VYPR

CVEs

38,082 total · page 287 of 762

  • CVE-2024-9142CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.00

    External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Computer Systems e-Belediye allows Manipulating Web Input to File System Calls. This issue affects e-Belediye: before 2.0.642.

  • CVE-2024-8940CriSep 25, 2024
    risk 0.65cvss 10.0epss 0.01

    Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload malicious files to the server due to the…

  • CVE-2024-8878CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.

  • CVE-2024-8877CriSep 25, 2024
    risk 0.70cvss 9.8epss 0.77

    Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.

  • CVE-2024-8436CriSep 25, 2024
    risk 0.64cvss 9.9epss 0.00

    The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId' and 'edit_imageDelete' parameters in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2024-46957CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in 0.22.0.

  • CVE-2024-46612CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information.

  • CVE-2024-45066CriSep 25, 2024
    risk 0.65cvss 10.0epss 0.01

    A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands.

  • CVE-2024-43693CriSep 25, 2024
    risk 0.65cvss 10.0epss 0.01

    A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands.

  • CVE-2024-43692CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly.

  • CVE-2024-43423CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.

  • CVE-2024-42797CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music playlist entries.

  • CVE-2024-42507CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2024-42506CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2024-42505CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-26689CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

  • CVE-2023-26686CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop.

  • CVE-2024-8791CriSep 24, 2024
    risk 0.57cvss 9.8epss 0.01

    The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.8.1.14. This is due to the plugin not properly verifying a user's identity when the ID…

  • CVE-2024-8671CriSep 24, 2024
    risk 0.59cvss 9.1epss 0.01

    The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insufficient file path validation in the inc/barcode.php file in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to…

  • CVE-2024-8624CriSep 24, 2024
    risk 0.64cvss 9.9epss 0.00

    The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' attribute of the 'mdf_select_title' shortcode in all versions up to, and including, 1.3.3.3 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2024-7024CriSep 23, 2024
    risk 0.62cvss 9.6epss 0.00

    Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2024-47222CriSep 23, 2024
    risk 0.64cvss 9.8epss 0.01

    New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via manipulation of requests from external document storage via the MS-WOPI protocol.

  • CVE-2024-0005CriSep 23, 2024
    risk 0.59cvss 9.1epss 0.01

    A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration.

  • CVE-2024-0004CriSep 23, 2024
    risk 0.59cvss 9.1epss 0.01

    A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.

  • CVE-2024-0003CriSep 23, 2024
    risk 0.59cvss 9.1epss 0.00

    A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access.

  • CVE-2024-0002CriSep 23, 2024
    risk 0.65cvss 10.0epss 0.01

    A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.

  • CVE-2024-0001CriSep 23, 2024
    risk 0.65cvss 10.0epss 0.01

    A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.

  • CVE-2024-9014CriSep 23, 2024
    risk 0.65cvss 9.9epss 0.10

    pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID and secret, leading to unauthorized access to user data.

  • CVE-2024-47066CriSep 23, 2024
    risk 0.52cvss 9.0epss 0.12

    Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and could be bypassed when attacker provides an external malicious URL…

  • CVE-2024-46997CriSep 23, 2024
    risk 0.64cvss 9.8epss 0.01

    DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote command execution by adding a carefully constructed h2 data source connection string. The vulnerability has been fixed in v2.10.1.

  • CVE-2024-34331CriSep 23, 2024
    risk 0.64cvss 9.8epss 0.01

    A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because Parallels Service is setuid root.

  • CVE-2024-7735CriSep 23, 2024
    risk 0.60cvss —epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Exnet Informatics Software Ferry Reservation System allows SQL Injection. This issue affects Ferry Reservation System: before 240805-002.

  • CVE-2024-47219CriSep 22, 2024
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.

  • CVE-2024-47218CriSep 22, 2024
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.

  • CVE-2024-46640CriSep 20, 2024
    risk 0.64cvss 9.8epss 0.01

    SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.

  • CVE-2024-46103CriSep 20, 2024
    risk 0.64cvss 9.8epss 0.01

    SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.

  • CVE-2024-46101CriSep 20, 2024
    risk 0.64cvss 9.8epss 0.00

    GDidees CMS <= v3.9.1 has a file upload vulnerability.

  • CVE-2024-45489CriSep 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the…

  • CVE-2024-46652CriSep 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.

  • CVE-2024-9043CriSep 20, 2024
    risk 0.64cvss 9.8epss 0.01

    Secure Email Gateway from Cellopoint has Buffer Overflow Vulnerability in authentication process. Remote unauthenticated attackers can send crafted packets to crash the process, thereby bypassing authentication and obtaining system administrator privileges.

  • CVE-2024-8853CriSep 20, 2024
    risk 0.57cvss 9.8epss 0.01

    The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by…

  • CVE-2024-46983CriSep 19, 2024
    risk 0.57cvss 9.8epss 0.01

    sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget chain that can bypass the…

  • CVE-2024-45410CriSep 19, 2024
    risk 0.57cvss 9.8epss 0.02

    Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers such as X-Forwarded-Host or X-Forwarded-Port are added by Traefik before the request is routed to the application. For a HTTP client, it should not be possible…

  • CVE-2023-27584CriSep 19, 2024
    risk 0.59cvss 9.8epss 0.34

    Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key for JWT, "Secret Key", is hard coded,…

  • CVE-2024-40125CriSep 19, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to execute arbitrary code via uploading a crafted PHP file to the upload endpoint.

  • CVE-2024-33109CriSep 19, 2024
    risk 0.64cvss 9.9epss 0.01

    Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.

  • CVE-2024-8963CriKEVSep 19, 2024
    risk 0.81cvss 9.4epss 0.99

    Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

  • CVE-2024-31570CriSep 19, 2024
    risk 0.64cvss 9.8epss 0.01

    libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cpp Load function via an XPM file.

  • CVE-2024-7785CriSep 19, 2024
    risk 0.60cvss —epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ece Software Electronic Ticket System allows Reflected XSS, Cross-Site Scripting (XSS). This issue affects Electronic Ticket System: before 2024.08.

  • CVE-2024-8986CriSep 19, 2024
    risk 0.52cvss —epss 0.01

    The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved by running `git remote get-url origin`. If credentials are included in the repository URI (for instance, to allow for…