VYPR

CVEs

31,788 total · page 278 of 636

  • CVE-2023-23513CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.02

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey 12.6.3. Mounting a maliciously crafted Samba network share may lead to arbitrary code execution.

  • CVE-2022-46723CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A remote user may be able to write arbitrary files.

  • CVE-2022-26760CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. A malicious application may be able to elevate privileges.

  • CVE-2023-24253CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Domotica Labs srl Ikon Server before v2.8.6 was discovered to contain a SQL injection vulnerability.

  • CVE-2022-48284CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.00

    A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.

  • CVE-2022-48283CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.00

    A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.

  • CVE-2022-48259CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could allow attackers to gain higher privileges.

  • CVE-2022-48255CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution.

  • CVE-2023-25234CriFeb 27, 2023
    risk 0.65cvss 9.8epss 0.17

    Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface.

  • CVE-2023-25233CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.

  • CVE-2023-25231CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.

  • CVE-2023-23156CriFeb 27, 2023
    risk 0.67cvss 9.8epss 0.04

    Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.

  • CVE-2023-23155CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the username parameter in the Admin Login.

  • CVE-2022-45140CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.

  • CVE-2022-45138CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full…

  • CVE-2023-23080CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.02

    Certain Tenda products are vulnerable to command injection. This affects Tenda CP7 Tenda CP7<=V11.10.00.2211041403 and Tenda CP3 v.10 Tenda CP3 v.10<=V20220906024_2025 and Tenda IT7-PCS Tenda IT7-PCS<=V2209020914 and Tenda IT7-LCS Tenda IT7-LCS<=V2209020914 and Tenda IT7-PRS…

  • CVE-2023-24206CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Davinci v0.3.0-rc was discovered to contain a SQL injection vulnerability via the copyDisplay function.

  • CVE-2023-26602CriFeb 26, 2023
    risk 0.68cvss 9.8epss 0.17

    ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution.

  • CVE-2021-3329CriFeb 26, 2023
    risk 0.62cvss 9.6epss 0.01

    Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack

  • CVE-2023-26550CriFeb 25, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field.

  • CVE-2022-2024CriFeb 25, 2023
    risk 0.01cvss 9.8epss 0.98

    OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.

  • CVE-2023-26034CriFeb 25, 2023
    risk 0.63cvss 9.6epss 0.02

    ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are affected by a SQL Injection vulnerability. The (blind) SQL Injection vulnerability is present within…

  • CVE-2023-24189CriFeb 24, 2023
    risk 0.64cvss 9.8epss 0.01

    An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile.

  • CVE-2021-35370CriFeb 24, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.

  • CVE-2021-33387CriFeb 24, 2023
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.

  • CVE-2021-33224CriFeb 24, 2023
    risk 0.64cvss 9.8epss 0.01

    File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.

  • CVE-2023-25696CriFeb 24, 2023
    risk 0.57cvss 9.8epss 0.02

    Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3.

  • CVE-2023-25693CriFeb 24, 2023
    risk 0.57cvss 9.8epss 0.02

    Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1.

  • CVE-2023-25691CriFeb 24, 2023
    risk 0.57cvss 9.8epss 0.02

    Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.

  • CVE-2021-4105CriFeb 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Handling of Parameters vulnerability in BG-TEK COSLAT Firewall allows Remote Code Inclusion. This issue affects COSLAT Firewall: from 5.24.0.R.20180630 before 5.24.0.R.20210727.

  • CVE-2023-26468CriFeb 24, 2023
    risk 0.00cvss 9.1epss 0.01

    Cerebrate 1.12 does not properly consider organisation_id during creation of API keys.

  • CVE-2023-24212CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.

  • CVE-2023-24205CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml).

  • CVE-2023-0755CriFeb 23, 2023
    risk 0.65cvss 9.8epss 0.12

    The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.

  • CVE-2023-0754CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.03

    The affected products are vulnerable to an integer overflow or wraparound, which could  allow an attacker to crash the server and remotely execute arbitrary code.

  • CVE-2022-36231CriFeb 23, 2023
    risk 0.57cvss 9.8epss 0.03

    pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.

  • CVE-2023-26326CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.04

    The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects…

  • CVE-2023-23914CriFeb 23, 2023
    risk 0.59cvss 9.1epss 0.01

    A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP…

  • CVE-2023-24104CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.

  • CVE-2022-2504CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Software SDD-Baro allows SQL Injection. This issue affects SDD-Baro: before 2.8.432.

  • CVE-2023-0939CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NTN Information Technologies Online Services Software allows SQL Injection. This issue affects Online Services Software: before 1.17.

  • CVE-2022-48149CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

  • CVE-2022-45599CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gain escalated privileges only when specific conditions regarding a given accounts hashed password.

  • CVE-2022-39983CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attackers to execute arbitrary code.

  • CVE-2023-24114CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.

  • CVE-2023-0104CriFeb 22, 2023
    risk 0.62cvss 9.3epss 0.22

    The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data.  

  • CVE-2023-24093CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    An access control issue in H3C A210-G A210-GV100R005 allows attackers to authenticate without a password.

  • CVE-2023-25813CriFeb 22, 2023
    risk 0.58cvss 10.0epss 0.01

    Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Parameters which are passed through replacements are not properly escaped which can lead to arbitrary SQL injection depending on the specific queries in use. The…

  • CVE-2022-41217CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage.

  • CVE-2023-24108CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.