VYPR

CVEs

31,788 total · page 267 of 636

  • CVE-2023-24796CriApr 26, 2023
    risk 0.64cvss 9.8epss 0.02

    Password vulnerability found in Vinga WR-AC1200 81.102.1.4370 and before allows a remote attacker to execute arbitrary code via the password parameter at the /goform/sysTools and /adm/systools.asp endpoints.

  • CVE-2023-30404CriApr 26, 2023
    risk 0.64cvss 9.8epss 0.02

    Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request.

  • CVE-2023-27843CriApr 26, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop askforaquote v.5.4.2 and before allow a remote attacker to gain privileges via the QuotesProduct::deleteProduct component.

  • CVE-2012-5872CriApr 26, 2023
    risk 0.57cvss 9.8epss 0.01

    ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php via comments in a SPARQL WHERE clause.

  • CVE-2023-30839CriApr 25, 2023
    risk 0.57cvss 9.9epss 0.02

    PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can write, update, and delete in the database, even without having specific rights. PrestaShop 8.0.4 and 1.7.8.9 contain a patch for this…

  • CVE-2021-44547CriApr 25, 2023
    risk 0.59cvss 9.1epss 0.01

    A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading to privilege escalation.

  • CVE-2023-25313CriApr 25, 2023
    risk 0.57cvss 9.8epss 0.01

    OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video link feature.

  • CVE-2023-27105CriApr 25, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows attackers to arbitrarily read, delete, or modify any critical system files via…

  • CVE-2023-28771CriKEVApr 25, 2023
    risk 0.87cvss 9.8epss 0.99

    Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an…

  • CVE-2023-30627CriApr 24, 2023
    risk 0.00cvss 9.0epss 0.01

    jellyfin-web is the web client for Jellyfin, a free-software media system. Starting in version 10.1.0 and prior to version 10.8.10, a stored cross-site scripting vulnerability in device.js can be used to make arbitrary calls to the `REST` endpoints with admin privileges. When…

  • CVE-2023-1020CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.05

    The Steveas WP Live Chat Shoutbox WordPress plugin through 1.4.2 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

  • CVE-2023-29566CriApr 24, 2023
    risk 0.57cvss 9.8epss 0.02

    huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.

  • CVE-2023-27849CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.02

    rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.

  • CVE-2023-27848CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.02

    broccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.

  • CVE-2023-26865CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privileges via the BdroppyCronModuleFrontController::importProducts component.

  • CVE-2023-24823CriApr 24, 2023
    risk 0.00cvss 9.8epss 0.01

    RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in a type confusion between IPv6 extension headers…

  • CVE-2023-30378CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30376CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30375CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function "getIfIp" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30373CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30372CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30371CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30370CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability.

  • CVE-2023-24819CriApr 24, 2023
    risk 0.00cvss 9.8epss 0.01

    RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in an out of bounds write in the packet buffer. The…

  • CVE-2023-30369CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow.

  • CVE-2023-30368CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function.

  • CVE-2023-25133CriApr 24, 2023
    risk 0.59cvss 9.1epss 0.01

    Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel…

  • CVE-2023-25132CriApr 24, 2023
    risk 0.59cvss 9.1epss 0.01

    Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and…

  • CVE-2023-25131CriApr 24, 2023
    risk 0.61cvss 9.4epss 0.01

    Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for…

  • CVE-2023-22581CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under the context of the web application (the default installation makes the webserver run as the root user).

  • CVE-2023-22577CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Within White Rabbit Switch it's possible as an unauthenticated user to retrieve sensitive information such as password hashes and the SNMP community strings.

  • CVE-2023-28131CriApr 24, 2023
    risk 0.64cvss 9.6epss 0.23

    A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself…

  • CVE-2023-31060CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Repetier Server through 1.4.10 executes as SYSTEM. This can be leveraged in conjunction with CVE-2023-31059 for full compromise.

  • CVE-2023-31056CriApr 24, 2023
    risk 0.59cvss 9.1epss 0.01

    CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The fixed versions are 5.15.4, 5.16.2, 5.17.3, and 6.0.x.

  • CVE-2023-23753CriApr 23, 2023
    risk 0.64cvss 9.8epss 0.01

    The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be able to read, modify and delete data on it.

  • CVE-2023-30621CriApr 21, 2023
    risk 0.00cvss 9.8epss 0.02

    Gipsy is a multi-purpose discord bot which aim to be as modular and user-friendly as possible. In versions prior to 1.3 users can run command on the host machine with sudoer permission. The `!ping` command when provided with an IP or hostname used to run a bash `ping `…

  • CVE-2023-29924CriApr 21, 2023
    risk 0.64cvss 9.8epss 0.01

    PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution.

  • CVE-2023-26556CriApr 21, 2023
    risk 0.59cvss 9.1epss 0.01

    io.finnet tss-lib before 2.0.0 can leak a secret key via a timing side-channel attack because it relies on the scalar-multiplication implementation in Go crypto/elliptic, which is not constant time (there is an if statement in a loop). One leak is in ecdsa/keygen/round_2.go.…

  • CVE-2023-2231CriApr 21, 2023
    risk 0.64cvss 9.8epss 0.02

    A vulnerability, which was classified as critical, was found in MAXTECH MAX-G866ac 0.4.1_TBRO_20160314. This affects an unknown part of the component Remote Management. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit…

  • CVE-2023-2227CriApr 21, 2023
    risk 0.56cvss 9.1epss 0.44

    Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.

  • CVE-2023-1892CriApr 21, 2023
    risk 0.56cvss 9.6epss 0.03

    Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.

  • CVE-2023-2131CriApr 20, 2023
    risk 0.65cvss 10.0epss 0.02

    Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to remotely execute arbitrary code.

  • CVE-2023-20873CriApr 20, 2023
    risk 0.57cvss 9.8epss 0.01

    In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to…

  • CVE-2023-20864CriApr 20, 2023
    risk 0.69cvss 9.8epss 0.70

    VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.

  • CVE-2023-30076CriApr 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms/print_judges.php?print_judges.php=&se_name=&sub_event_id=.

  • CVE-2023-29528CriApr 20, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1 and massively improved in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus…

  • CVE-2023-27350CriKEVApr 20, 2023
    risk 0.93cvss 9.8epss 1.00

    This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from…

  • CVE-2023-29926CriApr 20, 2023
    risk 0.64cvss 9.8epss 0.01

    PowerJob V4.3.2 has unauthorized interface that causes remote code execution.

  • CVE-2022-29606CriApr 20, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading to a network operator. Improper handling of such port numbers causes inconsistency between intent and flow rules in the network.

  • CVE-2022-29604CriApr 20, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows the CORRUPT state, which is misleading to a network operator. Improper handling of case sensitivity causes inconsistency between intent and flow rules in the network.