VYPR

CVEs

38,095 total · page 320 of 762

  • CVE-2024-32458CriApr 22, 2024
    risk 0.00cvss 9.8epss 0.02

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use `/gfx` or `/rfx` modes (on by…

  • CVE-2024-32041CriApr 22, 2024
    risk 0.00cvss 9.8epss 0.02

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, deactivate `/gfx` (on by default, set…

  • CVE-2024-32039CriApr 22, 2024
    risk 0.00cvss 9.8epss 0.02

    FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients using a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to integer overflow and out-of-bounds write. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use `/gfx`…

  • CVE-2024-27574CriApr 22, 2024
    risk 0.59cvss 9.1epss 0.01

    SQL Injection vulnerability in Trainme Academy version Ichin v.1.3.2 allows a remote attacker to obtain sensitive information via the informacion, idcurso, and tit parameters.

  • CVE-2024-4040CriKEVApr 22, 2024
    risk 0.87cvss 9.8epss 1.00

    A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and…

  • CVE-2024-32238CriApr 22, 2024
    risk 0.68cvss 9.8epss 0.53

    H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the management system page login interface.

  • CVE-2024-31545CriApr 22, 2024
    risk 0.61cvss 9.4epss 0.01

    Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/?page=user/manage_user&id=6.

  • CVE-2024-31666CriApr 22, 2024
    risk 0.64cvss 9.8epss 0.02

    An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component.

  • CVE-2024-27349CriApr 22, 2024
    risk 0.52cvss 9.1epss 0.01

    Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0. Users are recommended to upgrade to version 1.3.0, which fixes the issue.

  • CVE-2024-27348CriKEVApr 22, 2024
    risk 0.80cvss 9.8epss 0.99

    RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.

  • CVE-2024-29661CriApr 22, 2024
    risk 0.64cvss 9.8epss 0.01

    A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.

  • CVE-2024-32418CriApr 22, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.

  • CVE-2024-31547CriApr 19, 2024
    risk 0.59cvss 9.1epss 0.01

    Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_item.php.

  • CVE-2024-31546CriApr 19, 2024
    risk 0.64cvss 9.8epss 0.01

    Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/damage/view_damage.php.

  • CVE-2023-47435CriApr 19, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass authentication and access password protected pages.

  • CVE-2024-32644CriApr 19, 2024
    risk 0.52cvss 9.1epss 0.01

    Evmos is a scalable, high-throughput Proof-of-Stake EVM blockchain that is fully compatible and interoperable with Ethereum. Prior to 17.0.0, there is a way to mint arbitrary tokens due to the possibility to have two different states not in sync during the execution of a…

  • CVE-2024-32038CriApr 19, 2024
    risk 0.64cvss 9.8epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. There is a buffer overflow hazard in wazuh-analysisd when handling Unicode characters from Windows Eventchannel messages. It impacts Wazuh Manager 3.8.0 and above. This vulnerability is…

  • CVE-2024-29204CriApr 19, 2024
    risk 0.64cvss 9.8epss 0.04

    A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands

  • CVE-2024-24996CriApr 19, 2024
    risk 0.66cvss 9.8epss 0.32

    A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute arbitrary commands.

  • CVE-2024-22061CriApr 19, 2024
    risk 0.64cvss 9.8epss 0.04

    A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands

  • CVE-2024-31750CriApr 19, 2024
    risk 0.65cvss 9.8epss 0.19

    SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter.

  • CVE-2024-30938CriApr 19, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to obtain sensitive information via the ID parameter in the SEMCMS_User.php component.

  • CVE-2024-30923CriApr 18, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Document Rendering

  • CVE-2024-30922CriApr 18, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in Award Document Rendering.

  • CVE-2024-30564CriApr 18, 2024
    risk 0.57cvss 9.8epss 0.01

    An issue inandrei-tatar nora-firebase-common between v.1.0.41 and v.1.12.2 allows a remote attacker to execute arbitrary code via a crafted script to the updateState parameter of the updateStateInternal method.

  • CVE-2024-2796CriApr 18, 2024
    risk 0.60cvss 9.3epss 0.00

    A server-side request forgery (SSRF) was discovered in the Akana API Platform in versions prior to and including 2022.1.3. Reported by Jakob Antonsson.

  • CVE-2024-29021CriApr 18, 2024
    risk 0.60cvss 9.0epss 0.20

    Judge0 is an open-source online code execution system. The default configuration of Judge0 leaves the service vulnerable to a sandbox escape via Server Side Request Forgery (SSRF). This allows an attacker with sufficient access to the Judge0 API to obtain unsandboxed code…

  • CVE-2024-28189CriApr 18, 2024
    risk 0.62cvss 10.0epss 0.07

    Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file within the sandbox. An attacker can abuse this by creating a symbolic link (symlink) to a file outside the sandbox, allowing the attacker to run chown on…

  • CVE-2024-28185CriApr 18, 2024
    risk 0.62cvss 10.0epss 0.07

    Judge0 is an open-source online code execution system. The application does not account for symlinks placed inside the sandbox directory, which can be leveraged by an attacker to write to arbitrary files and gain code execution outside of the sandbox. When executing a…

  • CVE-2024-32599CriApr 18, 2024
    risk 0.65cvss 10.0epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Deepak anand WP Dummy Content Generator wp-dummy-content-generator.This issue affects WP Dummy Content Generator: from n/a through <= 3.2.1.

  • CVE-2023-49742CriApr 18, 2024
    risk 0.64cvss 9.9epss 0.01

    Missing Authorization vulnerability in Support Genix.This issue affects Support Genix: from n/a through 1.2.3.

  • CVE-2024-32340CriApr 17, 2024
    risk 0.62cvss 9.6epss 0.01

    A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the WEBSITE TITLE parameter under the Menu module.

  • CVE-2024-3817CriApr 17, 2024
    risk 0.57cvss 9.8epss 0.01

    HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.

  • CVE-2024-31581CriApr 17, 2024
    risk 0.00cvss 9.8epss 0.01

    FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c. This vulnerability allows attackers to cause undefined behavior within the application.

  • CVE-2024-30990CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "searchdata" parameter.

  • CVE-2024-32161CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    jizhiCMS 2.5 suffers from a File upload vulnerability.

  • CVE-2024-30985CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "todate" and "fromdate" parameters.

  • CVE-2024-30982CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter in the /view-user-detail.php file.

  • CVE-2024-30981CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.00

    SQL Injection vulnerability in /edit-computer-detail.php in phpgurukul Cyber Cafe Management System Using PHP & MySQL v1.0 allows attackers to run arbitrary SQL commands via editid in the application URL.

  • CVE-2024-30980CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the Computer Location parameter in manage-computer.php page.

  • CVE-2024-32318CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the formSetVlanInfo function.

  • CVE-2024-32286CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromVirtualSer function.

  • CVE-2024-32301CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7V1.0 v15.03.06.44 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.

  • CVE-2023-39367CriApr 17, 2024
    risk 0.62cvss 9.1epss 0.38

    An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this…

  • CVE-2024-26877CriApr 17, 2024
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: crypto: xilinx - call finalize with bh disabled When calling crypto_finalize_request, BH should be disabled to avoid triggering the following calltrace: ------------[ cut here ]------------ WARNING:…

  • CVE-2024-26853CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: igc: avoid returning frame twice in XDP_REDIRECT When a frame can not be transmitted in XDP_REDIRECT (e.g. due to a full queue), it is necessary to free it by calling xdp_return_frame_rx_napi. However, this…

  • CVE-2024-26828CriApr 17, 2024
    risk 0.61cvss 9.4epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: cifs: fix underflow in parse_server_interfaces() In this loop, we step through the buffer and after each item we check if the size_left is greater than the minimum size we need. However, the problem is that…

  • CVE-2024-32514CriApr 17, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker.This issue affects WP Poll Maker: from n/a through 3.4.

  • CVE-2024-21082CriApr 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…

  • CVE-2024-21071CriApr 16, 2024
    risk 0.59cvss 9.1epss 0.01

    Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise…