VYPR

CVEs

31,788 total · page 261 of 636

  • CVE-2023-33476CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.02

    ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by incorrect validation logic when handling HTTP requests using chunked transport encoding. This results in other code later using attacker-controlled chunk…

  • CVE-2023-30604CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    It is identified a vulnerability of insufficient authentication in the system configuration interface of Hitron Technologies CODA-5310. An unauthorized remote attacker can exploit this vulnerability to access system configuration interface, resulting in performing arbitrary…

  • CVE-2023-30603CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Hitron Technologies CODA-5310 Telnet function with the default account and password, and there is no warning or prompt to ask users to change the default password and account. An unauthenticated remote attackers can exploit this vulnerability to obtain the administrator’s…

  • CVE-2023-28701CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    ELITE TECHNOLOGY CORP. Web Fax has a vulnerability of SQL Injection. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to perform arbitrary system commands, disrupt service or terminate service.

  • CVE-2023-28698CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Wade Graphic Design FANTSY has a vulnerability of insufficient authorization check. An unauthenticated remote user can exploit this vulnerability by modifying URL parameters to gain administrator privileges to perform arbitrary system operation or disrupt service.

  • CVE-2023-3000CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Erikoglu Technology ErMon allows Command Line Execution through SQL Injection, Authentication Bypass. This issue affects ErMon: before 230602.

  • CVE-2023-29746CriJun 2, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in The Thaiger v.1.2 for Android allows unauthorized apps to cause a code execution attack by manipulating the SharedPreference files.

  • CVE-2022-45938CriJun 2, 2023
    risk 0.62cvss 9.0epss 0.45

    An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code Execution and privilege escalation..

  • CVE-2023-29736CriJun 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary files in its internal storage and achieve arbitrary code execution.

  • CVE-2023-29722CriJun 1, 2023
    risk 0.59cvss 9.1epss 0.01

    The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized apps to actively request permission to modify data in the database that records information about a user's personal preferences and will be loaded into memory to be read and used when the app is…

  • CVE-2023-33963CriJun 1, 2023
    risk 0.64cvss 9.8epss 0.01

    DataEase is an open source data visualization and analysis tool. Prior to version 1.18.7, a deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The vulnerability has been fixed in v1.18.7. There are no known…

  • CVE-2023-33965CriJun 1, 2023
    risk 0.56cvss 9.6epss 0.02

    Brook is a cross-platform programmable network tool. The `tproxy` server is vulnerable to a drive-by command injection. An attacker may fool a victim into visiting a malicious web page which will trigger requests to the local `tproxy` service leading to remote code execution. A…

  • CVE-2023-22647CriJun 1, 2023
    risk 0.57cvss 9.9epss 0.01

    An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing permissions to manipulate Kubernetes secrets in the local cluster, resulting in the secret being deleted, but their read-level permissions to the secret being…

  • CVE-2022-4333CriJun 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardening guidelines.

  • CVE-2023-33778CriJun 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and Myvigor firmware versions below 2.3.2 were discovered to use hardcoded encryption keys which allows attackers to bind any affected…

  • CVE-2023-23952CriJun 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.

  • CVE-2023-34257CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in BMC Patrol through 23.1.00. The agent's configuration can be remotely modified (and, by default, authentication is not required). Some configuration fields related to SNMP (e.g., masterAgentName or masterAgentStartLine) result in code execution when…

  • CVE-2023-33735CriMay 31, 2023
    risk 0.66cvss 9.8epss 0.33

    D-Link DIR-846 v1.00A52 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in the /HNAP1 interface.

  • CVE-2023-33730CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan Management Console 14.0.1400.2281 allows any remote attacker to retrieve password of any admin or normal user in plain text format.

  • CVE-2021-45039CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.04

    Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21, IPC23, IPC32, IPC36, IPC62, and IPC_HCMN) offer an undocumented UDP service on port 7788 that allows a remote unauthenticated attacker to overflow an internal buffer and achieve…

  • CVE-2022-35744CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability

  • CVE-2023-29747CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Story Saver for Instragram - Video Downloader 1.0.6 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the…

  • CVE-2023-34218CriMay 31, 2023
    risk 0.59cvss 9.1epss 0.01

    In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible

  • CVE-2023-33509CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.01

    KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection.

  • CVE-2023-33508CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.01

    KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE).

  • CVE-2023-33487CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion vulnerability in setDiagnosisCfg.This vulnerability allows an attacker to execute arbitrary commands through the "ip" parameter.

  • CVE-2023-33486CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setOpModeCfg. This vulnerability allows an attacker to execute arbitrary commands through the "hostName" parameter.

  • CVE-2023-2987CriMay 31, 2023
    risk 0.57cvss 9.8epss 0.01

    The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on the 'wa_pdx_op_config_set' function in versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to the…

  • CVE-2023-28347CriMay 31, 2023
    risk 0.63cvss 9.6epss 0.03

    An issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for an attacker to create a proof-of-concept script that functions similarly to a Student Console, providing unauthenticated attackers with the ability to exploit XSS vulnerabilities within the…

  • CVE-2022-47526CriMay 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files. A remote attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the downstream node user. Exploitation of…

  • CVE-2023-29741CriMay 30, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause an escalation of privileges attack by manipulating the database.

  • CVE-2023-29739CriMay 30, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component.

  • CVE-2023-29728CriMay 30, 2023
    risk 0.64cvss 9.8epss 0.01

    The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privilege attack.

  • CVE-2023-29727CriMay 30, 2023
    risk 0.64cvss 9.8epss 0.01

    The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its database that is related to user privacy settings and affects the implementation of the normal functionality of the application. An attacker can…

  • CVE-2023-34152CriMay 30, 2023
    risk 0.64cvss 9.8epss 0.08

    A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

  • CVE-2023-33734CriMay 30, 2023
    risk 0.64cvss 9.8epss 0.01

    BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php.

  • CVE-2023-29734CriMay 30, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the database.

  • CVE-2023-29732CriMay 30, 2023
    risk 0.64cvss 9.8epss 0.01

    SoLive 1.6.14 thru 1.6.20 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the memory when the application…

  • CVE-2022-36247CriMay 30, 2023
    risk 0.59cvss 9.1epss 0.01

    Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za.

  • CVE-2022-36246CriMay 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Insecure Permissions.

  • CVE-2023-33975CriMay 30, 2023
    risk 0.00cvss 9.8epss 0.01

    RIOT-OS, an operating system for Internet of Things (IoT) devices, contains a network stack with the ability to process 6LoWPAN frames. In version 2023.01 and prior, an attacker can send a crafted frame to the device resulting in an out of bounds write in the packet buffer. The…

  • CVE-2023-2972CriMay 30, 2023
    risk 0.57cvss 9.8epss 0.01

    Prototype Pollution in GitHub repository antfu/utils prior to 0.7.3.

  • CVE-2023-33193CriMay 30, 2023
    risk 0.59cvss 9.1epss 0.02

    Emby Server is a user-installable home media server which stores and organizes a user's media files of virtually any format and makes them available for viewing at home and abroad on a broad range of client devices. This vulnerability may allow administrative access to an Emby…

  • CVE-2023-33189CriMay 30, 2023
    risk 0.58cvss 10.0epss 0.01

    Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisions may be made by Pomerium. This issue has been patched in versions 0.17.4, 0.18.1, 0.19.2, 0.20.1, 0.21.4 and 0.22.2.

  • CVE-2023-33175CriMay 30, 2023
    risk 0.52cvss 9.1epss 0.01

    ToUI is a Python package for creating user interfaces (websites and desktop apps) from HTML. ToUI is using Flask-Caching (SimpleCache) to store user variables. Websites that use `Website.user_vars` property. It affects versions 2.0.1 to 2.4.0. This issue has been patched in…

  • CVE-2023-34205CriMay 30, 2023
    risk 0.52cvss 9.1epss 0.00

    In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. Thus, signature validation can be bypassed via a Signature Wrapping attack (aka XSW).

  • CVE-2023-32692CriMay 30, 2023
    risk 0.57cvss 9.8epss 0.01

    CodeIgniter is a PHP full-stack web framework. This vulnerability allows attackers to execute arbitrary code when you use Validation Placeholders. The vulnerability exists in the Validation library, and validation methods in the controller and in-model validation are also…

  • CVE-2022-24629CriMay 29, 2023
    risk 0.70cvss 9.8epss 0.37

    An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to…

  • CVE-2022-24627CriMay 29, 2023
    risk 0.69cvss 9.8epss 0.26

    An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.

  • CVE-2019-19791CriMay 29, 2023
    risk 0.64cvss 9.8epss 0.01

    In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). For example, an attacker can insert index.fcgi/index.fcgi into a URL to…