VYPR

CVEs

38,073 total · page 273 of 762

  • CVE-2024-10961CriNov 23, 2024
    risk 0.57cvss 9.8epss 0.01

    The Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.9.0. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in…

  • CVE-2024-0138CriNov 23, 2024
    risk 0.64cvss 9.8epss 0.01

    NVIDIA Base Command Manager contains a missing authentication vulnerability in the CMDaemon component. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

  • CVE-2024-52034CriNov 22, 2024
    risk 0.65cvss 10.0epss 0.02

    An OS Command Injection vulnerability exists within myPRO Manager. A parameter within a command can be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.

  • CVE-2024-47407CriNov 22, 2024
    risk 0.73cvss 10.0epss 0.64

    A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.

  • CVE-2024-47138CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed.

  • CVE-2024-8807CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.02

    Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cohesive Networks VNS3. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2024-8806CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.02

    Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cohesive Networks VNS3. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2024-5716CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.02

    Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this vulnerability. The specific flaw…

  • CVE-2023-51639CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.02

    Allegra downloadExportedChart Directory Traversal Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The specific flaw…

  • CVE-2023-51638CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    Allegra Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2024-37782CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field.

  • CVE-2024-53438CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into the SQL query without proper sanitization or validation, allowing attackers to execute…

  • CVE-2024-52723CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.

  • CVE-2024-48862CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. We have already fixed the…

  • CVE-2024-48860CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.3.103 and later

  • CVE-2024-38643CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain access to and execute certain functions. We have already fixed the vulnerability in the following…

  • CVE-2024-41779CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. By sending a specially crafted request, an attacker could exploit this vulnerability to remotely execute code.

  • CVE-2024-8932CriNov 22, 2024
    risk 0.64cvss 9.8epss 0.01

    In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.

  • CVE-2024-52053CriNov 21, 2024
    risk 0.62cvss 9.6epss 0.01

    Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated attacker to inject client-side JavaScript into the web dashboard to automatically hijack admin accounts.

  • CVE-2024-51367CriNov 21, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attackers to execute arbitrary code via uploading a crafted .xml file.

  • CVE-2024-51366CriNov 21, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component \Roaming\Omega of OmegaT v6.0.1 allows attackers to execute arbitrary code via uploading a crafted .conf file.

  • CVE-2024-53095CriNov 21, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free of network namespace. Recently, we got a customer report that CIFS triggers oops while reconnecting to a server. [0] The workload runs on Kubernetes, and some pods mount CIFS…

  • CVE-2024-53094CriNov 21, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES While running ISER over SIW, the initiator machine encounters a warning from skb_splice_from_iter() indicating that a slab page is being used in…

  • CVE-2024-52289CriNov 21, 2024
    risk 0.00cvss 9.8epss 0.01

    authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx comparison. When no Redirect URIs are configured in a provider, authentik will automatically use the first redirect_uri value received as an allowed redirect…

  • CVE-2024-8525CriNov 21, 2024
    risk 0.65cvss —epss 0.01

    An unrestricted upload of file with dangerous type in Automated Logic WebCTRL 7.0 could allow an unauthenticated user to perform remote command execution via a crafted HTTP POST request which could lead to uploading a malicious file.

  • CVE-2024-29224CriNov 21, 2024
    risk 0.64cvss 9.8epss 0.06

    An OS command injection vulnerability exists in the NAT parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

  • CVE-2024-28892CriNov 21, 2024
    risk 0.64cvss 9.8epss 0.06

    An OS command injection vulnerability exists in the name parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

  • CVE-2024-21855CriNov 21, 2024
    risk 0.64cvss 9.8epss 0.02

    A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

  • CVE-2024-30896CriNov 21, 2024
    risk 0.56cvss 9.1epss 0.05

    InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud,…

  • CVE-2024-11320CriNov 21, 2024
    risk 0.74cvss 9.8epss 0.91

    Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4

  • CVE-2024-51151CriNov 21, 2024
    risk 0.66cvss 9.8epss 0.31

    D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter and cmd parameter.

  • CVE-2024-52765CriNov 20, 2024
    risk 0.65cvss 9.8epss 0.12

    H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.

  • CVE-2024-52677CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.01

    HkCms <= v2.3.2.240702 is vulnerable to file upload in the getFileName method in /app/common/library/Upload.php.

  • CVE-2024-48984CriNov 20, 2024
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in MBed OS 6.16.0. When parsing hci reports, the hci parsing software dynamically determines the length of a list of reports by reading a byte from an input stream. It then fetches the length of the first report, uses it to calculate the beginning of the…

  • CVE-2024-33439CriNov 20, 2024
    risk 0.59cvss 9.1epss 0.01

    An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary OS commands via cgi parameters.

  • CVE-2024-29292CriNov 20, 2024
    risk 0.59cvss 9.1epss 0.01

    Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to execute arbitrary OS commands via various cgi parameters.

  • CVE-2018-9479CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.00

    In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed.  User interaction is not needed for…

  • CVE-2018-9478CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.00

    In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed.  User interaction is not needed for…

  • CVE-2024-52771CriNov 20, 2024
    risk 0.59cvss 9.1epss 0.01

    DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.

  • CVE-2024-52770CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-10094CriNov 20, 2024
    risk 0.59cvss 9.1epss 0.00

    Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code

  • CVE-2024-9479CriNov 20, 2024
    risk 0.65cvss —epss 0.00

    Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.

  • CVE-2024-9478CriNov 20, 2024
    risk 0.65cvss —epss 0.00

    Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue affects upKeeper Instant Privilege Access: before 1.2.

  • CVE-2024-52443CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in masikonis Geolocator geolocator allows Object Injection.This issue affects Geolocator: from n/a through <= 1.1.

  • CVE-2024-52442CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect Privilege Assignment vulnerability in userplus UserPlus userplus allows Privilege Escalation.This issue affects UserPlus: from n/a through <= 2.0.

  • CVE-2024-52441CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Rajesh Thanoch Quick Learn quick-learn allows Object Injection.This issue affects Quick Learn: from n/a through <= 1.0.1.

  • CVE-2024-52440CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in xpresslane Xpresslane Fast Checkout xpresslane-integration-for-woocommerce allows Object Injection.This issue affects Xpresslane Fast Checkout: from n/a through <= 1.0.0.

  • CVE-2024-52439CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Mark O'Donnell Team Rosters team-rosters allows Object Injection.This issue affects Team Rosters: from n/a through <= 4.8.2.

  • CVE-2024-10127CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.

  • CVE-2018-9467CriNov 20, 2024
    risk 0.64cvss 9.8epss 0.00

    In the getHost() function of UriTest.java, there is the possibility of incorrect web origin determination. This could lead to incorrect security decisions with no additional execution privileges needed. User interaction is not needed for exploitation.