VYPR

CVEs

31,788 total · page 282 of 636

  • CVE-2021-36433CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.01

    SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_delete_mask function in jocms/apps/mask/mask.php.

  • CVE-2021-36431CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.01

    SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check() function in jocms/apps/mask/inc/mask.php.

  • CVE-2021-36424CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.

  • CVE-2023-24157CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2023-24156CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the ip parameter in the function recvSlaveUpgstatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2023-24155CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product.ini.

  • CVE-2023-24154CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK T8 V4.1.5cu was discovered to contain a command injection vulnerability via the slaveIpList parameter in the function setUpgradeFW.

  • CVE-2023-24153CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the version parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2023-24152CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the serverIp parameter in the function meshSlaveUpdate of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2023-24151CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2023-24150CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2023-24149CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow.

  • CVE-2023-24148CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadUserData function.

  • CVE-2023-24146CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the minute parameter in the setRebootScheCfg function.

  • CVE-2023-24145CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version parameter in the setUnloadUserData function.

  • CVE-2023-24144CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the setRebootScheCfg function.

  • CVE-2023-24143CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagTracertHop parameter in the setNetworkDiag function.

  • CVE-2023-24142CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize parameter in the setNetworkDiag function.

  • CVE-2023-24141CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingTimeOut parameter in the setNetworkDiag function.

  • CVE-2023-24140CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingNum parameter in the setNetworkDiag function.

  • CVE-2023-24139CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagHost parameter in the setNetworkDiag function.

  • CVE-2023-24138CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in the NTPSyncWithHost function.

  • CVE-2023-25139CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    sprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct buffer size. This is unrelated to CWE-676. It may write beyond the bounds of the destination buffer when attempting to write a padded, thousands-separated…

  • CVE-2023-25135CriFeb 3, 2023
    risk 0.66cvss 9.8epss 0.24

    vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling unserialize and then checking for errors.…

  • CVE-2022-48021CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.

  • CVE-2022-22486CriFeb 3, 2023
    risk 0.65cvss 10.0epss 0.01

    IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226328.

  • CVE-2022-48114CriFeb 2, 2023
    risk 0.64cvss 9.8epss 0.01

    RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.

  • CVE-2022-48113CriFeb 2, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials.

  • CVE-2022-48130CriFeb 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the parameters staticRouteNet, staticRouteMask, staticRouteGateway, staticRouteWAN.

  • CVE-2022-48082CriFeb 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Easyone CRM v5.50.02 was discovered to contain a SQL Injection vulnerability via the text parameter at /Services/Misc.asmx/SearchTag.

  • CVE-2022-48079CriFeb 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory of the system.

  • CVE-2023-23076CriFeb 1, 2023
    risk 0.70cvss 9.8epss 0.74

    OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.

  • CVE-2023-22501CriFeb 1, 2023
    risk 0.60cvss 9.1epss 0.16

    An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and…

  • CVE-2023-24997CriFeb 1, 2023
    risk 0.57cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7223…

  • CVE-2022-47714CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Last Yard 22.09.8-1 does not enforce HSTS headers

  • CVE-2022-47003CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.04

    A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.

  • CVE-2022-47002CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.06

    A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.

  • CVE-2022-42971CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Server 2016, 2019, 2022…

  • CVE-2022-42970CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7,…

  • CVE-2022-2329CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.02

    A CWE-190: Integer Overflow or Wraparound vulnerability exists that could cause heap-based buffer overflow, leading to denial of service and potentially remote code execution when an attacker sends multiple specially crafted messages. Affected Products: IGSS Data Server -…

  • CVE-2022-24324CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.01

    A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Products: IGSS Data Server - IGSSdataServer.exe…

  • CVE-2023-0587CriFeb 1, 2023
    risk 0.64cvss 9.1epss 0.60

    A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload arbitrary files to the…

  • CVE-2022-47770CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticated SQL Injection.

  • CVE-2022-47769CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the web root of the application to gain access to the server via the web shell.

  • CVE-2023-24241CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Forget Heart Message Box v1.1 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/loginpost.php.

  • CVE-2023-23924CriFeb 1, 2023
    risk 0.58cvss 10.0epss 0.04

    Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP < 8, through the `phar` URL wrapper. An attacker can exploit the…

  • CVE-2022-47873CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).

  • CVE-2022-45297CriJan 31, 2023
    risk 0.67cvss 9.8epss 0.03

    EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.

  • CVE-2022-47854CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    i-librarian 4.10 is vulnerable to Arbitrary file upload in ajaxsupplement.php.

  • CVE-2022-47699CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Incorrect Access Control.