VYPR

CVEs

38,084 total · page 297 of 762

  • CVE-2024-33897CriAug 6, 2024
    risk 0.59cvss 9.1epss 0.01

    A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024.

  • CVE-2024-30170CriAug 6, 2024
    risk 0.59cvss 9.1epss 0.01

    PrivX before 34.0 allows data exfiltration and denial of service via the REST API. This is fixed in minor versions 33.1, 32.3, 31.3, and later, and in major version 34.0 and later,

  • CVE-2024-7519CriAug 6, 2024
    risk 0.62cvss 9.6epss 0.01

    Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and…

  • CVE-2024-33974CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Users in…

  • CVE-2024-33973CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Attendance'…

  • CVE-2024-33972CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'events' in…

  • CVE-2024-33971CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'username' in…

  • CVE-2024-33970CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'studid' in…

  • CVE-2024-33969CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in…

  • CVE-2024-33968CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'Attendance' and…

  • CVE-2024-33967CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'view' in…

  • CVE-2024-33966CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'xtsearch' in…

  • CVE-2024-33965CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'view' in…

  • CVE-2024-33964CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in…

  • CVE-2024-33963CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'id' in…

  • CVE-2024-33962CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'code' in…

  • CVE-2024-33961CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'code' in…

  • CVE-2024-33960CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'end' in…

  • CVE-2024-33959CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the following 'categ' in…

  • CVE-2024-33958CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'phonenumber' in '/passwordrecover.php' parameter.

  • CVE-2024-33957CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in 'id' in '/admin/orders/controller.php' parameter

  • CVE-2024-6202CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymous actors could impersonate arbitrary HaloITSM users by just knowing their email address. HaloITSM versions past 2.146.1 (and…

  • CVE-2024-6886CriAug 6, 2024
    risk 0.61cvss —epss 0.33

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

  • CVE-2024-6782CriAug 6, 2024
    risk 0.66cvss 9.8epss 0.84

    Improper access control in Calibre 6.9.0 ~ 7.14.0 allow unauthenticated attackers to achieve remote code execution.

  • CVE-2024-6915CriAug 5, 2024
    risk 0.60cvss 9.3epss 0.01

    JFrog Artifactory versions below 7.90.6, 7.84.20, 7.77.14, 7.71.23, 7.68.22, 7.63.22, 7.59.23, 7.55.18 are vulnerable to Improper Input Validation that could potentially lead to cache poisoning.

  • CVE-2024-42009CriKEVAug 5, 2024
    risk 0.72cvss 9.3epss 0.83

    A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.

  • CVE-2024-42008CriAug 5, 2024
    risk 0.63cvss 9.3epss 0.34

    A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.

  • CVE-2024-40498CriAug 5, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in PuneethReddyHC Online Shopping sysstem advanced v.1.0 allows an attacker to execute arbitrary code via the register.php

  • CVE-2024-7397CriAug 5, 2024
    risk 0.61cvss —epss 0.01

    Improper filering of special characters result in a command ('command injection') vulnerability in Korenix JetPort 5601v3.This issue affects JetPort 5601v3: through 1.2.

  • CVE-2024-7395CriAug 5, 2024
    risk 0.61cvss —epss 0.01

    An authentication bypass vulnerability in Korenix JetPort 5601v3 allows an attacker to access functionality on the device without specifying a password.This issue affects JetPort 5601v3: through 1.2.

  • CVE-2024-38856CriKEVAug 5, 2024
    risk 0.80cvss 9.8epss 0.99

    Incorrect Authorization vulnerability in Apache OFBiz. This issue affects Apache OFBiz: through 18.12.14. Users are recommended to upgrade to version 18.12.15, which fixes the issue. Unauthenticated endpoints could allow execution of screen rendering code of screens if some…

  • CVE-2024-42447CriAug 5, 2024
    risk 0.57cvss 9.8epss 0.01

    Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions. The FAB provider prevented the user from logging out.   * FAB…

  • CVE-2024-6118CriAug 5, 2024
    risk 0.59cvss 9.1epss 0.00

    A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.

  • CVE-2024-41889CriAug 5, 2024
    risk 0.64cvss 9.8epss 0.01

    Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker.

  • CVE-2024-7257CriAug 3, 2024
    risk 0.57cvss 9.8epss 0.01

    The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_upload_file function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated…

  • CVE-2024-38887CriAug 2, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the execution of commands with unnecessary privileges.

  • CVE-2024-42348CriAug 2, 2024
    risk 0.60cvss 9.3epss 0.01

    FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a computer. This vulnerability is fixed in 1.5.10.41.3 and 1.6.0-beta.1395.

  • CVE-2024-38889CriAug 2, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command.

  • CVE-2024-38886CriAug 2, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the source of a communication channel.

  • CVE-2024-38883CriAug 2, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure algorithm during negotiation.

  • CVE-2024-38882CriAug 2, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutralization of special elements used in an OS command.

  • CVE-2024-7314CriAug 2, 2024
    risk 0.68cvss 9.8epss 0.52

    anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ";swagger-ui" to HTTP requests to bypass authentication and execute arbitrary Java on the victim server. Exploitation evidence was observed by the…

  • CVE-2024-36268CriAug 2, 2024
    risk 0.57cvss 9.8epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.13.0 or cherry-pick [1] to solve…

  • CVE-2024-42461CriAug 2, 2024
    risk 0.52cvss 9.1epss 0.01

    In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because BER-encoded signatures are allowed.

  • CVE-2024-42458CriAug 2, 2024
    risk 0.00cvss 9.8epss 0.01

    server.c in Neat VNC (aka neatvnc) before 0.8.1 does not properly validate the security type, a related issue to CVE-2006-2369.

  • CVE-2024-7093CriAug 1, 2024
    risk 0.61cvss —epss 0.01

    Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither properly sanitized nor sandboxed. This vulnerability enables users to construct command line scripts in their custom message…

  • CVE-2024-41259CriAug 1, 2024
    risk 0.59cvss 9.1epss 0.00

    Use of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's account information.

  • CVE-2024-39619CriAug 1, 2024
    risk 0.59cvss 9.0epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CridioStudio ListingPro listingpro-plugin allows PHP Local File Inclusion.This issue affects ListingPro: from n/a through <= 2.9.4.

  • CVE-2024-38770CriAug 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Privilege Management vulnerability in Revmakx Backup and Staging by WP Time Capsule allows Privilege Escalation, Authentication Bypass.This issue affects Backup and Staging by WP Time Capsule: from n/a through 1.22.20.

  • CVE-2024-41961CriAug 1, 2024
    risk 0.55cvss 9.6epss 0.01

    Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web application. An authenticated user can craft a search term containing…