VYPR

CVEs

38,085 total · page 303 of 762

  • CVE-2024-6209CriJul 5, 2024
    risk 0.69cvss 10.0epss 0.17

    Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized

  • CVE-2024-39943CriJul 4, 2024
    risk 0.61cvss 9.9epss 0.39

    rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process…

  • CVE-2024-39932CriJul 4, 2024
    risk 0.66cvss 9.9epss 0.17

    Gogs through 0.13.0 allows argument injection during the previewing of changes.

  • CVE-2024-39931CriJul 4, 2024
    risk 0.68cvss 9.9epss 0.53

    Gogs through 0.13.0 allows deletion of internal files.

  • CVE-2024-39930CriJul 4, 2024
    risk 0.61cvss 9.9epss 0.08

    The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening an SSH connection and sending a malicious --split-string env request if the built-in SSH server…

  • CVE-2024-39165CriJul 4, 2024
    risk 0.64cvss 9.8epss 0.01

    QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the data parameter in conjunction with a .php file name in the filename parameter. This occurs because an unnecessary QR/demoapp…

  • CVE-2024-39844CriJul 3, 2024
    risk 0.57cvss 9.8epss 0.04

    In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.

  • CVE-2024-39223CriJul 3, 2024
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey

  • CVE-2024-37082CriJul 3, 2024
    risk 0.59cvss 9.1epss 0.01

    When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundry applications.  You are affected if you have route-services enabled in…

  • CVE-2024-4708CriJul 2, 2024
    risk 0.64cvss 9.8epss 0.01

    mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.

  • CVE-2023-24531CriJul 2, 2024
    risk 0.57cvss 9.8epss 0.01

    Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment…

  • CVE-2024-36404CriJul 2, 2024
    risk 0.63cvss 9.8epss 0.76

    GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) is possible if an application uses certain GeoTools functionality to evaluate XPath expressions supplied by user input. Versions…

  • CVE-2024-32755CriJul 2, 2024
    risk 0.59cvss 9.1epss 0.01

    Under certain circumstances the web interface will accept characters unrelated to the expected input.

  • CVE-2023-41921CriJul 2, 2024
    risk 0.64cvss 9.8epss 0.00

    A vulnerability allows attackers to download source code or an executable from a remote location and execute the code without sufficiently verifying the origin and integrity of the code. This vulnerability can allow attackers to modify the firmware before uploading it to the…

  • CVE-2023-41920CriJul 2, 2024
    risk 0.64cvss 9.8epss 0.00

    The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the device is configured with the IP address of 10.10.10.10, the root user is automatically logged in.

  • CVE-2023-41919CriJul 2, 2024
    risk 0.64cvss 9.8epss 0.00

    Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access.

  • CVE-2023-41918CriJul 2, 2024
    risk 0.65cvss 10.0epss 0.01

    A vulnerability allows unauthorized access to functionality inadequately constrained by ACLs. Attackers may exploit this to unauthenticated execute commands potentially leading to unauthorized data manipulation, access to privileged functions, or even the execution of arbitrary…

  • CVE-2023-41917CriJul 2, 2024
    risk 0.65cvss 10.0epss 0.01

    Inadequate input validation exposes the system to potential remote code execution (RCE) risks. Attackers can exploit this vulnerability by appending shell commands to the Speed-Measurement feature, enabling unauthorized code execution.

  • CVE-2024-6172CriJul 2, 2024
    risk 0.57cvss 9.8epss 0.01

    The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the…

  • CVE-2024-39309CriJul 1, 2024
    risk 0.58cvss 9.8epss 0.20

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 and 7.1.0 allows SQL injection when Parse Server is configured to use the PostgreSQL database. The algorithm to detect SQL injection…

  • CVE-2024-37762CriJul 1, 2024
    risk 0.64cvss 9.9epss 0.01

    MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

  • CVE-2024-5322CriJul 1, 2024
    risk 0.59cvss 9.1epss 0.00

    The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.

  • CVE-2024-38368CriJul 1, 2024
    risk 0.01cvss 9.3epss 0.15

    trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older pods which migrated from the pre-2014 pull request workflow to trunk. If the pods had never been claimed then it was still possible to do so. It was also…

  • CVE-2024-38366CriJul 1, 2024
    risk 0.66cvss 10.0epss 0.18

    trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies whether a user has a real email address on signup used a rfc-822 library which executes a shell command to validate the email domain MX records validity. It…

  • CVE-2024-28200CriJul 1, 2024
    risk 0.59cvss 9.1epss 0.02

    The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any…

  • CVE-2024-39251CriJul 1, 2024
    risk 0.65cvss 10.0epss 0.01

    An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensitive information, execute arbitrary code, or escalate privileges via sending crafted IOCTL requests.

  • CVE-2024-39236CriJul 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier disputes this because the report is about a user attacking himself.

  • CVE-2024-38513CriJul 1, 2024
    risk 0.58cvss 10.0epss 0.01

    Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions 2 and above. This vulnerability allows users to supply their own session_id value, resulting in the creation of a…

  • CVE-2024-38476CriJul 1, 2024
    risk 0.60cvss 9.8epss 0.42

    Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes…

  • CVE-2024-38475CriKEVJul 1, 2024
    risk 0.72cvss 9.1epss 1.00

    Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or…

  • CVE-2024-38474CriJul 1, 2024
    risk 0.57cvss 9.8epss 0.02

    Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users…

  • CVE-2024-36401CriKEVJul 1, 2024
    risk 0.80cvss 9.8epss 1.00

    GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users through specially crafted input against a…

  • CVE-2024-6425CriJul 1, 2024
    risk 0.59cvss 9.1epss 0.01

    Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can register user accounts without being authenticated from the route "/account/Register/" and in the parameters "UserName=&Password=<PASSWO…

  • CVE-2024-6424CriJul 1, 2024
    risk 0.60cvss 9.3epss 0.00

    External server-side request vulnerability in MESbook 20221021.03 version, which could allow a remote, unauthenticated attacker to exploit the endpoint "/api/Proxy/Post?userName=&password=&uri=<FILE|INTERNAL URL|IP/HOST" or "/api/Proxy/Get?userName=&password=&uri=<ARCHIVO|URL…

  • CVE-2024-39017CriJul 1, 2024
    risk 0.64cvss 9.8epss 0.01

    agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-39015CriJul 1, 2024
    risk 0.64cvss 9.8epss 0.01

    cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-39014CriJul 1, 2024
    risk 0.64cvss 9.8epss 0.01

    ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-39013CriJul 1, 2024
    risk 0.64cvss 9.8epss 0.01

    2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-39008CriJul 1, 2024
    risk 0.58cvss 10.0epss 0.01

    robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-38999CriJul 1, 2024
    risk 0.58cvss 10.0epss 0.01

    jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-38996CriJul 1, 2024
    risk 0.57cvss 9.8epss 0.01

    ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-38993CriJul 1, 2024
    risk 0.64cvss 9.8epss 0.01

    rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.

  • CVE-2024-20080CriJul 1, 2024
    risk 0.64cvss 9.8epss 0.00

    In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue…

  • CVE-2024-20078CriJul 1, 2024
    risk 0.64cvss 9.8epss 0.00

    In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08737250; Issue ID: MSV-1452.

  • CVE-2024-5926CriJun 30, 2024
    risk 0.59cvss 9.1epss 0.01

    A path traversal vulnerability in the get-project-files functionality of stitionai/devika allows attackers to read arbitrary files from the filesystem and cause a Denial of Service (DoS). This issue is present in all versions of the application. The vulnerability arises due to…

  • CVE-2024-39848CriJun 29, 2024
    risk 0.59cvss 9.1epss 0.00

    Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the UyY29r password for the M3vwHr account. This also affects…

  • CVE-2024-6265CriJun 29, 2024
    risk 0.57cvss 9.8epss 0.02

    The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uwp_sort_by’ parameter in all versions up to, and including, 1.2.10 due to insufficient…

  • CVE-2019-25211CriJun 29, 2024
    risk 0.52cvss 9.1epss 0.00

    parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is that only https://example.com/* should be allowed, and http://localhost.example.com/* is allowed…

  • CVE-2024-37371CriJun 28, 2024
    risk 0.59cvss 9.1epss 0.02

    In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.

  • CVE-2024-5827CriJun 28, 2024
    risk 0.64cvss 9.8epss 0.03

    Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can inject malicious SQL training data and generate corresponding queries to write arbitrary files on the victim's file system, such as backdoor.php with contents…