VYPR

CVEs

31,788 total · page 280 of 636

  • CVE-2022-43969CriFeb 16, 2023
    risk 0.59cvss 9.1epss 0.01

    Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.

  • CVE-2021-33925CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in nitinparashar30 cms-corephp through commit bdabe52ef282846823bda102728a35506d0ec8f9 (May 19, 2021) allows unauthenticated attackers to gain escilated privledges via a crafted login.

  • CVE-2021-33304CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pico_fragments_reassemble, allows attackers to execute arbitrary code.

  • CVE-2020-21120CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the cookie_cart parameter to /index.php/cart/num.

  • CVE-2020-21119CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Kliqqi-CMS 2.0.2 in admin/admin_update_module_widgets.php in recordIDValue parameter, allows attackers to gain escalated privileges and execute arbitrary code.

  • CVE-2020-19825CriFeb 15, 2023
    risk 0.00cvss 9.6epss 0.01

    Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.

  • CVE-2023-22855CriFeb 15, 2023
    risk 0.68cvss 9.8epss 0.15

    Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path is handed to a path-concatenation method (Path.Combine from .NET) without proper sanitisation. This yields the possibility of…

  • CVE-2023-23465CriFeb 15, 2023
    risk 0.59cvss 9.1epss 0.00

    Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint.

  • CVE-2023-23462CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Libpeconv – integer overflow, before commit 75b1565 (30/11/2022).

  • CVE-2023-23461CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Libpeconv – access violation, before commit b076013 (30/11/2022).

  • CVE-2023-23460CriFeb 15, 2023
    risk 0.59cvss 9.1epss 0.01

    Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass.

  • CVE-2023-23459CriFeb 15, 2023
    risk 0.59cvss 9.1epss 0.01

    Priority Windows may allow Command Execution via SQL Injection using an unspecified method.

  • CVE-2023-22807CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker could control and tamper with the PLC by sending the packets to the PLC over its XGT protocol.

  • CVE-2023-22804CriFeb 15, 2023
    risk 0.59cvss 9.1epss 0.01

    LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This could allow an attacker to create and use an account with elevated privileges and take control of the device.

  • CVE-2023-0102CriFeb 15, 2023
    risk 0.59cvss 9.1epss 0.01

    LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command. This could allow an attacker to delete arbitrary files.

  • CVE-2022-46892CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.

  • CVE-2023-25765CriFeb 15, 2023
    risk 0.57cvss 9.9epss 0.01

    In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the…

  • CVE-2023-21803CriFeb 14, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows iSCSI Discovery Service Remote Code Execution Vulnerability

  • CVE-2023-21716CriFeb 14, 2023
    risk 0.70cvss 9.8epss 0.82

    Microsoft Word Remote Code Execution Vulnerability

  • CVE-2023-21692CriFeb 14, 2023
    risk 0.65cvss 9.8epss 0.21

    Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

  • CVE-2023-21690CriFeb 14, 2023
    risk 0.66cvss 9.8epss 0.28

    Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

  • CVE-2023-21689CriFeb 14, 2023
    risk 0.66cvss 9.8epss 0.27

    Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

  • CVE-2023-25725CriFeb 14, 2023
    risk 0.60cvss 9.1epss 0.05

    HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers…

  • CVE-2023-24161CriFeb 14, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.

  • CVE-2023-24160CriFeb 14, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.

  • CVE-2023-24159CriFeb 14, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in the setPasswordCfg function.

  • CVE-2023-24482CriFeb 14, 2023
    risk 0.65cvss 10.0epss 0.01

    A vulnerability has been identified in COMOS V10.2 (All versions), COMOS V10.3.3.1 (All versions < V10.3.3.1.45), COMOS V10.3.3.2 (All versions < V10.3.3.2.33), COMOS V10.3.3.3 (All versions < V10.3.3.3.9), COMOS V10.3.3.4 (All versions < V10.3.3.4.6), COMOS V10.4.0.0 (All…

  • CVE-2022-47034CriFeb 13, 2023
    risk 0.00cvss 9.8epss 0.01

    A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.

  • CVE-2023-24646CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2023-24084CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function.

  • CVE-2023-25718CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signature, such as instructions that result in offering the end user a (different) attacker-controlled…

  • CVE-2023-25717CriKEVFeb 13, 2023
    risk 0.83cvss 9.8epss 0.98

    Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.

  • CVE-2023-24188CriFeb 13, 2023
    risk 0.59cvss 9.1epss 0.01

    ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.

  • CVE-2023-23551CriFeb 13, 2023
    risk 0.59cvss 9.1epss 0.01

    Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to remotely execute arbitrary code.

  • CVE-2022-4445CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

  • CVE-2022-40022CriFeb 13, 2023
    risk 0.74cvss 9.8epss 0.92

    Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.

  • CVE-2022-48323CriFeb 13, 2023
    risk 0.68cvss 9.8epss 0.57

    Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated attacker can execute arbitrary programs on the victim host by sending a crafted HTTP request, as demonstrated by /check?cmd=ping../…

  • CVE-2022-48322CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affects MR60 before 1.1.7.132, MS60 before 1.1.7.132, R6900P before 1.3.3.154, R7000P before 1.3.3.154, R7960P before 1.4.4.94, and R8000P before 1.4.4.94.

  • CVE-2022-4557CriFeb 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01.

  • CVE-2022-45088CriFeb 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows PHP Local File Inclusion. This issue affects Smartpower Web: before 23.01.01.

  • CVE-2022-40514CriFeb 12, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame.

  • CVE-2022-33279CriFeb 12, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption due to stack based buffer overflow in WLAN having invalid WNM frame length.

  • CVE-2022-33232CriFeb 12, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory.

  • CVE-2022-25729CriFeb 12, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in modem due to improper length check while copying into memory

  • CVE-2023-23163CriFeb 10, 2023
    risk 0.67cvss 9.8epss 0.04

    Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.

  • CVE-2023-23162CriFeb 10, 2023
    risk 0.67cvss 9.8epss 0.04

    Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.

  • CVE-2023-0777CriFeb 10, 2023
    risk 0.61cvss 9.8epss 0.15

    Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4.

  • CVE-2022-45766CriFeb 10, 2023
    risk 0.59cvss 9.1epss 0.01

    Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remote attackers to impact availability, confidentiality, accessibility and dependability of electronic key boxes.

  • CVE-2023-24352CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWPS.

  • CVE-2023-24351CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the FILECODE parameter at /goform/formLogin.