VYPR

CVEs

31,788 total · page 277 of 636

  • CVE-2023-24734CriMar 6, 2023
    risk 0.65cvss 9.8epss 0.21

    An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbitrary code via a crafted image file.

  • CVE-2021-36394CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.07

    In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

  • CVE-2021-36393CriMar 6, 2023
    risk 0.68cvss 9.8epss 0.52

    In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.

  • CVE-2021-36392CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.

  • CVE-2023-24776CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php.

  • CVE-2023-0979CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData MedDataPACS allows SQL Injection. This issue affects MedDataPACS : before 2023-03-03.

  • CVE-2022-4328CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.04

    The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server

  • CVE-2023-0839CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Protection for Outbound Error Messages and Alert Signals vulnerability in ProMIS Process Co. InSCADA allows Account Footprinting. This issue affects inSCADA: before 20230115-1.

  • CVE-2023-22344CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and execute it. As a result of exploiting this vulnerability with CVE-2023-22335 and…

  • CVE-2023-22336CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a specially crafted file to an arbitrary directory. As a result of exploiting this vulnerability with CVE-2023-22335 and…

  • CVE-2023-26481CriMar 4, 2023
    risk 0.59cvss 9.1epss 0.00

    authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow link that is created by an admin (or sent via email by an admin) can be used to set the password for any arbitrary user. This attack is only possible if a recovery flow exists,…

  • CVE-2023-27290CriMar 3, 2023
    risk 0.63cvss 9.1epss 0.09

    Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: …

  • CVE-2023-26779CriMar 3, 2023
    risk 0.64cvss 9.8epss 0.01

    CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE).

  • CVE-2023-27574CriMar 3, 2023
    risk 0.00cvss 9.8epss 0.00

    ShadowsocksX-NG 1.10.0 signs with com.apple.security.get-task-allow entitlements because of CODE_SIGNING_INJECT_BASE_ENTITLEMENTS.

  • CVE-2022-46973CriMar 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Report v0.9.8.6 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability.

  • CVE-2023-24643CriMar 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateBlankTxtview.php.

  • CVE-2023-24642CriMar 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateTxtview.php.

  • CVE-2023-24641CriMar 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateview.php.

  • CVE-2023-20079CriMar 3, 2023
    risk 0.65cvss 9.8epss 0.10

    Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details…

  • CVE-2023-20078CriMar 3, 2023
    risk 0.65cvss 9.8epss 0.10

    Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details…

  • CVE-2022-45553CriMar 3, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary commands via serial connection to the UART port.

  • CVE-2022-45551CriMar 3, 2023
    risk 0.66cvss 9.8epss 0.23

    An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint.

  • CVE-2022-46501CriMar 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function.

  • CVE-2023-26475CriMar 2, 2023
    risk 0.63cvss 9.9epss 0.65

    XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by annotating the document. This has been…

  • CVE-2023-26474CriMar 2, 2023
    risk 0.64cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execute a text area property. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. There are no known workarounds.

  • CVE-2023-26472CriMar 2, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with the right of IconThemeSheet author by creating an icon theme with certain content. This can be done by creating a new page or even through the user profile for…

  • CVE-2023-26471CriMar 2, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in restricted mode (anything dangerous is disabled), but the async macro does not take into account the restricted mode. This means…

  • CVE-2023-26055CriMar 2, 2023
    risk 0.64cvss 9.9epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-milestone-1, any user can edit their own profile and inject code, which is going to be executed with programming right. The same vulnerability can also be exploited in…

  • CVE-2023-26477CriMar 2, 2023
    risk 0.64cvss 10.0epss 0.75

    XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the `newThemeName` request parameter (URL parameter), in combination with additional…

  • CVE-2023-26780CriMar 2, 2023
    risk 0.64cvss 9.8epss 0.01

    CleverStupidDog yf-exam v 1.8.0 is vulnerable to SQL Injection.

  • CVE-2021-3854CriMar 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Useroam Hotspot allows SQL Injection. This issue affects Useroam Hotspot: before 5.1.0.15.

  • CVE-2023-1097CriMar 1, 2023
    risk 0.61cvss 9.3epss 0.01

    Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP GET command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods have been tested and validated…

  • CVE-2023-23315CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initContent()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a…

  • CVE-2023-1114CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization vulnerability in Eskom e-Belediye allows Information Elicitation. This issue affects e-Belediye: from 1.0.0.95 before 1.0.0.100.

  • CVE-2023-1064CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighbridge Automation Software allows SQL Injection. This issue affects Weighbridge Automation Software: before 1.1.

  • CVE-2023-22752CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-22751CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-22750CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.02

    There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-22749CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.02

    There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-22748CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.02

    There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-22747CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.02

    There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-20032CriMar 1, 2023
    risk 0.66cvss 9.8epss 0.29

    On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to…

  • CVE-2022-37938CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated server side request forgery in HPE Serviceguard Manager

  • CVE-2022-37937CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Pre-auth memory corruption in HPE Serviceguard

  • CVE-2022-37936CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Java deserialization vulnerability in Serviceguard Manager

  • CVE-2023-27372CriFeb 28, 2023
    risk 0.75cvss 9.8epss 1.00

    SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.

  • CVE-2023-20946CriFeb 28, 2023
    risk 0.64cvss 9.8epss 0.00

    In onStart of BluetoothSwitchPreferenceController.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-0511CriFeb 28, 2023
    risk 0.59cvss 9.1epss 0.01

    Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all versions up to 5.10.1

  • CVE-2023-0339CriFeb 28, 2023
    risk 0.59cvss 9.1epss 0.01

    Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Policy Agent: all versions up to 5.10.1

  • CVE-2023-24258CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.02

    SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request.