VYPR

CVEs

31,788 total · page 270 of 636

  • CVE-2023-28808CriApr 11, 2023
    risk 0.59cvss 9.1epss 0.01

    Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices.

  • CVE-2023-28250CriApr 11, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

  • CVE-2023-21554CriApr 11, 2023
    risk 0.74cvss 9.8epss 0.95

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2020-19802CriApr 11, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the upload file type parameter.

  • CVE-2022-41331CriApr 11, 2023
    risk 0.64cvss 9.8epss 0.01

    A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.

  • CVE-2023-27192CriApr 11, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in DUALSPACE Super Secuirty v.2.3.7 allows an attacker to cause a denial of service via the key_wifi_safe_net_check_url, KEY_Cirus_scan_whitelist and KEY_AD_NEW_USER_AVOID_TIME parameters.

  • CVE-2023-27645CriApr 11, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in POWERAMP audioplayer build 925 bundle play and build 954 allows a remote attacker to gain privileges via the reverb and EQ preset parameters.

  • CVE-2023-28489CriApr 11, 2023
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). Affected devices are vulnerable to command injection via the web server port 443/tcp, if the parameter “Remote Operation” is enabled.…

  • CVE-2023-29492CriKEVApr 11, 2023
    risk 0.76cvss 9.8epss 0.03

    Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.

  • CVE-2023-28765CriApr 11, 2023
    risk 0.65cvss 9.8epss 0.15

    An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, can get access to lcmbiar file and further decrypt the file. After this attacker can gain access to BI user’s passwords and depending on the…

  • CVE-2023-27497CriApr 11, 2023
    risk 0.65cvss 10.0epss 0.01

    Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation, the attacker can…

  • CVE-2023-27267CriApr 11, 2023
    risk 0.60cvss 9.0epss 0.14

    Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker…

  • CVE-2023-27178CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the upload function of GDidees CMS 3.9.1 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2023-27076CriApr 10, 2023
    risk 0.66cvss 9.8epss 0.23

    Command injection vulnerability found in Tenda G103 v.1.0.0.5 allows attacker to execute arbitrary code via a the language parameter.

  • CVE-2023-26070CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).

  • CVE-2023-26069CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 3 of 4).

  • CVE-2023-26068CriApr 10, 2023
    risk 0.68cvss 9.8epss 0.12

    Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).

  • CVE-2023-26066CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.

  • CVE-2023-26065CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain Lexmark devices through 2023-02-19 have an Integer Overflow.

  • CVE-2023-26064CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.

  • CVE-2023-26063CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain Lexmark devices through 2023-02-19 access a Resource By Using an Incompatible Type.

  • CVE-2022-46709CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13, iOS 16. An app may be able to execute arbitrary code with kernel privileges

  • CVE-2023-27650CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE parameter.

  • CVE-2023-29375CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 before 14.3.8025. There is potentially dangerous file upload through the SharePoint connector.

  • CVE-2022-41976CriApr 10, 2023
    risk 0.64cvss 9.9epss 0.02

    An privilege escalation issue was discovered in Scada-LTS 2.7.1.1 build 2948559113 allows remote attackers, authenticated in the application as a low-privileged user to change role (e.g., to administrator) by updating their user profile.

  • CVE-2023-1478CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.01

    The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.

  • CVE-2023-29216CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.02

    In Apache Linkis <=1.3.1, because the parameters are not effectively filtered, the attacker uses the MySQL data source and malicious parameters to configure a new data source to trigger a deserialization vulnerability, eventually leading to remote code execution. Versions of…

  • CVE-2023-29215CriApr 10, 2023
    risk 0.57cvss 9.8epss 0.02

    In Apache Linkis <=1.3.1, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in JDBC EengineConn Module will trigger a deserialization vulnerability and eventually lead to remote code execution. Therefore, the parameters…

  • CVE-2023-27987CriApr 10, 2023
    risk 0.59cvss 9.1epss 0.01

    In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the default token for the attack. Generation rules should add random values. We recommend users upgrade the version of Linkis to…

  • CVE-2023-27603CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.02

    In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2.

  • CVE-2023-27602CriApr 10, 2023
    risk 0.64cvss 9.8epss 0.02

    In Apache Linkis <=1.3.1, The PublicService module uploads files without restrictions on the path to the uploaded files, and file types. We recommend users upgrade the version of Linkis to version 1.3.2.  For versions <=1.3.1, we suggest turning on the file path check…

  • CVE-2023-27720CriApr 9, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_48d630 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-27719CriApr 9, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_478360 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-27718CriApr 9, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-27033CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Prestashop cdesigner v3.1.3 to v3.1.8 was discovered to contain a code injection vulnerability via the component CdesignerSaverotateModuleFrontController::initContent().

  • CVE-2023-28706CriApr 7, 2023
    risk 0.57cvss 9.8epss 0.03

    Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0.

  • CVE-2023-29478CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.02

    BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution.

  • CVE-2023-26978CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pppoeAcName parameter at /setting/setWanIeCfg.

  • CVE-2023-26848CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the org parameter at setting/delStaticDhcpRules.

  • CVE-2023-27021CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the formSetFirewallCfg function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-27020CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the saveParentControlInfo function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-27019CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_458FBC function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-27018CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45EC1C function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-27017CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_45DC58 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-27016CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-27015CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_4A75C0 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-27014CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the sub_46AC38 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-27013CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the get_parentControl_list_Info function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-27012CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via the setSchedWifi function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.

  • CVE-2023-25220CriApr 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 was discovered to contain a stack overflow via the add_white_node function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.