated to process the string value. This allows an attacker to execute code of their…

  • CVE-2023-3173CriJun 9, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.

  • CVE-2023-29405CriJun 8, 2023
    risk 0.64cvss 9.8epss 0.02

    The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive.…

  • CVE-2023-29404CriJun 8, 2023
    risk 0.64cvss 9.8epss 0.02

    The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive.…

  • CVE-2023-29402CriJun 8, 2023
    risk 0.64cvss 9.8epss 0.02

    The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline characters in their names. Modules…

  • CVE-2023-34566CriJun 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.

  • CVE-2023-33443CriJun 8, 2023
    risk 0.64cvss 9.8epss 0.04

    Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitrary administrative commands via a crafted payload sent to the desired endpoints.

  • CVE-2023-2986CriJun 8, 2023
    risk 0.67cvss 9.8epss 0.43

    The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the abandoned cart link decode through the plugin. This allows…

  • CVE-2023-33556CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg.

  • CVE-2023-33496CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode.

  • CVE-2023-31116CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. An incorrect default permission can cause unintended querying of RCS capability via a crafted application.

  • CVE-2023-31114CriJun 7, 2023
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer between spheres can cause unintended querying of the SIM status via a crafted application.

  • CVE-2023-33864CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.04

    StreamReader::ReadFromExternal in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. It uses uint32_t(m_BufferSize-m_InputSize) even though m_InputSize can exceed m_BufferSize.

  • CVE-2023-33863CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.04

    SerialiseValue in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. 0xffffffff is sign-extended to 0xffffffffffffffff (SIZE_MAX) and then there is an attempt to add 1.

  • CVE-2023-33282CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid session. This makes it possible to make backend calls to endpoints in the application.

  • CVE-2023-2530CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    A privilege escalation allowing remote code execution was discovered in the orchestration service.