VYPR

CVEs

31,788 total · page 262 of 636

  • CVE-2015-20108CriMay 27, 2023
    risk 0.57cvss 9.8epss 0.01

    xml_security.rb in the ruby-saml gem before 1.0.0 for Ruby allows XPath injection and code execution because prepared statements are not used.

  • CVE-2023-32321CriMay 26, 2023
    risk 0.64cvss 9.8epss 0.02

    CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have been discovered in Ckan which may lead to remote code execution. An arbitrary file write in `resource_create` and `package_update` actions, using the…

  • CVE-2023-2825CriMay 26, 2023
    risk 0.74cvss 10.0epss 0.72

    An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

  • CVE-2022-48479CriMay 26, 2023
    risk 0.64cvss 9.8epss 0.00

    The facial recognition TA of some products has the out-of-bounds memory read vulnerability. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.

  • CVE-2022-48478CriMay 26, 2023
    risk 0.64cvss 9.8epss 0.00

    The facial recognition TA of some products lacks memory length verification. Successful exploitation of this vulnerability may cause exceptions of the facial recognition service.

  • CVE-2021-46887CriMay 26, 2023
    risk 0.64cvss 9.8epss 0.00

    Lack of length check vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may cause out-of-bounds read.

  • CVE-2023-30145CriMay 26, 2023
    risk 0.63cvss 9.8epss 0.46

    Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.

  • CVE-2022-46945CriMay 26, 2023
    risk 0.55cvss 9.1epss 0.04

    Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php.

  • CVE-2023-33280CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.

  • CVE-2023-33279CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.

  • CVE-2023-33278CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    In the Store Commander scexportcustomers module for PrestaShop through 3.6.1, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.

  • CVE-2023-26216CriMay 25, 2023
    risk 0.59cvss 9.1epss 0.01

    The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an exploitable vulnerability that allows an attacker to upload files to a directory accessible by the web server. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 4.5.16 and below.

  • CVE-2023-2851CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AGT Tech Ceppatron allows Command Line Execution through SQL Injection, SQL Injection. This issue affects all versions of the sofware also EOS when CVE-ID assigned.

  • CVE-2023-2887CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

  • CVE-2023-2884CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability in CBOT Chatbot allows Signature Spoofing by Key Recreation. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

  • CVE-2023-2882CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Generation of Incorrect Security Tokens vulnerability in CBOT Chatbot allows Token Impersonation, Privilege Abuse. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

  • CVE-2023-2734CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.04

    The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being supplied during the cart sync from mobile REST API request through the plugin. This makes it possible…

  • CVE-2023-2733CriMay 25, 2023
    risk 0.64cvss 9.8epss 0.01

    The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being supplied during the coupon redemption REST API request through the plugin. This makes it possible for…

  • CVE-2023-2732CriMay 25, 2023
    risk 0.69cvss 9.8epss 0.68

    The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for…

  • CVE-2023-31458CriMay 24, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the Edge Gateway component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because initial installation does not enforce…

  • CVE-2023-29721CriMay 24, 2023
    risk 0.64cvss 9.8epss 0.01

    SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution.

  • CVE-2023-33796CriMay 24, 2023
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, granting them access to sensitive data stored in the database. NOTE: the vendor disputes this because the reporter's only query was for the schema of the API, which…

  • CVE-2023-31457CriMay 24, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.

  • CVE-2023-2868CriKEVMay 24, 2023
    risk 0.83cvss 9.4epss 0.87

    A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape…

  • CVE-2023-1174CriMay 24, 2023
    risk 0.64cvss 9.8epss 0.01

    This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube container.

  • CVE-2023-33246CriKEVMay 24, 2023
    risk 0.16cvss 9.8epss 0.97

    For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit…

  • CVE-2023-2064CriMay 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Minova Technology eTrace allows SQL Injection. This issue affects eTrace: before 23.05.20.

  • CVE-2023-2045CriMay 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ipekyolu Software Auto Damage Tracking Software allows SQL Injection. This issue affects Auto Damage Tracking Software: before 4.

  • CVE-2023-33010CriKEVMay 24, 2023
    risk 0.78cvss 9.8epss 0.29

    A buffer overflow vulnerability in the ID processing function in Zyxel ATP series firmware versions 4.32 through 5.36 Patch 1, USG FLEX series firmware versions 4.50 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.25 through 5.36 Patch 1, USG20(W)-VPN firmware versions…

  • CVE-2023-33009CriKEVMay 24, 2023
    risk 0.78cvss 9.8epss 0.28

    A buffer overflow vulnerability in the notification function in Zyxel ATP series firmware versions 4.60 through 5.36 Patch 1, USG FLEX series firmware versions 4.60 through 5.36 Patch 1, USG FLEX 50(W) firmware versions 4.60 through 5.36 Patch 1, USG20(W)-VPN firmware versions…

  • CVE-2023-2750CriMay 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cityboss E-municipality allows SQL Injection. This issue affects E-municipality: before 6.05.

  • CVE-2023-1424CriMay 24, 2023
    risk 0.65cvss 10.0epss 0.03

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules and MELSEC iQ-R Series CPU modules allows a remote unauthenticated attacker to cause a denial of service (DoS) condition or…

  • CVE-2023-1508CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adam Retail Automation Systems Mobilmen Terminal Software allows SQL Injection. This issue affects Mobilmen Terminal Software: before 3.

  • CVE-2023-31752CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/classes/Login.php.

  • CVE-2023-23306CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    The `Toybox.Ant.BurstPayload.add` API method in CIQ API version 2.2.0 through 4.1.7 suffers from a type confusion vulnreability, which can result in an out-of-bounds write operation. A malicious application could create a specially crafted `Toybox.Ant.BurstPayload` object, call…

  • CVE-2023-23305CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    The GarminOS TVM component in CIQ API version 1.0.0 through 4.1.7 is vulnerable to various buffer overflows when loading binary resources. A malicious application embedding specially crafted resources could hijack the execution of the device's firmware.

  • CVE-2023-23304CriMay 23, 2023
    risk 0.59cvss 9.1epss 0.01

    The GarminOS TVM component in CIQ API version 2.1.0 through 4.1.7 allows applications with a specially crafted head section to use the `Toybox.SensorHistory` module without permission. A malicious application could call any functions from the `Toybox.SensorHistory` module…

  • CVE-2023-23303CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    The `Toybox.Ant.GenericChannel.enableEncryption` API method in CIQ API version 3.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with specially crafted…

  • CVE-2023-23302CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    The `Toybox.GenericChannel.setDeviceConfig` API method in CIQ API version 1.2.0 through 4.1.7 does not validate its parameter, which can result in buffer overflows when copying various attributes. A malicious application could call the API method with specially crafted object…

  • CVE-2023-23301CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    The `news` MonkeyC operation code in CIQ API version 1.0.0 through 4.1.7 fails to check that string resources are not extending past the end of the expected sections. A malicious CIQ application could craft a string that starts near the end of a section, and whose length extends…

  • CVE-2023-23300CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    The `Toybox.Cryptography.Cipher.initialize` API method in CIQ API version 3.0.0 through 4.1.7 does not validate its parameters, which can result in buffer overflows when copying data. A malicious application could call the API method with specially crafted parameters and hijack…

  • CVE-2023-23298CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    The `Toybox.Graphics.BufferedBitmap.initialize` API method in CIQ API version 2.3.0 through 4.1.7 does not validate its parameters, which can result in integer overflows when allocating the underlying bitmap buffer. A malicious application could call the API method with…

  • CVE-2023-33362CriMay 23, 2023
    risk 0.67cvss 9.8epss 0.09

    Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.

  • CVE-2023-33361CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php.

  • CVE-2023-33338CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.04

    Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.

  • CVE-2023-28413CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.02

    Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition.

  • CVE-2023-28409CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file.

  • CVE-2023-28408CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.02

    Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to alter the website or cause a denial-of-service (DoS) condition, and obtain sensitive information depending on settings.

  • CVE-2023-27507CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.

  • CVE-2023-27397CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.