VYPR

CVEs

38,085 total · page 298 of 762

  • CVE-2024-41961CriAug 1, 2024
    risk 0.55cvss 9.6epss 0.01

    Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web application. An authenticated user can craft a search term containing…

  • CVE-2024-7332CriAug 1, 2024
    risk 0.65cvss 9.8epss 0.21

    A vulnerability was found in TOTOLINK CP450 4.1.0cu.747_B20191224. It has been classified as critical. This affects an unknown part of the file /web_cste/cgi-bin/product.ini of the component Telnet Service. The manipulation leads to use of hard-coded password. It is possible to…

  • CVE-2024-38182CriJul 31, 2024
    risk 0.59cvss 9.0epss 0.01

    Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.

  • CVE-2024-41660CriJul 31, 2024
    risk 0.64cvss 9.8epss 0.01

    slpd-lite is a unicast SLP UDP server. Any OpenBMC system that includes the slpd-lite package is impacted. Installing this package is the default when building OpenBMC. Nefarious users can send slp packets to the BMC using UDP port 427 to cause memory overflow issues within the…

  • CVE-2024-41947CriJul 31, 2024
    risk 0.55cvss 9.0epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets on the side of the other user, which…

  • CVE-2024-37901CriJul 31, 2024
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can perform arbitrary remote code execution by adding instances of `XWiki.SearchSuggestConfig` and `XWiki.SearchSuggestSourceClass` to…

  • CVE-2024-6980CriJul 31, 2024
    risk 0.64cvss 9.8epss 0.01

    A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-5 running only on premise.

  • CVE-2024-7205CriJul 31, 2024
    risk 0.61cvss —epss 0.01

    When the device is shared, the homepage module are before 2.19.0  in eWeLink Cloud Service allows Secondary user to take over devices as primary user via sharing unnecessary device-sensitive information.

  • CVE-2024-6695CriJul 31, 2024
    risk 0.64cvss 9.8epss 0.01

    it's possible for an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions. This is due to improper logic flow on the user registration process.

  • CVE-2024-38983CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Prototype Pollution in alykoshin mini-deep-assign v0.0.8 allows an attacker to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the _assign() method at (/lib/index.js:91)

  • CVE-2024-41611CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.

  • CVE-2024-41610CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.

  • CVE-2024-39012CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    ais-ltd strategyen v0.4.0 was discovered to contain a prototype pollution via the function mergeObjects. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-39011CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the function mergeObjects.

  • CVE-2024-39010CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    chase-moskal snapstate v0.0.9 was discovered to contain a prototype pollution via the function attemptNestedProperty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-38986CriJul 30, 2024
    risk 0.57cvss 9.8epss 0.01

    Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via merge methods of lodash to merge objects.

  • CVE-2024-38984CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via the __proto__ property.

  • CVE-2024-36572CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.

  • CVE-2024-38909CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.00

    Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.

  • CVE-2024-6699CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mikafon Electronic Inc. Mikafon MA7 allows SQL Injection. This issue affects Mikafon MA7: from v3.0 before v3.1.

  • CVE-2024-41702CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.00

    SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

  • CVE-2023-48396CriJul 30, 2024
    risk 0.52cvss 9.1epss 0.01

    Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in any user. Attacker can get secret key in /seatunnel-server/seatunnel-app/src/main/resources/application.yml and then create a…

  • CVE-2024-42108CriJul 30, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: net: rswitch: Avoid use-after-free in rswitch_poll() The use-after-free is actually in rswitch_tx_free(), which is inlined in rswitch_poll(). Since `skb` and `gq->skbs[gq->dirty]` are in fact the same pointer,…

  • CVE-2024-5975CriJul 30, 2024
    risk 0.59cvss 9.1epss 0.02

    The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

  • CVE-2024-5765CriJul 30, 2024
    risk 0.66cvss 9.8epss 0.27

    The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

  • CVE-2024-37858CriJul 29, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php.

  • CVE-2024-28805CriJul 29, 2024
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.

  • CVE-2024-41081CriJul 29, 2024
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: ila: block BH in ila_output() As explained in commit 1378817486d6 ("tipc: block BH before using dst_cache"), net/core/dst_cache.c helpers need to be called with BH disabled. ila_output() is called from…

  • CVE-2024-41073CriJul 29, 2024
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: nvme: avoid double free special payload If a discard request needs to be retried, and that retry may fail before a new special payload is added, a double free will result. Clear the RQF_SPECIAL_LOAD when the…

  • CVE-2024-41040CriJul 29, 2024
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: net/sched: Fix UAF when resolving a clash KASAN reports the following UAF: BUG: KASAN: slab-use-after-free in tcf_ct_flow_table_process_conn+0x12b/0x380 [act_ct] Read of size 1 at addr ffff888c07603600 by…

  • CVE-2024-38529CriJul 29, 2024
    risk 0.52cvss 9.0epss 0.01

    Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.10, there is a Remote Code Execution Vulnerability in the Message module of the Admidio Application, where it is possible to upload a PHP file in the…

  • CVE-2024-37906CriJul 29, 2024
    risk 0.57cvss 9.9epss 0.01

    Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.9, there is an SQL Injection in the `/adm_program/modules/ecards/ecard_send.php` source file of the Admidio Application. The SQL Injection results in a…

  • CVE-2024-6366CriJul 29, 2024
    risk 0.61cvss 9.1epss 0.29

    The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality of WP.

  • CVE-2024-7202CriJul 29, 2024
    risk 0.64cvss 9.8epss 0.01

    The query functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.

  • CVE-2024-7201CriJul 29, 2024
    risk 0.64cvss 9.8epss 0.01

    The login functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.

  • CVE-2024-5670CriJul 29, 2024
    risk 0.64cvss 9.8epss 0.01

    The web services of Softnext's products, Mail SQR Expert and Mail Archiving Expert do not properly validate user input, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the remote server.

  • CVE-2024-32671CriJul 29, 2024
    risk 0.00cvss 9.8epss 0.00

    Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.

  • CVE-2024-42049CriJul 28, 2024
    risk 0.62cvss 9.1epss 0.02

    TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.

  • CVE-2024-41120CriJul 26, 2024
    risk 0.57cvss 9.8epss 0.01

    streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` variable on line 63 of `pages/9_🔲_Vector_Data_Visualization.py` takes user input, which is later passed to the `gpd.read_file`…

  • CVE-2024-41119CriJul 26, 2024
    risk 0.57cvss 9.8epss 0.01

    streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 80 in `8_🏜️_Raster_Data_Visualization.py` takes user input, which is later used in the `eval()`…

  • CVE-2024-41117CriJul 26, 2024
    risk 0.57cvss 9.8epss 0.01

    streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 115 in `pages/10_🌍_Earth_Engine_Datasets.py` takes user input, which is later used in the `eval()`…

  • CVE-2024-41116CriJul 26, 2024
    risk 0.57cvss 9.8epss 0.01

    streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 1254 in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` function on line…

  • CVE-2024-41115CriJul 26, 2024
    risk 0.57cvss 9.8epss 0.01

    streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette` variable on line 488 in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` function on line 493,…

  • CVE-2024-41114CriJul 26, 2024
    risk 0.57cvss 9.8epss 0.01

    streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette` variable on line 430 in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` function on line 435,…

  • CVE-2024-41113CriJul 26, 2024
    risk 0.57cvss 9.8epss 0.01

    streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 383 or line 390 in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()`…

  • CVE-2024-41112CriJul 26, 2024
    risk 0.57cvss 9.8epss 0.01

    streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the palette variable in `pages/1_📷_Timelapse.py` takes user input, which is later used in the `eval()` function on line 380, leading to…

  • CVE-2024-40117CriJul 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting to the web administration server. Not existing for SL 200, 500, 1000 / fixed in 4.2.8 for SL 250, 300, 1200, 2000, SL 50 Gateway…

  • CVE-2024-26520CriJul 26, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Hangzhou Xiongwei Technology Development Co., Ltd. Restaurant Digital Comprehensive Management platform v1 allows an attacker to bypass authentication and perform arbitrary password resets.

  • CVE-2024-4447CriJul 26, 2024
    risk 0.64cvss 9.9epss 0.00

    In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via the Direct Web Remoting API (UserSessionAjax.getSessionList.dwr) calls. While this is information that would and should be available to admins who possess "Sign In As" powers,…

  • CVE-2024-41473CriJul 25, 2024
    risk 0.64cvss 9.8epss 0.07

    Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac