VYPR

CVEs

38,083 total · page 295 of 762

  • CVE-2024-42637CriAug 16, 2024
    risk 0.64cvss 9.8epss 0.01

    H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

  • CVE-2024-42634CriAug 16, 2024
    risk 0.64cvss 9.8epss 0.02

    A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root privileges.

  • CVE-2024-42466CriAug 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.

  • CVE-2024-42465CriAug 16, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.

  • CVE-2024-42462CriAug 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.

  • CVE-2024-6460CriAug 16, 2024
    risk 0.64cvss 9.8epss 0.05

    The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parameter. This makes it possible for attackers to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

  • CVE-2024-42757CriAug 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat function page.

  • CVE-2024-42472CriAug 15, 2024
    risk 0.00cvss 10.0epss 0.01

    Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have access to, which is an attack on…

  • CVE-2024-27730CriAug 15, 2024
    risk 0.00cvss 9.8epss 0.01

    Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar event feature.

  • CVE-2024-23168CriAug 15, 2024
    risk 0.64cvss 9.8epss 0.00

    Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code execution.

  • CVE-2024-42978CriAug 15, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP request.

  • CVE-2024-42967CriAug 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.

  • CVE-2024-42966CriAug 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.

  • CVE-2024-42947CriAug 15, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request.

  • CVE-2024-42843CriAug 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Projectworlds Online Examination System v1.0 is vulnerable to SQL Injection via the subject parameter in feed.php.

  • CVE-2024-42360CriAug 14, 2024
    risk 0.57cvss 9.8epss 0.01

    SequenceServer lets you rapidly set up a BLAST+ server with an intuitive user interface for personal or group use. Several HTTP endpoints did not properly sanitize user input and/or query parameters. This could be exploited to inject and run unwanted shell commands. This…

  • CVE-2024-5914CriAug 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.

  • CVE-2024-39397CriAug 14, 2024
    risk 0.59cvss 9.0epss 0.01

    Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a…

  • CVE-2024-7732CriAug 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.

  • CVE-2024-7731CriAug 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.

  • CVE-2024-38652CriAug 14, 2024
    risk 0.60cvss 9.1epss 0.08

    Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.

  • CVE-2024-20083CriAug 14, 2024
    risk 0.64cvss 9.8epss 0.00

    In venc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08810810 / ALPS08805789; Issue ID: MSV-1502.

  • CVE-2024-20082CriAug 14, 2024
    risk 0.64cvss 9.8epss 0.01

    In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01182594; Issue ID: MSV-1529.

  • CVE-2024-28986CriKEVAug 13, 2024
    risk 0.82cvss 9.8epss 0.85

    SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been…

  • CVE-2024-7593CriKEVAug 13, 2024
    risk 0.87cvss 9.8epss 1.00

    Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

  • CVE-2024-7569CriAug 13, 2024
    risk 0.63cvss 9.6epss 0.02

    An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.

  • CVE-2024-38199CriAug 13, 2024
    risk 0.64cvss 9.8epss 0.02

    Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability

  • CVE-2024-38160CriAug 13, 2024
    risk 0.59cvss 9.1epss 0.02

    Windows Network Virtualization Remote Code Execution Vulnerability

  • CVE-2024-38159CriAug 13, 2024
    risk 0.59cvss 9.1epss 0.02

    Windows Network Virtualization Remote Code Execution Vulnerability

  • CVE-2024-38140CriAug 13, 2024
    risk 0.64cvss 9.8epss 0.04

    Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

  • CVE-2024-38109CriAug 13, 2024
    risk 0.59cvss 9.1epss 0.02

    An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.

  • CVE-2024-38108CriAug 13, 2024
    risk 0.61cvss 9.3epss 0.01

    Azure Stack Hub Spoofing Vulnerability

  • CVE-2024-38063CriAug 13, 2024
    risk 0.69cvss 9.8epss 0.71

    Windows TCP/IP Remote Code Execution Vulnerability

  • CVE-2024-7746CriAug 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the Traccar solution that should otherwise be protected by the authentication…

  • CVE-2024-41623CriAug 13, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload

  • CVE-2024-43160CriAug 13, 2024
    risk 0.65cvss 10.0epss 0.05

    Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6.

  • CVE-2024-43153CriAug 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.10.

  • CVE-2024-43141CriAug 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Injection.This issue affects Participants Database: from n/a through 2.5.9.2.

  • CVE-2024-37287CriAug 13, 2024
    risk 0.59cvss 9.1epss 0.02

    A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototype pollution vulnerability, ultimately leading to arbitrary code execution.

  • CVE-2024-43121CriAug 13, 2024
    risk 0.59cvss 9.1epss 0.00

    Improper Privilege Management vulnerability in realmag777 HUSKY allows Privilege Escalation.This issue affects HUSKY: from n/a through 1.3.6.1.

  • CVE-2024-41940CriAug 13, 2024
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a privileged command queue. This could allow an authenticated attacker to execute OS commands with elevated privileges.

  • CVE-2024-41730CriAug 13, 2024
    risk 0.70cvss 9.8epss 0.76

    In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a REST endpoint. The attacker can fully compromise the system resulting in High impact on confidentiality,…

  • CVE-2024-7094CriAug 13, 2024
    risk 0.67cvss 9.8epss 0.38

    The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on…

  • CVE-2024-43360CriAug 12, 2024
    risk 0.00cvss 9.8epss 0.06

    ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.

  • CVE-2024-42547CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.

  • CVE-2024-42546CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the password parameter in the loginauth function.

  • CVE-2024-42545CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg function.

  • CVE-2024-42543CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.

  • CVE-2024-42489CriAug 12, 2024
    risk 0.00cvss 10.0epss 0.01

    Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform remote code execution. Other macros like Viewppt are vulnerable to the same kind…

  • CVE-2023-7249CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.