VYPR

CVEs

38,082 total · page 286 of 762

  • CVE-2024-24117CriOct 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.

  • CVE-2024-9441CriOct 2, 2024
    risk 0.68cvss 9.8epss 0.53

    The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP.

  • CVE-2024-24116CriOct 2, 2024
    risk 0.66cvss 9.8epss 0.28

    An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.

  • CVE-2024-20432CriOct 2, 2024
    risk 0.64cvss 9.9epss 0.01

    A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. This vulnerability is due to improper user…

  • CVE-2024-6360CriOct 2, 2024
    risk 0.64cvss 9.8epss 0.00

    Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized access or privileges to Vertica agent apikey. This issue affects Vertica: from 10.0 through 10.X, from 11.0 through 11.X, from 12.0…

  • CVE-2024-44097CriOct 2, 2024
    risk 0.64cvss 9.8epss 0.00

    According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing the TLS connection. This allows for a network attacker to intercept the connection…

  • CVE-2024-35293CriOct 2, 2024
    risk 0.59cvss 9.1epss 0.01

    An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resulting in data loss and/or a DoS.

  • CVE-2024-45186CriOct 2, 2024
    risk 0.64cvss 9.8epss 0.01

    FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.

  • CVE-2024-45999CriOct 1, 2024
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php. The vulnerability is exploitable via the station_id parameter.

  • CVE-2024-47608CriOct 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Logicytics is designed to harvest and collect data for forensic analysis. Logicytics has a basic vuln affecting compromised devices from shell injections. This vulnerability is fixed in 2.3.2.

  • CVE-2024-9402CriOct 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox <…

  • CVE-2024-9401CriOct 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This…

  • CVE-2024-9392CriOct 1, 2024
    risk 0.64cvss 9.8epss 0.01

    A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.

  • CVE-2024-25660CriOct 1, 2024
    risk 0.59cvss 9.0epss 0.01

    The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.

  • CVE-2024-41276CriOct 1, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit PIN code sent to their email for authorization after entering their login credentials. However, the request…

  • CVE-2024-9289CriOct 1, 2024
    risk 0.64cvss 9.8epss 0.01

    The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due to the rtwwwap_login_request_callback() function not properly validating a user's identity prior to authenticating…

  • CVE-2024-9265CriOct 1, 2024
    risk 0.64cvss 9.8epss 0.01

    The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due to the plugin not properly restricting the roles that can set during registration through the echo_check_post_header_sent()…

  • CVE-2024-9108CriOct 1, 2024
    risk 0.64cvss 9.8epss 0.01

    The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'convert_remoteimage_to_local' function in versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to upload…

  • CVE-2024-9106CriOct 1, 2024
    risk 0.64cvss 9.8epss 0.02

    The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log…

  • CVE-2024-9194CriSep 30, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsoft Windows Octopus Server on Windows, Linux allows SQL Injection.This issue affects Octopus Server: from 2024.1.0 before 2024.1.13038, from 2024.2.0 before…

  • CVE-2024-42017CriSep 30, 2024
    risk 0.65cvss 10.0epss 0.01

    An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if the application is remotely accessible, it allows an attacker to execute arbitrary commands with system privilege on the endpoint…

  • CVE-2024-46293CriSep 30, 2024
    risk 0.64cvss 9.8epss 0.00

    Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does…

  • CVE-2024-8456CriSep 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware and system configurations, ultimately gaining full control of the devices.

  • CVE-2024-8353CriSep 28, 2024
    risk 0.62cvss 9.8epss 0.29

    The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and 'card_address'. This makes it…

  • CVE-2024-46256CriSep 27, 2024
    risk 0.00cvss 9.8epss 0.03

    A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.

  • CVE-2024-8630CriSep 27, 2024
    risk 0.61cvss 9.4epss 0.01

    Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database.

  • CVE-2024-8310CriSep 27, 2024
    risk 0.64cvss 9.8epss 0.01

    OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges.

  • CVE-2024-6981CriSep 27, 2024
    risk 0.64cvss 9.8epss 0.01

    OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication.

  • CVE-2024-46367CriSep 27, 2024
    risk 0.62cvss 9.6epss 0.01

    A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the…

  • CVE-2024-22170CriSep 27, 2024
    risk 0.60cvss —epss 0.00

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow Buffers.This issue affects My Cloud: before 5.29.102.

  • CVE-2024-47070CriSep 27, 2024
    risk 0.00cvss 9.0epss 0.01

    authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header with an unparsable IP address, e.g. `a`. This results in a possibility of logging into any…

  • CVE-2024-3373CriSep 27, 2024
    risk 0.60cvss —epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RSM Design Website Template allows SQL Injection. This issue affects Website Template: before 1.2.

  • CVE-2024-46865CriSep 27, 2024
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: fou: fix initialization of grc The grc must be initialize first. There can be a condition where if fou is NULL, goto out will be executed and grc would be used uninitialized.

  • CVE-2024-8643CriSep 27, 2024
    risk 0.64cvss 9.8epss 0.00

    Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking. This issue affects ValeApp: before v2.0.0.

  • CVE-2024-8607CriSep 27, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic Software ValeApp allows SQL Injection. This issue affects ValeApp: before v2.0.0.

  • CVE-2024-46628CriSep 26, 2024
    risk 0.65cvss 9.8epss 0.12

    Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.

  • CVE-2024-9166CriSep 26, 2024
    risk 0.61cvss —epss 0.02

    The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.

  • CVE-2024-46627CriSep 26, 2024
    risk 0.59cvss 9.1epss 0.04

    Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.

  • CVE-2024-7108CriSep 26, 2024
    risk 0.64cvss 9.8epss 0.00

    Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects CyberMath: before CYBM.240816253.

  • CVE-2024-0132CriSep 26, 2024
    risk 0.64cvss 9.0epss 0.41

    NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A…

  • CVE-2024-7772CriSep 26, 2024
    risk 0.57cvss 9.8epss 0.02

    The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation in the 'validate' function in all versions up to, and including, 4.6.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the…

  • CVE-2024-4657CriSep 25, 2024
    risk 0.60cvss —epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software BAP Automation allows Stored XSS. This issue affects BAP Automation: before 30840.

  • CVE-2024-6593CriSep 25, 2024
    risk 0.59cvss 9.1epss 0.01

    Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained network access could exploit this vulnerability…

  • CVE-2024-6592CriSep 25, 2024
    risk 0.59cvss 9.1epss 0.01

    An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications…

  • CVE-2024-8275CriSep 25, 2024
    risk 0.68cvss 9.8epss 0.50

    The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

  • CVE-2024-8514CriSep 25, 2024
    risk 0.52cvss 9.1epss 0.01

    The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.11 via deserialization of untrusted input from the 'prisna_import' parameter. This makes it possible for authenticated attackers,…

  • CVE-2024-7385CriSep 25, 2024
    risk 0.59cvss 9.1epss 0.01

    The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

  • CVE-2024-8621CriSep 25, 2024
    risk 0.57cvss 9.9epss 0.01

    The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_verse' shortcode in all versions up to, and including, 2024.08.26 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

  • CVE-2024-8485CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via the updateUserInfo() due to missing validation on the 'openid' user controlled key that determines what user will be…

  • CVE-2024-9148CriSep 25, 2024
    risk 0.55cvss 9.6epss 0.01

    Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.