VYPR

CVEs

38,082 total · page 289 of 762

  • CVE-2024-44430CriSep 13, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary code and obtain sensitive information via a crafted payload to the kortex_lite/control/register_case.php interface

  • CVE-2024-46049CriSep 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.

  • CVE-2024-46048CriSep 13, 2024
    risk 0.65cvss 9.8epss 0.11

    Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i

  • CVE-2024-46046CriSep 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.

  • CVE-2024-46045CriSep 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.

  • CVE-2024-46044CriSep 13, 2024
    risk 0.64cvss 9.8epss 0.01

    CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.

  • CVE-2024-41874CriSep 13, 2024
    risk 0.66cvss 9.8epss 0.30

    ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by providing crafted input to the…

  • CVE-2024-6656CriSep 13, 2024
    risk 0.64cvss 9.8epss 0.00

    Use of Hard-coded Credentials vulnerability in TNB Mobile Solutions Cockpit Software allows Read Sensitive Strings Within an Executable. This issue affects Cockpit Software: before v2.13.

  • CVE-2024-46697CriSep 13, 2024
    risk 0.64cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: nfsd: ensure that nfsd4_fattr_args.context is zeroed out If nfsd4_encode_fattr4 ends up doing a "goto out" before we get to checking for the security label, then args.context will be set to uninitialized junk…

  • CVE-2024-46696CriSep 13, 2024
    risk 0.64cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: nfsd: fix potential UAF in nfsd4_cb_getattr_release Once we drop the delegation reference, the fields embedded in it are no longer safe to access. Do that last.

  • CVE-2024-46695CriSep 13, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: selinux,smack: don't bypass permissions check in inode_setsecctx hook Marek Gresko reports that the root user on an NFS client is able to change the security labels on files on an NFS filesystem that is…

  • CVE-2024-46690CriSep 13, 2024
    risk 0.64cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfsd4_deleg_getattr_conflict in presence of third party lease It is not safe to dereference fl->c.flc_owner without first confirming fl->fl_lmops is the expected manager. …

  • CVE-2024-7961CriSep 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to the server that could result in a remote code execution.

  • CVE-2024-7960CriSep 12, 2024
    risk 0.59cvss 9.1epss 0.00

    The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The vulnerability exists due to having an incorrect privilege matrix that allows users to have access to functions they should not.

  • CVE-2024-6678CriSep 12, 2024
    risk 0.58cvss 9.9epss 0.02

    An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances.

  • CVE-2024-8696CriSep 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.

  • CVE-2024-8695CriSep 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.

  • CVE-2024-45824CriSep 12, 2024
    risk 0.64cvss 9.8epss 0.01

    CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and allows for full unauthenticated remote code execution. The link in the mitigations…

  • CVE-2024-40457CriSep 12, 2024
    risk 0.59cvss 9.1epss 0.01

    No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is that cleartext in /etc/default/noip-duc is recommended and is the intentional behavior.

  • CVE-2024-28991CriSep 12, 2024
    risk 0.59cvss 9.0epss 0.03

    SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution.

  • CVE-2024-45856CriSep 12, 2024
    risk 0.59cvss 9.0epss 0.01

    A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI.

  • CVE-2024-8529CriSep 12, 2024
    risk 0.69cvss 10.0epss 0.12

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied…

  • CVE-2024-8522CriSep 12, 2024
    risk 0.66cvss 10.0epss 0.63

    The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on the user supplied…

  • CVE-2024-29847CriSep 12, 2024
    risk 0.68cvss 9.8epss 0.53

    Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

  • CVE-2024-44541CriSep 11, 2024
    risk 0.67cvss 9.8epss 0.03

    evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."

  • CVE-2024-45030CriSep 11, 2024
    risk 0.64cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: igb: cope with large MAX_SKB_FRAGS Sabrina reports that the igb driver does not cope well with large MAX_SKB_FRAG values: setting MAX_SKB_FRAG to 45 causes payload corruption on TX. An easy reproducer is to…

  • CVE-2024-45013CriSep 11, 2024
    risk 0.64cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: nvme: move stopping keep-alive into nvme_uninit_ctrl() Commit 4733b65d82bd ("nvme: start keep-alive after admin queue setup") moves starting keep-alive from nvme_start_ctrl() into nvme_init_ctrl_finish(), but…

  • CVE-2024-44466CriSep 11, 2024
    risk 0.65cvss 9.8epss 0.11

    COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface.

  • CVE-2024-27115CriSep 11, 2024
    risk 0.64cvss 9.8epss 0.05

    A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a publicly accessible folder before verifying any requirements. This leads to the…

  • CVE-2024-27114CriSep 11, 2024
    risk 0.64cvss 9.8epss 0.01

    A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be available for execution for a few milliseconds before it is removed, leading to…

  • CVE-2024-27113CriSep 11, 2024
    risk 0.64cvss 9.8epss 0.00

    An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database by exporting it as a CSV…

  • CVE-2024-27112CriSep 11, 2024
    risk 0.64cvss 9.8epss 0.00

    A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this vulnerability to gain access to the underlying database. The vulnerability has been remediated in version 1.52.02.

  • CVE-2024-6091CriSep 11, 2024
    risk 0.57cvss 9.8epss 0.01

    A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to block specific commands, such as 'whoami' and '/bin/whoami'. An attacker can circumvent this…

  • CVE-2024-45790CriSep 11, 2024
    risk 0.64cvss 9.8epss 0.01

    This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user passwords,…

  • CVE-2024-8277CriSep 11, 2024
    risk 0.64cvss 9.8epss 0.02

    The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to the plugin not properly validating what user transient is being used in the login() function and not properly…

  • CVE-2024-8503CriSep 10, 2024
    risk 0.73cvss 9.8epss 0.79

    An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.

  • CVE-2024-43040CriSep 10, 2024
    risk 0.59cvss 9.1epss 0.00

    Renwoxing Enterprise Intelligent Management System before v3.0 was discovered to contain a SQL injection vulnerability via the parid parameter at /fx/baseinfo/SearchInfo.

  • CVE-2024-45409CriSep 10, 2024
    risk 0.59cvss 10.0epss 0.11

    The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus…

  • CVE-2024-44893CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.

  • CVE-2024-43491CriSep 10, 2024
    risk 0.65cvss 9.8epss 0.13

    Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated…

  • CVE-2024-38220CriSep 10, 2024
    risk 0.59cvss 9.0epss 0.01

    Azure Stack Hub Elevation of Privilege Vulnerability

  • CVE-2024-45593CriSep 10, 2024
    risk 0.00cvss 9.0epss 0.01

    Nix is a package manager for Linux and other Unix systems. A bug in Nix 2.24 prior to 2.24.6 allows a substituter or malicious user to craft a NAR that, when unpacked by Nix, causes Nix to write to arbitrary file system locations to which the Nix process has access. This will be…

  • CVE-2024-44677CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.01

    eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.

  • CVE-2023-37234CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.00

    Loftware Spectrum through 4.6 has unprotected JMX Registry.

  • CVE-2023-36103CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.

  • CVE-2023-37231CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.

  • CVE-2023-37227CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.

  • CVE-2023-37226CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.

  • CVE-2024-40754CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.00

    Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.

  • CVE-2024-45032CriSep 10, 2024
    risk 0.65cvss 10.0epss 0.01

    A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versions < V2.3.1-1). Affected components do not properly validate the device tokens. This could allow an unauthenticated remote attacker to…