VYPR

CVEs

31,788 total · page 273 of 636

  • CVE-2023-27886CriMar 28, 2023
    risk 0.64cvss 9.8epss 0.02

    Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP POST parameter called by index.php script.

  • CVE-2023-27394CriMar 28, 2023
    risk 0.65cvss 9.8epss 0.18

    Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.php and AlarmsView.php scripts.

  • CVE-2022-46387CriMar 28, 2023
    risk 0.64cvss 9.8epss 0.01

    ConEmu through 220807 and Cmder before 1.3.21 report the title of the terminal, including control characters, which allows an attacker to change the title and then execute it as commands.

  • CVE-2022-24673CriMar 28, 2023
    risk 0.64cvss 9.8epss 0.03

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Canon imageCLASS MF644Cdw 10.02 printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the SLP protocol. The…

  • CVE-2022-23125CriMar 28, 2023
    risk 0.57cvss 9.8epss 0.04

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyapplfile function. When parsing the len element, the process does not…

  • CVE-2022-23124CriMar 28, 2023
    risk 0.57cvss 9.8epss 0.03

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_finderinfo method. The issue results from the lack of proper…

  • CVE-2022-23123CriMar 28, 2023
    risk 0.57cvss 9.8epss 0.04

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getdirparams method. The issue results from the lack of proper…

  • CVE-2022-23122CriMar 28, 2023
    risk 0.57cvss 9.8epss 0.04

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setfilparams function. The issue results from the lack of proper…

  • CVE-2022-23121CriMar 28, 2023
    risk 0.57cvss 9.8epss 0.09

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries function. The issue results from the lack of proper error…

  • CVE-2022-0194CriMar 28, 2023
    risk 0.57cvss 9.8epss 0.04

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment function. The issue results from the lack of proper…

  • CVE-2023-27821CriMar 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Databasir v1.0.7 was discovered to contain a remote code execution (RCE) vulnerability via the mockDataScript parameter.

  • CVE-2023-28326CriMar 28, 2023
    risk 0.57cvss 9.8epss 0.01

    Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room

  • CVE-2022-3682CriMar 28, 2023
    risk 0.64cvss 9.9epss 0.01

    A vulnerability exists in the SDM600 file permission validation. An attacker could exploit the vulnerability by gaining access to the system and uploading a specially crafted message to the system node, which could result in Arbitrary code Executing. This issue affects: All…

  • CVE-2023-1665CriMar 27, 2023
    risk 0.00cvss 9.8epss 0.01

    Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 0.0.0.

  • CVE-2022-48353CriMar 27, 2023
    risk 0.64cvss 9.8epss 0.00

    Some smartphones have configuration issues. Successful exploitation of this vulnerability may cause kernel privilege escalation, which results in system service exceptions.

  • CVE-2022-48349CriMar 27, 2023
    risk 0.59cvss 9.1epss 0.00

    The control component has a spoofing vulnerability. Successful exploitation of this vulnerability may affect confidentiality and availability.

  • CVE-2022-48348CriMar 27, 2023
    risk 0.59cvss 9.1epss 0.00

    The MediaProvider module has a vulnerability of unauthorized data read. Successful exploitation of this vulnerability may affect confidentiality and integrity.

  • CVE-2023-25261CriMar 27, 2023
    risk 0.64cvss 9.8epss 0.02

    Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the local file system is not prohibited in any way. Therefore, an…

  • CVE-2022-46416CriMar 27, 2023
    risk 0.59cvss 9.1epss 0.01

    Parrot Bebop 4.7.1. allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool. To accomplish this, the attacker would first need to connect to the device's internal Wi-Fi network (e.g., by guessing the password). Then, the attacker…

  • CVE-2022-46415CriMar 27, 2023
    risk 0.59cvss 9.1epss 0.01

    DJI Spark 01.00.0900 allows remote attackers to prevent legitimate terminal connections by exhausting the DHCP IP address pool. To accomplish this, the attacker would first need to connect to the device's internal Wi-Fi network (e.g., by guessing the password). Then, the…

  • CVE-2023-27847CriMar 27, 2023
    risk 0.64cvss 9.8epss 0.05

    SQL injection vulnerability found in PrestaShop xipblog v.2.0.1 and before allow a remote attacker to gain privileges via the xipcategoryclass and xippostsclass components.

  • CVE-2023-1140CriMar 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability that could allow an attacker to achieve unauthenticated remote code execution in the context of an administrator.

  • CVE-2023-1136CriMar 27, 2023
    risk 0.64cvss 9.8epss 0.01

    In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated attacker could generate a valid token, which would lead to authentication bypass.

  • CVE-2023-1133CriMar 27, 2023
    risk 0.71cvss 9.8epss 0.50

    Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contain a vulnerability in which the Device-status service listens on port 10100/ UDP by default. The service accepts the unverified UDP packets and deserializes the content, which could allow an unauthenticated…

  • CVE-2023-26959CriMar 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Phpgurukul Park Ticketing Management System 1.0 is vulnerable to SQL Injection via the User Name parameter.

  • CVE-2022-4126CriMar 27, 2023
    risk 0.62cvss 9.6epss 0.01

    Use of Default Password vulnerability in ABB RCCMD on Windows, Linux, MacOS allows Try Common or Default Usernames and Passwords.This issue affects RCCMD: before 4.40 230207.

  • CVE-2023-25909CriMar 27, 2023
    risk 0.64cvss 9.8epss 0.01

    HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary command or disrupt service.

  • CVE-2023-24838CriMar 27, 2023
    risk 0.64cvss 9.8epss 0.01

    HGiga PowerStation has a vulnerability of Information Leakage. An unauthenticated remote attacker can exploit this vulnerability to obtain the administrator's credential. This credential can then be used to login PowerStation or Secure Shell to achieve remote code execution.

  • CVE-2023-28883CriMar 27, 2023
    risk 0.00cvss 9.8epss 0.01

    In Cerebrate 1.13, a blind SQL injection exists in the searchAll API endpoint.

  • CVE-2018-25083CriMar 27, 2023
    risk 0.57cvss 9.8epss 0.03

    The pullit package before 1.4.0 for Node.js allows OS Command Injection because eval is used on an attacker-supplied Git branch name.

  • CVE-2023-26802CriMar 26, 2023
    risk 0.68cvss 9.8epss 0.49

    An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication and execute arbitrary commands via a crafted request.

  • CVE-2023-26801CriMar 26, 2023
    risk 0.69cvss 9.8epss 0.70

    LB-LINK BL-AC1900_2.0 v1.0.1, LB-LINK BL-WR9000 v2.4.9, LB-LINK BL-X26 v1.2.5, and LB-LINK BL-LTE300 v1.0.8 were discovered to contain a command injection vulnerability via the mac, time1, and time2 parameters at /goform/set_LimitClient_cfg.

  • CVE-2023-26800CriMar 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Ruijie Networks RG-EW1200 Wireless Routers EW_3.0(1)B11P204 was discovered to contain a command injetion vulnerability via the params.path parameter in the upgradeConfirm function.

  • CVE-2023-28437CriMar 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Dataease is an open source data visualization and analysis tool. The blacklist for SQL injection protection is missing entries. This vulnerability has been fixed in version 1.18.5. There are no known workarounds.

  • CVE-2023-25668CriMar 25, 2023
    risk 0.57cvss 9.8epss 0.01

    TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be included in TensorFlow version 2.12.0 and…

  • CVE-2023-23149CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.01

    DEK-1705 <=Firmware:34.23.1 device was discovered to have a command execution vulnerability.

  • CVE-2022-45597CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.00

    ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport layer) and "Certificates are exchanged in a controlled fashion…

  • CVE-2023-26864CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop smplredirectionsmanager v.1.1.19 and before allow a remote attacker to gain privileges via the SmplTools::getMatchingRedirectionsFromPartscomponent.

  • CVE-2023-28444CriMar 24, 2023
    risk 0.57cvss 9.9epss 0.01

    angular-server-side-configuration helps configure an angular application at runtime on the server or in a docker container via environment variables. angular-server-side-configuration detects used environment variables in TypeScript (.ts) files during build time of an Angular…

  • CVE-2023-21058CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.00

    In lcsm_SendRrAcquiAssist of lcsm_bcm_assist.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21057CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.00

    In ProfSixDecomTcpSACKoption of RohcPacketCommon, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-20954CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.00

    In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-20951CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.00

    In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-42499CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In sms_SendMmCpErrMsg of sms_MmConManagement.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-42498CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.00

    In Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2022-20532CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.00

    In parseTrackFragmentRun() of MPEG4Extractor.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-1177CriMar 24, 2023
    risk 0.59cvss 9.3epss 0.69

    Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.

  • CVE-2022-42948CriKEVMar 24, 2023
    risk 0.76cvss 9.8epss 0.03

    Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

  • CVE-2022-28495CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2023-28445CriMar 24, 2023
    risk 0.57cvss 9.9epss 0.01

    Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are shrunk during the asynchronous operation could result in an out-of-bound read/write. It is unlikely that this has been exploited in…