VYPR

CVEs

31,788 total · page 281 of 636

  • CVE-2023-24350CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail.

  • CVE-2023-24349CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute.

  • CVE-2023-24348CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetACLFilter.

  • CVE-2022-43501CriFeb 10, 2023
    risk 0.59cvss 9.1epss 0.01

    KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP connections from an insufficiently random source. An attacker may be able to determine the ISN of the current or future TCP connections and either hijack existing ones or spoof future…

  • CVE-2022-45699CriFeb 10, 2023
    risk 0.70cvss 9.8epss 0.77

    Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.

  • CVE-2022-43550CriFeb 9, 2023
    risk 0.00cvss 9.8epss 0.02

    A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which could allow an attacker to insert an arbitrary URL which opens up the opportunity to remote execution.

  • CVE-2022-48290CriFeb 9, 2023
    risk 0.59cvss 9.1epss 0.00

    The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality and integrity.

  • CVE-2023-25168CriFeb 9, 2023
    risk 0.55cvss 9.6epss 0.01

    Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively on the host system. This vulnerability can be combined with `GHSA-p8r3-83r8-jwj5` to overwrite files on the host system. In order to use this exploit, an…

  • CVE-2022-45982CriFeb 8, 2023
    risk 0.64cvss 9.8epss 0.01

    thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

  • CVE-2022-45527CriFeb 8, 2023
    risk 0.64cvss 9.8epss 0.01

    File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory.

  • CVE-2022-45526CriFeb 8, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_transfer.php.

  • CVE-2022-43764CriFeb 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code.

  • CVE-2022-43761CriFeb 8, 2023
    risk 0.61cvss 9.4epss 0.01

    Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration. 

  • CVE-2023-0744CriFeb 8, 2023
    risk 0.60cvss 9.8epss 0.06

    Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.

  • CVE-2023-0743CriFeb 8, 2023
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4.

  • CVE-2023-0742CriFeb 8, 2023
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

  • CVE-2023-0741CriFeb 8, 2023
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.

  • CVE-2023-0740CriFeb 8, 2023
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

  • CVE-2021-36471CriFeb 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Directory Traversal vulnerability in AdminLTE 3.1.0 allows remote attackers to gain escalated privilege and view sensitive information via /admin/index2.html, /admin/index3.html URIs. Note: AdminLTE developers dispute that this a weakness with AdminLTE and is instead a…

  • CVE-2023-24813CriFeb 7, 2023
    risk 0.58cvss 10.0epss 0.02

    Dompdf is an HTML to PDF converter written in php. Due to the difference in the attribute parser of Dompdf and php-svg-lib, an attacker can still call arbitrary URLs with arbitrary protocols. Dompdf parses the href attribute of `image` tags and respects `xlink:href` even if…

  • CVE-2022-43757CriFeb 7, 2023
    risk 0.64cvss 9.9epss 0.01

    A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials exposed This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to…

  • CVE-2022-3229CriFeb 6, 2023
    risk 0.08cvss 9.8epss 0.66

    Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated…

  • CVE-2023-23333CriFeb 6, 2023
    risk 0.75cvss 9.8epss 0.99

    There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.

  • CVE-2021-31578CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    In Boa, there is a possible escalation of privilege due to a stack buffer overflow. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210008;…

  • CVE-2021-31577CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    In Boa, there is a possible escalation of privilege due to a missing permission check. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210008;…

  • CVE-2021-31575CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.02

    In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2021-31574CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.02

    In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2021-31573CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.02

    In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2022-48311CriFeb 6, 2023
    risk 0.59cvss 9.0epss 0.01

    **UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Model Number A9U23B allows authenticated attacker to inject their own script into the page via HTTP configuration page. NOTE: This vulnerability…

  • CVE-2022-4681CriFeb 6, 2023
    risk 0.67cvss 9.8epss 0.04

    The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

  • CVE-2022-47071CriFeb 6, 2023
    risk 0.66cvss 9.8epss 0.26

    In NVS365 V01, the background network test function can trigger command execution.

  • CVE-2022-48078CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component ASTree.cpp:BuildFromCode.

  • CVE-2023-24276CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules.

  • CVE-2023-24202CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.

  • CVE-2023-24201CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php.

  • CVE-2023-24200CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php.

  • CVE-2023-24199CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.

  • CVE-2023-24198CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters.

  • CVE-2021-36226CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.

  • CVE-2021-36224CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Western Digital My Cloud devices before OS5 have a nobody account with a blank password.

  • CVE-2022-31733CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.00

    Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. If mTLS route integrity is enabled AND unproxied ports are…

  • CVE-2023-23088CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer OverFlow Vulnerability in Barenboim json-parser master and v1.1.0 fixed in v1.1.1 allows an attacker to execute arbitrary code via the json_value_parse function.

  • CVE-2023-23087CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was found in MojoJson v1.2.3 allows attackers to execute arbitary code via the destroy function.

  • CVE-2023-23086CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function.

  • CVE-2021-37497CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.

  • CVE-2021-37317CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.02

    Directory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the target for COPY and MOVE operations.

  • CVE-2021-37315CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.01

    Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.

  • CVE-2021-36503CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in native-php-cms 1.0 allows remote attackers to run arbitrary SQL commands via the cat parameter to /list.php file.

  • CVE-2021-36484CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page.

  • CVE-2021-36434CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.01

    SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check function in jocms/apps/mask/inc/getmask.php.