VYPR

CVEs

38,085 total · page 300 of 762

  • CVE-2024-0857CriJul 18, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software Inc. FlexWater Corporate Water Management allows SQL Injection. This issue affects FlexWater Corporate Water Management: before 5.452.0.

  • CVE-2024-5619CriJul 18, 2024
    risk 0.62cvss 9.6epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Apinizer Management Console: before 2024.05.1.

  • CVE-2024-5618CriJul 18, 2024
    risk 0.64cvss 9.9epss 0.00

    Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Apinizer Management Console: before 2024.05.1.

  • CVE-2024-40629CriJul 18, 2024
    risk 0.58cvss 10.0epss 0.01

    JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser. An attacker can exploit the Ansible playbook to write…

  • CVE-2024-40628CriJul 18, 2024
    risk 0.58cvss 10.0epss 0.01

    JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser. An attacker can exploit the ansible playbook to read arbitrary…

  • CVE-2024-39911CriJul 18, 2024
    risk 0.65cvss 10.0epss 0.05

    1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent handling. This issue has been addressed in version 1.10.12-lts. Users are advised to upgrade. There are no known workarounds for this vulnerability.

  • CVE-2024-39907CriJul 18, 2024
    risk 0.59cvss 9.8epss 0.29

    1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultimately leading to RCEs. These sql injections have been resolved in version 1.10.12-tls.…

  • CVE-2024-6164CriJul 18, 2024
    risk 0.64cvss 9.8epss 0.01

    The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an unauthenticated attacker to include and execute PHP files on the server, allowing the execution of any PHP code in those files.

  • CVE-2024-41184CriJul 18, 2024
    risk 0.64cvss 9.8epss 0.01

    In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user.

  • CVE-2024-20419CriJul 17, 2024
    risk 0.74cvss 10.0epss 0.81

    A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper implementation of the…

  • CVE-2024-20401CriJul 17, 2024
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files on the underlying operating system. This vulnerability is due to improper handling of email…

  • CVE-2023-4976CriJul 17, 2024
    risk 0.60cvss —epss 0.00

    A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array.

  • CVE-2024-6834CriJul 17, 2024
    risk 0.59cvss 9.0epss 0.00

    A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Zowe's client certificate. This allows access to a user to the endpoints requiring an internal client certificate without any credentials. It could lead to…

  • CVE-2024-28074CriJul 17, 2024
    risk 0.63cvss 9.6epss 0.11

    It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented the researcher was able to bypass these and use a different method to exploit the vulnerability.

  • CVE-2024-23475CriJul 17, 2024
    risk 0.63cvss 9.6epss 0.02

    The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.

  • CVE-2024-23472CriJul 17, 2024
    risk 0.64cvss 9.6epss 0.19

    SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability. This vulnerability allows an authenticated user to arbitrary read and delete files in ARM.

  • CVE-2024-23471CriJul 17, 2024
    risk 0.63cvss 9.6epss 0.01

    The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution.

  • CVE-2024-23470CriJul 17, 2024
    risk 0.62cvss 9.6epss 0.01

    The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to run commands and executables.

  • CVE-2024-23469CriJul 17, 2024
    risk 0.64cvss 9.6epss 0.18

    SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions with SYSTEM privileges.

  • CVE-2024-23467CriJul 17, 2024
    risk 0.63cvss 9.6epss 0.03

    The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform remote code execution.

  • CVE-2024-23466CriJul 17, 2024
    risk 0.63cvss 9.6epss 0.03

    SolarWinds Access Rights Manager (ARM) is susceptible to a Directory Traversal Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions with SYSTEM privileges.

  • CVE-2024-36491CriJul 17, 2024
    risk 0.64cvss 9.8epss 0.01

    FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OS command, obtain and/or alter sensitive information, and cause a denial-of-service (DoS) condition.

  • CVE-2024-31070CriJul 17, 2024
    risk 0.59cvss 9.1epss 0.01

    Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allows a remote unauthenticated attacker to access telnet service unlimitedly.

  • CVE-2024-6220CriJul 17, 2024
    risk 0.60cvss 9.8epss 0.35

    The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload…

  • CVE-2024-21181CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to…

  • CVE-2023-7012CriJul 16, 2024
    risk 0.62cvss 9.6epss 0.00

    Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a malicious app to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)

  • CVE-2023-4860CriJul 16, 2024
    risk 0.62cvss 9.6epss 0.00

    Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2019-25154CriJul 16, 2024
    risk 0.62cvss 9.6epss 0.00

    Inappropriate implementation in iframe in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-6779CriJul 16, 2024
    risk 0.62cvss 9.6epss 0.06

    Out of bounds memory access in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-40535CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a stack overflow via the apn_name_3g parameter in the config_3g_para function.

  • CVE-2024-40515CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in SHENZHEN TENDA TECHNOLOGY CO.,LTD Tenda AX2pro V16.03.29.48_cn allows a remote attacker to execute arbitrary code via the Routing functionality.

  • CVE-2024-40505CriJul 16, 2024
    risk 0.60cvss 9.3epss 0.00

    Directory Traversal vulnerability in D-Link DAP-1650 Firmware v.1.03 allows a local attacker to escalate privileges via the hedwig.cgi component.

  • CVE-2024-40456CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php.

  • CVE-2024-40394CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Simple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnerability via the component ajax.php.

  • CVE-2024-40393CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerability via the user parameter at login.php.

  • CVE-2024-40392CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    SourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and Bootstrap Framework with Source Code 1.0 was discovered to contain a SQL injection vulnerability via the name parameter under addnew.php.

  • CVE-2024-40130CriJul 16, 2024
    risk 0.57cvss 9.8epss 0.01

    open5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c.

  • CVE-2024-40129CriJul 16, 2024
    risk 0.57cvss 9.8epss 0.00

    Open5GS v2.6.4 is vulnerable to Buffer Overflow. via /lib/pfcp/context.c.

  • CVE-2024-40425CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute arbitrary code via the contorller/common.php component.

  • CVE-2024-39700CriJul 16, 2024
    risk 0.57cvss 9.9epss 0.01

    JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged…

  • CVE-2019-16639CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, which can allow an attacker (who only has web interface access) to use TELNET commands and/or show admin passwords via the mode_url=exec&command= substring. This…

  • CVE-2024-35338CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.

  • CVE-2024-33182CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/addWifiMacFilter.

  • CVE-2024-33180CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/saveParentControlInfo.

  • CVE-2024-22442CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The vulnerability could be remotely exploited to bypass authentication.

  • CVE-2022-48851CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: staging: gdm724x: fix use after free in gdm_lte_rx() The netif_rx_ni() function frees the skb so we can't dereference it to save the skb->len.

  • CVE-2022-48829CriJul 16, 2024
    risk 0.52cvss 9.1epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes iattr::ia_size is a loff_t, so these NFSv3 procedures must be careful to deal with incoming client size values that are larger than s64_max without…

  • CVE-2022-48828CriJul 16, 2024
    risk 0.59cvss 9.1epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix ia_size underflow iattr::ia_size is a loff_t, which is a signed 64-bit type. NFSv3 and NFSv4 both define file size as an unsigned 64-bit type. Thus there is a range of valid file size values an NFS…

  • CVE-2022-48790CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: nvme: fix a possible use-after-free in controller reset during load Unlike .queue_rq, in .submit_async_event drivers may not check the ctrl readiness for AER submission. This may lead to a use-after-free…

  • CVE-2022-48789CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix possible use-after-free in transport error_recovery work While nvme_tcp_submit_async_event_work is checking the ctrl and queue state before preparing the AER command and scheduling io_work, in…