VYPR

CVEs

31,788 total · page 260 of 636

  • CVE-2023-33553CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipulation of the LoginStatus cookie.

  • CVE-2023-20887CriKEVJun 7, 2023
    risk 0.87cvss 9.8epss 0.98

    Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.

  • CVE-2021-4380CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.05

    The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up to, and including, 1.14.3. This makes it possible for…

  • CVE-2020-36705CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.07

    The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and including, 1.5.5. This makes it possible for unauthenticated attackers to upload arbitrary files on…

  • CVE-2023-33604CriJun 7, 2023
    risk 0.59cvss 9.1epss 0.01

    Imperial CMS v7.5 was discovered to contain an arbitrary file deletion vulnerability via the DelspReFile function in /sp/ListSp.php. This vulnerability is exploited by attackers via a crafted POST request.

  • CVE-2021-4381CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::import_new_layout method in versions up to, and including, 1.6.6. This makes it possible for…

  • CVE-2021-4374CriJun 7, 2023
    risk 0.63cvss 9.1epss 0.16

    The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the process_form.php file. This makes it possible for unauthenticated attackers to…

  • CVE-2021-4370CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is seldom validated. This issue exists in versions up to, and including, 1.6.6. This makes it possible…

  • CVE-2021-4368CriJun 7, 2023
    risk 0.64cvss 9.9epss 0.02

    The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_settings AJAX action. This makes it possible for…

  • CVE-2021-4362CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiwi_social_share_get_option AJAX action in version 2.1.0. This makes it possible for unauthenticated…

  • CVE-2021-4360CriJun 7, 2023
    risk 0.64cvss 9.9epss 0.01

    The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator role with unrestricted…

  • CVE-2021-4357CriJun 7, 2023
    risk 0.59cvss 9.1epss 0.01

    The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers…

  • CVE-2021-4356CriJun 7, 2023
    risk 0.59cvss 9.0epss 0.02

    The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action.…

  • CVE-2021-4347CriJun 7, 2023
    risk 0.64cvss 9.9epss 0.01

    The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any…

  • CVE-2021-4346CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers to edit any…

  • CVE-2021-4343CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_register AJAX action function being accessible and taking roles unprotected. This makes it possible…

  • CVE-2021-4341CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and including, 1.6.6. This makes it possible for…

  • CVE-2021-4340CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

  • CVE-2020-36727CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.02

    The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed through a deserialization function. This potentially makes it…

  • CVE-2020-36726CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.02

    The Ultimate Reviews plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.32 via deserialization of untrusted input in several vulnerable functions. This allows unauthenticated attackers to inject a PHP Object. No POP chain is present…

  • CVE-2020-36724CriJun 7, 2023
    risk 0.57cvss 9.8epss 0.02

    The Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This is due to the use of a user supplied hashing algorithm passed to the hash_hmac() function and the use of a loose comparison on the hash which allows an attacker…

  • CVE-2020-36719CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.04

    The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. This is due to a missing capability check on the lp_cc_addons_actions function. This makes it possible for…

  • CVE-2020-36718CriJun 7, 2023
    risk 0.57cvss 9.8epss 0.02

    The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization of untrusted input "njt_gdpr_allow_permissions" value. This allows unauthenticated attackers to inject a PHP Object.

  • CVE-2020-36713CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.02

    The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.1.5. This is due to unrestricted access to the 'register' and 'update_user_profile' routes. This makes it possible for unauthenticated attackers to create new…

  • CVE-2020-36708CriJun 7, 2023
    risk 0.69cvss 9.8epss 0.65

    The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <=…

  • CVE-2019-25141CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.04

    The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. This is due to missing capability checks on the admin_init() function, in addition to insufficient input validation. This makes it possible for unauthenticated…

  • CVE-2019-25138CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.02

    The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_check_images function in versions up to, and including, 20190312. This makes it possible for unauthenticated attackers to upload arbitrary files…

  • CVE-2016-15033CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.02

    The Delete All Comments plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the via the delete-all-comments.php file in versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to upload arbitrary…

  • CVE-2023-30400CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Anyka Microelectronics AK3918EV300 MCU v18. A command injection vulnerability in the network configuration script within the MCU's operating system allows attackers to perform arbitrary command execution via a crafted wifi SSID or password.

  • CVE-2023-34409CriJun 6, 2023
    risk 0.64cvss 9.8epss 0.01

    In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path traversal attempts. This allows an unauthenticated remote user, when a crafted POST request is made…

  • CVE-2023-29632CriJun 6, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop jmspagebuilder 3.x is vulnerable to SQL Injection via ajax_jmspagebuilder.php.

  • CVE-2023-32550CriJun 6, 2023
    risk 0.60cvss 9.3epss 0.00

    Landscape's server-status page exposed sensitive system information. This data leak included GET requests which contain information to attack and leak further information from the Landscape API.

  • CVE-2023-33532CriJun 6, 2023
    risk 0.65cvss 9.8epss 0.16

    There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters, thereby gaining shell privileges.

  • CVE-2023-31569CriJun 6, 2023
    risk 0.64cvss 9.8epss 0.03

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection via the setWanCfg function.

  • CVE-2023-29631CriJun 5, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop jmsslider 1.6.0 is vulnerable to Incorrect Access Control via ajax_jmsslider.php.

  • CVE-2023-29630CriJun 5, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop jmsmegamenu 1.1.x and 2.0.x is vulnerable to SQL Injection via ajax_jmsmegamenu.php.

  • CVE-2023-29629CriJun 5, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop jmsthemelayout 2.5.5 is vulnerable to SQL Injection via ajax_jmsvermegamenu.php.

  • CVE-2023-33386CriJun 5, 2023
    risk 0.64cvss 9.8epss 0.01

    MarsCTF 1.2.1 has an arbitrary file upload vulnerability in the interface for uploading attachments in the background.

  • CVE-2023-3065CriJun 5, 2023
    risk 0.59cvss 9.1epss 0.01

    Improper Authentication vulnerability in Mobatime mobile application AMXGT100 allows Authentication Bypass.This issue affects Mobatime mobile application AMXGT100 through 1.3.20.

  • CVE-2023-32217CriJun 5, 2023
    risk 0.59cvss 9.0epss 0.01

    IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p3, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p6, IdentityIQ 8.1 and all 8.1 patch levels prior to 8.1p7, IdentityIQ 8.0 and all 8.0 patch levels prior to 8.0p6 allow an authenticated user to invoke a Java…

  • CVE-2023-3086CriJun 3, 2023
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

  • CVE-2023-33762CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    eMedia Consulting simpleRedak up to v2.47.23.05 was discovered to contain a SQL injection vulnerability via the Activity parameter.

  • CVE-2023-33675CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the get_parentControl_list_Info function.

  • CVE-2023-33673CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the firewallEn parameter in the formSetFirewallCfg function.

  • CVE-2023-33671CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the deviceId parameter in the saveParentControlInfo function.

  • CVE-2023-33670CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the time parameter in the sub_4a79ec function.

  • CVE-2023-33669CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AC8V4.0-V16.03.34.06 was discovered to contain a stack overflow via the timeZone parameter in the sub_44db3c function.

  • CVE-2023-3069CriJun 2, 2023
    risk 0.00cvss 9.8epss 0.01

    Unverified Password Change in GitHub repository tsolucio/corebos prior to 8.

  • CVE-2023-30149CriJun 2, 2023
    risk 0.65cvss 9.8epss 0.18

    SQL injection vulnerability in the City Autocomplete (cityautocomplete) module from ebewe.net for PrestaShop, prior to version 1.8.12 (for PrestaShop version 1.5/1.6) or prior to 2.0.3 (for PrestaShop version 1.7), allows remote attackers to execute arbitrary SQL commands via…

  • CVE-2023-34362CriKEVJun 2, 2023
    risk 0.93cvss 9.8epss 1.00

    In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL injection vulnerability has been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain access…