VYPR

CVEs

38,083 total · page 292 of 762

  • CVE-2024-43941CriAug 29, 2024
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Propovoice Propovoice Pro allows SQL Injection.This issue affects Propovoice Pro: from n/a through 1.7.0.3.

  • CVE-2024-43931CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.3.

  • CVE-2024-43918CriAug 29, 2024
    risk 0.65cvss 10.0epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WBW Product Table PRO allows SQL Injection.This issue affects WBW Product Table PRO: from n/a through 1.9.4.

  • CVE-2024-43917CriAug 29, 2024
    risk 0.65cvss 9.3epss 0.23

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TemplateInvaders TI WooCommerce Wishlist allows SQL Injection.This issue affects TI WooCommerce Wishlist: from n/a through 2.8.2.

  • CVE-2024-43144CriAug 29, 2024
    risk 0.61cvss 9.3epss 0.02

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Cost Calculator Builder allows SQL Injection.This issue affects Cost Calculator Builder: from n/a through 3.2.15.

  • CVE-2024-43132CriAug 29, 2024
    risk 0.60cvss 9.3epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPWeb Elite Docket (WooCommerce Collections / Wishlist / Watchlist) allows SQL Injection.This issue affects Docket (WooCommerce Collections / Wishlist / Watchlist): from n/a…

  • CVE-2024-39653CriAug 29, 2024
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E4J s.R.L. VikRentCar allows SQL Injection.This issue affects VikRentCar: from n/a through 1.4.0.

  • CVE-2024-39622CriAug 29, 2024
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro allows SQL Injection.This issue affects ListingPro: from n/a through <= 2.9.4.

  • CVE-2024-38795CriAug 29, 2024
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CridioStudio ListingPro listingpro-plugin allows SQL Injection.This issue affects ListingPro: from n/a through <= 2.9.4.

  • CVE-2024-5057CriAug 29, 2024
    risk 0.61cvss 9.3epss 0.03

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Easy Digital Downloads allows SQL Injection.This issue affects Easy Digital Downloads: from n/a through 3.2.12.

  • CVE-2024-4428CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Managment Portal allows Collect Data as Provided by Users. This issue affects Managment Portal: through 21.05.2024.

  • CVE-2024-29731CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query:  https://XXXXXXX.saludydesafio.com/app/ax/checkBlindFields/…

  • CVE-2024-29730CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query:  https://XXXXXXX.saludydesafio.com/app/ax/consejoRandom/ ,…

  • CVE-2024-29729CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/generateShortURL/,…

  • CVE-2024-29728CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/inscribeUsuario/ ,…

  • CVE-2024-29727CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sendParticipationRe…

  • CVE-2024-29726CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/setAsRead/,…

  • CVE-2024-29725CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/app/ax/sort_bloques/,…

  • CVE-2024-29724CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/ax/registerSp/, parameter…

  • CVE-2024-29723CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to retrieve, update and delete all information in the database by sending a specially crafted SQL query: https://XXXXXXX.saludydesafio.com/conexiones/ax/openTracExt/,…

  • CVE-2024-45435CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Chartist 1.x through 1.3.0 allows Prototype Pollution via the extend function.

  • CVE-2024-45233CriAug 29, 2024
    risk 0.57cvss 9.8epss 0.00

    An issue was discovered in powermail extension through 12.3.5 for TYPO3. Several actions in the OutputController can directly be called, due to missing or insufficiently implemented access checks, resulting in Broken Access Control. Depending on the configuration of the…

  • CVE-2024-34195CriAug 28, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack of length restriction on the wlan_ssid field. This oversight leads to potential buffer overflow…

  • CVE-2024-44761CriAug 28, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.

  • CVE-2024-42905CriAug 28, 2024
    risk 0.65cvss 9.8epss 0.15

    Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device administrator privileges via the getVar function in the code/function/system/tool/ping.php file.

  • CVE-2024-34198CriAug 28, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa program fails to limit the length of the wlan_ssid field from user input. This allows attackers to craft malicious HTTP requests by supplying…

  • CVE-2024-8030CriAug 28, 2024
    risk 0.64cvss 9.8epss 0.01

    The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store_kit_wishlist cookie in…

  • CVE-2024-7720CriAug 27, 2024
    risk 0.64cvss 9.8epss 0.01

    HP Security Manager is potentially vulnerable to Remote Code Execution as a result of code vulnerability within the product's solution open-source libraries.

  • CVE-2024-36068CriAug 27, 2024
    risk 0.64cvss 9.8epss 0.00

    An incorrect access control vulnerability in Rubrik CDM versions prior to 9.1.2-p1, 9.0.3-p6 and 8.1.3-p12, allows an attacker with network access to execute arbitrary code.

  • CVE-2024-44342CriAug 27, 2024
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This vulnerability is exploited via a crafted POST request.

  • CVE-2024-44341CriAug 27, 2024
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.

  • CVE-2024-41622CriAug 27, 2024
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in /HNAP1/ interface.

  • CVE-2024-6633CriAug 27, 2024
    risk 0.64cvss 9.8epss 0.01

    The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are published in a vendor knowledgebase article. Misuse of these credentials could lead to a compromise of confidentiality, integrity, or availability of the software. The HSQLDB is only…

  • CVE-2024-7071CriAug 27, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in Brain Information Technologies Inc. Brain Low-Code allows SQL Injection. This issue affects Brain Low-Code: before 2.1.0.

  • CVE-2024-8181CriAug 27, 2024
    risk 0.67cvss 9.8epss 0.45

    An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.

  • CVE-2024-4872CriAug 27, 2024
    risk 0.64cvss 9.9epss 0.01

    A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential.

  • CVE-2024-3980CriAug 27, 2024
    risk 0.64cvss 9.9epss 0.01

    The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the…

  • CVE-2024-45265CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in the poll component in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to execute arbitrary SQL commands via the psid parameter.

  • CVE-2024-42913CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.00

    RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1.

  • CVE-2024-41444CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.00

    SeaCMS v12.9 has a SQL injection vulnerability in the key parameter of /js/player/dmplayer/dmku/index.php?ac=so.

  • CVE-2024-44557CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function setIptvInfo.

  • CVE-2024-44555CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function setIptvInfo.

  • CVE-2024-44553CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formGetIptv.

  • CVE-2024-44552CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.00

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.

  • CVE-2024-44551CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formGetIptv.

  • CVE-2024-44550CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formGetIptv.

  • CVE-2024-44549CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.00

    Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formGetIptv.

  • CVE-2024-41285CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    A stack overflow in FAST FW300R v1.3.13 Build 141023 Rel.61347n allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted file path.

  • CVE-2024-34087CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    An SEH-based buffer overflow in the BPQ32 HTTP Server in BPQ32 6.0.24.1 allows remote attackers with access to the Web Terminal to achieve remote code execution via an HTTP POST /TermInput request.

  • CVE-2024-7988CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.05

    A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be…