VYPR

CVEs

38,077 total · page 284 of 762

  • CVE-2024-9972CriOct 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

  • CVE-2024-48823CriOct 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the PassageAutoServer.php page.

  • CVE-2023-48082CriOct 14, 2024
    risk 0.59cvss 9.1epss 0.02

    Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate.

  • CVE-2024-48168CriOct 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code.

  • CVE-2024-46535CriOct 14, 2024
    risk 0.64cvss 9.8epss 0.00

    Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability via the orderSQL parameter at /homePortal/loadUserMsg.

  • CVE-2024-48153CriOct 14, 2024
    risk 0.64cvss 9.8epss 0.01

    DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subconfig function.

  • CVE-2024-48150CriOct 14, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.

  • CVE-2024-48257CriOct 14, 2024
    risk 0.00cvss 9.8epss 0.01

    Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.

  • CVE-2024-48251CriOct 14, 2024
    risk 0.00cvss 9.8epss 0.01

    Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.

  • CVE-2024-48255CriOct 14, 2024
    risk 0.64cvss 9.8epss 0.00

    Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.

  • CVE-2024-48253CriOct 14, 2024
    risk 0.64cvss 9.8epss 0.00

    Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.

  • CVE-2024-9137CriOct 14, 2024
    risk 0.61cvss 9.4epss 0.01

    The affected product lacks an authentication check when sending commands to the server via the Moxa service. This vulnerability allows an attacker to execute specified commands, potentially leading to unauthorized downloads or uploads of configuration files and system compromise.

  • CVE-2024-9924CriOct 14, 2024
    risk 0.64cvss 9.8epss 0.01

    The fix for CVE-2024-26261 was incomplete, and and the specific package for OAKlouds from Hgiga remains at risk. Unauthenticated remote attackers still can download arbitrary system files, which may be deleted subsequently .

  • CVE-2024-9921CriOct 14, 2024
    risk 0.64cvss 9.8epss 0.01

    The Team+ from TEAMPLUS TECHNOLOGY does not properly validate specific page parameter, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify and delete database contents.

  • CVE-2024-7099CriOct 13, 2024
    risk 0.00cvss 9.8epss 0.01

    netease-youdao/qanything version 1.4.1 contains a vulnerability where unsafe data obtained from user input is concatenated in SQL queries, leading to SQL injection. The affected functions include `get_knowledge_base_name`, `from_status_to_status`, `delete_files`, and…

  • CVE-2024-9047CriOct 12, 2024
    risk 0.71cvss 9.8epss 0.93

    The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory.…

  • CVE-2024-48772CriOct 11, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48787CriOct 11, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue in Revic Optics Revic Ops (us.revic.revicops) 1.12.5 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48786CriOct 11, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue in SWITCHBOT INC SwitchBot (com.theswitchbot.switchbot) 5.0.4 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48784CriOct 11, 2024
    risk 0.64cvss 9.8epss 0.01

    An Incorrect Access Control issue in SAMPMAX com.sampmax.homemax 2.1.2.7 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48778CriOct 11, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue in GIANT MANUFACTURING CO., LTD RideLink (tw.giant.ridelink) 2.0.7 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48769CriOct 11, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue in BURG-WCHTER KG de.burgwachter.keyapp.app 4.5.0 allows a remote attacker to obtain sensitve information via the firmware update process.

  • CVE-2024-48033CriOct 11, 2024
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in baptiste.gourdin Talkback talkback-secure-linkback-protocol allows Object Injection.This issue affects Talkback: from n/a through <= 1.0.

  • CVE-2024-47331CriOct 11, 2024
    risk 0.60cvss 9.3epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ninja Team Multi Step for Contact Form cf7-multi-step allows SQL Injection.This issue affects Multi Step for Contact Form: from n/a through <= 2.7.7.

  • CVE-2024-46532CriOct 11, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in OpenHIS v.1.0 allows an attacker to execute arbitrary code via the refund function in the PayController.class.php component.

  • CVE-2024-46088CriOct 11, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the ProductAction.entphone interface of Zhejiang University Entersoft Customer Resource Management System v2002 to v2024 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-44730CriOct 11, 2024
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name.

  • CVE-2024-42640CriOct 11, 2024
    risk 0.70cvss 9.8epss 0.40

    angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to the server, which can subsequently be accessed through demo/uploads. This leads to…

  • CVE-2024-47875CriOct 11, 2024
    risk 0.58cvss 10.0epss 0.01

    DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.

  • CVE-2024-47830CriOct 11, 2024
    risk 0.00cvss 9.3epss 0.01

    Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js. This may permit an attacker to induce the server side into performing requests to unintended locations. This vulnerability is…

  • CVE-2024-47074CriOct 11, 2024
    risk 0.00cvss 9.8epss 0.01

    DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source function can customize the JDBC connection parameters and the PG server target to be connected. In backend/src/main/java/io/dataease/provider/datasource/JdbcPro…

  • CVE-2024-9707CriOct 11, 2024
    risk 0.64cvss 9.8epss 0.09

    The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated…

  • CVE-2024-9234CriOct 11, 2024
    risk 0.65cvss 9.8epss 0.10

    The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function (install-active-plugin REST API…

  • CVE-2024-9164CriOct 11, 2024
    risk 0.62cvss 9.6epss 0.01

    An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.

  • CVE-2024-21534CriOct 11, 2024
    risk 0.57cvss 9.8epss 0.09

    All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix…

  • CVE-2024-9822CriOct 11, 2024
    risk 0.64cvss 9.8epss 0.01

    The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5. This is due to insufficient restriction on the 'login_admin_user' function. This makes it possible for unauthenticated attackers to log to the first user,…

  • CVE-2024-47871CriOct 10, 2024
    risk 0.59cvss 9.1epss 0.00

    Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves **insecure communication** between the FRP (Fast Reverse Proxy) client and server when Gradio's `share=True` option is used. HTTPS is not enforced on the connection, allowing…

  • CVE-2024-9487CriOct 10, 2024
    risk 0.61cvss 9.1epss 0.26

    An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed resulting in unauthorized provisioning of users and access to the instance. Exploitation required the encrypted…

  • CVE-2024-47167CriOct 10, 2024
    risk 0.64cvss 9.8epss 0.00

    Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to **Server-Side Request Forgery (SSRF)** in the `/queue/join` endpoint. Gradio’s `async_save_url_to_cache` function allows attackers to force the Gradio server to send HTTP…

  • CVE-2024-47636CriOct 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in eyecix JobSearch wp-jobsearch allows Object Injection.This issue affects JobSearch: from n/a through <= 2.5.9.

  • CVE-2023-25581CriOct 10, 2024
    risk 0.53cvss —epss 0.02

    pac4j is a security framework for Java. `pac4j-core` prior to version 4.0.0 is affected by a Java deserialization vulnerability. The vulnerability affects systems that store externally controlled values in attributes of the `UserProfile` class from pac4j-core. It can be…

  • CVE-2024-9201CriOct 10, 2024
    risk 0.61cvss 9.4epss 0.00

    The SEUR plugin, in its versions prior to 2.5.11, is vulnerable to time-based SQL injection through the use of the ‘id_order’ parameter of the ‘/modules/seur/ajax/saveCodFee.php’ endpoint.

  • CVE-2024-45115CriOct 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain unauthorized access or elevated privileges within…

  • CVE-2024-9798CriOct 10, 2024
    risk 0.59cvss 9.0epss 0.00

    The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.

  • CVE-2024-9796CriOct 10, 2024
    risk 0.64cvss 9.8epss 0.03

    The WP-Advanced-Search WordPress plugin before 3.3.9.2 does not sanitize and escape the t parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks

  • CVE-2024-9518CriOct 10, 2024
    risk 0.64cvss 9.8epss 0.01

    The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restriction on the 'form_actions' and 'userplus_update_user_profile' functions. This makes it possible for unauthenticated attackers to specify their…

  • CVE-2024-48949CriOct 10, 2024
    risk 0.52cvss 9.1epss 0.01

    The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.

  • CVE-2024-47832CriOct 9, 2024
    risk 0.57cvss 9.8epss 0.00

    ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass attacks. An attacker can carry out signature bypass if you have access to certain IDP-signed messages. The underlying mechanism exploits differential behavior…

  • CVE-2024-9465CriKEVOct 9, 2024
    risk 0.79cvss 9.1epss 1.00

    An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary…

  • CVE-2024-45746CriOct 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Trusted Firmware-M through 2.1.0. User provided (and controlled) mailbox messages contain a pointer to a list of input arguments (in_vec) and output arguments (out_vec). These list pointers are never validated. Each argument list contains a buffer…