VYPR

CVEs

31,788 total · page 263 of 636

  • CVE-2023-27388CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper authentication vulnerability in T&D Corporation and ESPEC MIC CORP. data logger products allows a remote unauthenticated attacker to login to the product as a registered user. Affected products and versions are as follows: T&D Corporation data logger products…

  • CVE-2023-25953CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected product is installed to inject arbitrary code while processing the product execution. Since a full disk access privilege is…

  • CVE-2023-31814CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-300 firmware <=REVA1.06 and <=REVB2.06 is vulnerable to File inclusion via /model/__lang_msg.php.

  • CVE-2023-29919CriMay 23, 2023
    risk 0.64cvss 9.1epss 0.60

    SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.

  • CVE-2023-27068CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.02

    Deserialization of Untrusted Data in Sitecore Experience Platform through 10.2 allows remote attackers to run arbitrary code via ValidationResult.aspx.

  • CVE-2020-20012CriMay 23, 2023
    risk 0.64cvss 9.8epss 0.01

    WebPlus Pro v1.4.7.8.4-01 is vulnerable to Incorrect Access Control.

  • CVE-2023-31689CriMay 22, 2023
    risk 0.65cvss 9.8epss 0.20

    In Wcms 0.3.2, an attacker can send a crafted request from a vulnerable web application backend server /wcms/wex/html.php via the finish parameter and the textAreaCode parameter. It can write arbitrary strings into custom file names and upload any files, and write malicious code…

  • CVE-2023-2840CriMay 22, 2023
    risk 0.00cvss 9.8epss 0.01

    NULL Pointer Dereference in GitHub repository gpac/gpac prior to 2.2.2.

  • CVE-2023-2838CriMay 22, 2023
    risk 0.00cvss 9.1epss 0.01

    Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.2.2.

  • CVE-2023-33294CriMay 22, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in KaiOS 3.0 before 3.1. The /system/bin/tctweb_server binary exposes a local web server that responds to GET and POST requests on port 2929. The server accepts arbitrary Bash commands and executes them as root. Because it is not permission or context…

  • CVE-2023-31098CriMay 22, 2023
    risk 0.57cvss 9.8epss 0.01

    Weak Password Requirements vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.6.0.  When users change their password to a simple password (with any character or symbol), attackers can easily guess the user's…

  • CVE-2023-31066CriMay 22, 2023
    risk 0.52cvss 9.1epss 0.01

    Files or Directories Accessible to External Parties vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0. Different users in InLong could delete, edit, stop, and start others' sources! Users are advised to upgrade…

  • CVE-2023-31065CriMay 22, 2023
    risk 0.52cvss 9.1epss 0.01

    Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.6.0.  An old session can be used by an attacker even after the user has been deleted or the password has been changed. Users are…

  • CVE-2023-31062CriMay 22, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Privilege Management Vulnerabilities in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0.  When the attacker has access to a valid (but unprivileged) account, the exploit can be executed using Burp Suite by sending a…

  • CVE-2023-2586CriMay 22, 2023
    risk 0.59cvss 9.0epss 0.01

    Teltonika’s Remote Management System versions 4.14.0 is vulnerable to an unauthorized attacker registering previously unregistered devices through the RMS platform. If the user has not disabled the "RMS management feature" enabled by default, then an attacker could register…

  • CVE-2023-33236CriMay 22, 2023
    risk 0.64cvss 9.8epss 0.01

    MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.

  • CVE-2023-2713CriMay 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Authentication Abuse, Authentication Bypass. This issue affects Rental Module: before 23.05.15.

  • CVE-2023-2712CriMay 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server. This issue affects Rental Module: before 23.05.15.

  • CVE-2023-2276CriMay 20, 2023
    risk 0.64cvss 9.8epss 0.01

    The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 2.10.7. This is due to the plugin providing user-controlled access to objects, letting a user…

  • CVE-2023-31707CriMay 19, 2023
    risk 0.64cvss 9.8epss 0.01

    SEMCMS 1.5 is vulnerable to SQL Injection via Ant_Rponse.php.

  • CVE-2023-2704CriMay 19, 2023
    risk 0.64cvss 9.8epss 0.02

    The BP Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.5. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for unauthenticated…

  • CVE-2023-30470CriMay 18, 2023
    risk 0.00cvss 9.8epss 0.01

    A use-after-free related to unsound inference in the bytecode generation when optimizations are enabled for Hermes prior to commit da8990f737ebb9d9810633502f65ed462b819c09 could have been used by an attacker to achieve remote code execution. Note that this is only exploitable in…

  • CVE-2023-28753CriMay 18, 2023
    risk 0.00cvss 9.8epss 0.02

    netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could leverage this overflow to create heap memory corruption with attacker controlled data.

  • CVE-2023-28081CriMay 18, 2023
    risk 0.57cvss 9.8epss 0.01

    A bytecode optimization bug in Hermes prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could be used to cause an use-after-free and obtain arbitrary code execution via a carefully crafted payload. Note that this is only exploitable in cases where Hermes is used to…

  • CVE-2023-25933CriMay 18, 2023
    risk 0.00cvss 9.8epss 0.01

    A type confusion bug in TypedArray prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81 could have been used by a malicious attacker to execute arbitrary code via untrusted JavaScript. Note that this is only exploitable in cases where Hermes is used to execute untrusted…

  • CVE-2023-23557CriMay 18, 2023
    risk 0.00cvss 9.8epss 0.01

    An error in Hermes' algorithm for copying objects properties prior to commit a00d237346894c6067a594983be6634f4168c9ad could be used by a malicious attacker to execute arbitrary code via type confusion. Note that this is only exploitable in cases where Hermes is used to execute…

  • CVE-2023-23556CriMay 18, 2023
    risk 0.00cvss 9.8epss 0.01

    An error in BigInt conversion to Number in Hermes prior to commit a6dcafe6ded8e61658b40f5699878cd19a481f80 could have been used by a malicious attacker to execute arbitrary code due to an out-of-bound write. Note that this bug is only exploitable in cases where Hermes is used to…

  • CVE-2023-2024CriMay 18, 2023
    risk 0.65cvss 10.0epss 0.01

    Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.

  • CVE-2023-30333CriMay 18, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/ThemeController.java of PerfreeBlog v3.1.2 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2023-27217CriMay 18, 2023
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow in the ChangeFriendlyName() function of Belkin Smart Outlet V2 F7c063 firmware_2.00.11420.OWRT.PVT_SNSV2 allows attackers to cause a Denial of Service (DoS) via a crafted UPNP request.

  • CVE-2023-31729CriMay 18, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3300R v17.0.0cu.557 is vulnerable to Command Injection via /cgi-bin/cstecgi.cgi.

  • CVE-2023-29985CriMay 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vulnerability.

  • CVE-2023-2319CriMay 17, 2023
    risk 0.64cvss 9.8epss 0.01

    It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix for the Webpack issue CVE-2023-28154 (for PCS package), which was previously addressed in Red Hat Enterprise Linux 9.1 via…

  • CVE-2023-2780CriMay 17, 2023
    risk 0.57cvss 9.8epss 0.06

    Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.

  • CVE-2023-30191CriMay 17, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop cdesigner < 3.1.9 is vulnerable to SQL Injection via CdesignerTraitementModuleFrontController::initContent().

  • CVE-2023-31903CriMay 17, 2023
    risk 0.64cvss 9.8epss 0.02

    GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file.

  • CVE-2023-31902CriMay 17, 2023
    risk 0.67cvss 9.8epss 0.09

    RPA Technology Mobile Mouse 3.6.0.4 is vulnerable to Remote Code Execution (RCE).

  • CVE-2023-31703CriMay 17, 2023
    risk 0.62cvss 9.0epss 0.04

    Cross Site Scripting (XSS) in the edit user form in Microworld Technologies eScan management console 14.0.1400.2281 allows remote attacker to inject arbitrary code via the from parameter.

  • CVE-2023-30438CriMay 17, 2023
    risk 0.60cvss 9.3epss 0.00

    An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the isolation between logical partitions which could lead to data leakage or the…

  • CVE-2023-30189CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.01

    Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook().

  • CVE-2023-27742CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.01

    IDURAR ERP/CRM v1 was discovered to contain a SQL injection vulnerability via the component /api/login.

  • CVE-2023-31890CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.01

    An XML Deserialization vulnerability in glazedlists v1.11.0 allows an attacker to execute arbitrary code via the BeanXMLByteCoder.decode() parameter.

  • CVE-2023-31857CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.02

    Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution. The vulnerability path is /classes/Users.php?f=save.

  • CVE-2023-31856CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.03

    A command injection vulnerability in the hostTime parameter in the function NTPSyncWithHostof TOTOLINK CP300+ V5.2cu.7594_B20200910 allows attackers to execute arbitrary commands via a crafted http packet.

  • CVE-2023-31587CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AC5 router V15.03.06.28 was discovered to contain a remote code execution (RCE) vulnerability via the Mac parameter at ip/goform/WriteFacMac.

  • CVE-2023-31519CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.01

    Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the email parameter at login_core.php.

  • CVE-2023-2499CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.01

    The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user being supplied during a Google social login through the plugin. This makes it possible for…

  • CVE-2023-32956CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.02

    Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to execute arbitrary code via unspecified vectors.

  • CVE-2023-29961CriMay 16, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup,

  • CVE-2021-0877CriMay 15, 2023
    risk 0.64cvss 9.8epss 0.00

    Product: AndroidVersions: Android SoCAndroid ID: A-273754094