VYPR

CVEs

38,095 total · page 319 of 762

  • CVE-2024-3191CriApr 29, 2024
    risk 0.00cvss 9.8epss 0.05

    A vulnerability, which was classified as critical, has been found in MailCleaner up to 2023.03.14. This issue affects some unknown processing of the component Email Handler. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has…

  • CVE-2024-33546CriApr 29, 2024
    risk 0.62cvss 9.6epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10.

  • CVE-2024-33544CriApr 29, 2024
    risk 0.61cvss 9.3epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through 14.0.10.

  • CVE-2024-33559CriApr 29, 2024
    risk 0.64cvss 9.3epss 0.04

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through 9.3.5.

  • CVE-2024-33551CriApr 29, 2024
    risk 0.60cvss 9.3epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from n/a through 5.3.5.

  • CVE-2024-4300CriApr 29, 2024
    risk 0.64cvss 9.8epss 0.01

    E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. Accessing this path allows attacker to obtain the database credential with the…

  • CVE-2024-1874CriApr 29, 2024
    risk 0.57cvss 9.4epss 0.33

    In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would…

  • CVE-2022-48666CriApr 28, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix a use-after-free There are two .exit_cmd_priv implementations. Both implementations use resources associated with the SCSI host. Make sure that these resources are still available when…

  • CVE-2024-3342CriApr 27, 2024
    risk 0.57cvss 9.9epss 0.01

    The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attribute of the 'mp-timetable' shortcode in all versions up to, and including, 2.4.11 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2024-30804CriApr 26, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via crafted IOCTL requests.

  • CVE-2024-28322CriApr 26, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST request.

  • CVE-2024-32881CriApr 26, 2024
    risk 0.57cvss 9.8epss 0.01

    Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Tokens. Anyone with network access can steal slack bot tokens and set them. This implies full compromise of the customer's slack bot,…

  • CVE-2024-31601CriApr 26, 2024
    risk 0.64cvss 9.8epss 0.00

    An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v. 20240323 and before allows attackers to execute arbitrary code via the exportpdf.php component.

  • CVE-2024-25343CriApr 26, 2024
    risk 0.59cvss 9.1epss 0.01

    Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords.

  • CVE-2024-33344CriApr 26, 2024
    risk 0.65cvss 9.8epss 0.20

    D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arbitrary commands via shell.

  • CVE-2024-32880CriApr 26, 2024
    risk 0.59cvss 9.1epss 0.01

    pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template to the specified folder lead to remote code execution. There is no fix available at the time of publication.

  • CVE-2024-32766CriApr 26, 2024
    risk 0.65cvss 10.0epss 0.02

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.3.2578 build…

  • CVE-2024-32764CriApr 26, 2024
    risk 0.64cvss 9.9epss 0.00

    A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege level of some functionality via a network. We have already fixed the vulnerability in the following…

  • CVE-2023-47222CriApr 26, 2024
    risk 0.62cvss 9.6epss 0.01

    An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following version:…

  • CVE-2024-0740CriApr 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vulnerability that does not require authentication. The fixed version is included in Eclipse IDE 2024-03

  • CVE-2024-3962CriApr 26, 2024
    risk 0.57cvss 9.8epss 0.01

    The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ppom_upload_file function in all versions up to, and including, 32.0.18. This makes it possible for unauthenticated attackers to…

  • CVE-2024-22633CriApr 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hprinter parameter. This vulnerability is triggered via a crafted POST request.

  • CVE-2024-22632CriApr 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hmsg parameter. This vulnerability is triggered via a crafted POST request.

  • CVE-2024-33668CriApr 26, 2024
    risk 0.52cvss 9.1epss 0.00

    An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to brute force them to upload malicious content to article drafts they have no access to.

  • CVE-2024-33661CriApr 26, 2024
    risk 0.00cvss 9.1epss 0.01

    Portainer before 2.20.0 allows redirects when the target is not index.yaml.

  • CVE-2024-32651CriApr 26, 2024
    risk 0.65cvss 10.0epss 0.84

    changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command…

  • CVE-2024-0916CriApr 25, 2024
    risk 0.65cvss 10.0epss 0.01

    Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3.

  • CVE-2022-36029CriApr 25, 2024
    risk 0.00cvss 9.1epss 0.00

    Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue.

  • CVE-2022-36028CriApr 25, 2024
    risk 0.00cvss 9.1epss 0.00

    Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the value of the `return_to` cookie. Versions 2.13.0 contains a patch for the issue.

  • CVE-2024-31615CriApr 25, 2024
    risk 0.64cvss 9.8epss 0.01

    ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.

  • CVE-2024-31266CriApr 25, 2024
    risk 0.59cvss 9.1epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in AlgolPlus Advanced Order Export For WooCommerce allows Code Injection.This issue affects Advanced Order Export For WooCommerce: from n/a through 3.4.4.

  • CVE-2024-30560CriApr 25, 2024
    risk 0.62cvss 9.6epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in 大侠WP DX-Watermark.This issue affects DX-Watermark: from n/a through 1.0.4.

  • CVE-2024-22144CriApr 25, 2024
    risk 0.59cvss 9.0epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Eli Scheetz Anti-Malware Security and Brute-Force Firewall gotmls allows Code Injection.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a through 4.21.96.

  • CVE-2023-51484CriApr 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in wp-buy Login as User or Customer (User Switching) allows Privilege Escalation.This issue affects Login as User or Customer (User Switching): from n/a through 3.8.

  • CVE-2023-51482CriApr 25, 2024
    risk 0.64cvss 9.9epss 0.01

    Improper Authentication vulnerability in EazyPlugins Eazy Plugin Manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Eazy Plugin Manager: from n/a through 4.1.2.

  • CVE-2023-51478CriApr 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in Abdul Hakeem Build App Online allows Privilege Escalation.This issue affects Build App Online: from n/a through 1.0.19.

  • CVE-2023-51477CriApr 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in BUDDYBOSS DMCC BuddyBoss Theme allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects BuddyBoss Theme: from n/a through 2.4.60.

  • CVE-2023-51472CriApr 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in Mestres do WP Checkout Mestres WP allows Privilege Escalation.This issue affects Checkout Mestres WP: from n/a through 7.1.9.7.

  • CVE-2023-51425CriApr 24, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Privilege Management vulnerability in Jacques Malgrange Rencontre – Dating Site allows Privilege Escalation.This issue affects Rencontre – Dating Site: from n/a through 3.10.1.

  • CVE-2023-31090CriApr 24, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates):…

  • CVE-2024-32954CriApr 24, 2024
    risk 0.59cvss 9.1epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.5.

  • CVE-2024-32836CriApr 24, 2024
    risk 0.59cvss 9.1epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay.This issue affects WP-Lister Lite for eBay: from n/a through <= 3.5.11.

  • CVE-2024-32709CriApr 24, 2024
    risk 0.61cvss 9.3epss 0.06

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Plechev Andrey WP-Recall.This issue affects WP-Recall: from n/a through 16.26.5.

  • CVE-2024-32948CriApr 24, 2024
    risk 0.59cvss 9.1epss 0.01

    Missing Authorization vulnerability in Repute Infosystems ARMember.This issue affects ARMember: from n/a through 4.0.28.

  • CVE-2024-28613CriApr 24, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component.

  • CVE-2024-32659CriApr 23, 2024
    risk 0.00cvss 9.8epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read if `((nWidth == 0) and (nHeight == 0))`. Version 3.5.1 contains a patch for the issue. No known workarounds are available.

  • CVE-2024-32658CriApr 23, 2024
    risk 0.00cvss 9.8epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version 3.5.1 contains a patch for the issue. No known workarounds are available.

  • CVE-2024-33215CriApr 23, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/addressNat.

  • CVE-2024-21511CriApr 23, 2024
    risk 0.57cvss 9.8epss 0.01

    Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.

  • CVE-2024-32459CriApr 22, 2024
    risk 0.00cvss 9.8epss 0.04

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. No known workarounds are available.