VYPR

CVEs

38,095 total · page 321 of 762

  • CVE-2024-21014CriApr 16, 2024
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network…

  • CVE-2024-21010CriApr 16, 2024
    risk 0.64cvss 9.9epss 0.01

    Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows low privileged attacker with network access…

  • CVE-2024-20997CriApr 16, 2024
    risk 0.64cvss 9.9epss 0.01

    Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows low privileged attacker with network access…

  • CVE-2024-3660CriApr 16, 2024
    risk 0.57cvss 9.8epss 0.02

    A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.

  • CVE-2024-3863CriApr 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.

  • CVE-2024-32027CriApr 16, 2024
    risk 0.00cvss 9.1epss 0.03

    Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss v22.6.1 is vulnerable to command injection in `finetune_gui.py` This vulnerability is fixed in 23.1.5.

  • CVE-2024-32026CriApr 16, 2024
    risk 0.00cvss 9.1epss 0.03

    Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `git_caption_gui.py`. This vulnerability is fixed in 23.1.5.

  • CVE-2024-32025CriApr 16, 2024
    risk 0.00cvss 9.1epss 0.02

    Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `group_images_gui.py`. This vulnerability is fixed in 23.1.5.

  • CVE-2024-32022CriApr 16, 2024
    risk 0.00cvss 9.1epss 0.03

    Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to command injection in basic_caption_gui.py. This vulnerability is fixed in 23.1.5.

  • CVE-2024-3871CriApr 16, 2024
    risk 0.64cvss 9.8epss 0.02

    The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and stack overflows vulnerabilities. Successful exploitation of these flaws would allow remote…

  • CVE-2024-3573CriApr 16, 2024
    risk 0.54cvss 9.3epss 0.01

    mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary files on the system. The issue arises from the 'is_local_uri' function's failure to properly handle URIs with empty or 'file'…

  • CVE-2024-3271CriApr 16, 2024
    risk 0.57cvss 9.8epss 0.03

    A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval function. Attackers can bypass the intended security mechanism, which checks for the presence of underscores in code generated by LLM, to execute arbitrary code.…

  • CVE-2024-2912CriApr 16, 2024
    risk 0.58cvss 10.0epss 0.02

    An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted POST request. By exploiting this vulnerability, attackers can execute arbitrary commands on the server hosting the BentoML application.…

  • CVE-2024-2083CriApr 16, 2024
    risk 0.60cvss 9.9epss 0.37

    A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can exploit this vulnerability by manipulating the 'logs' URI path in the request to fetch arbitrary file content, bypassing intended access…

  • CVE-2024-1739CriApr 16, 2024
    risk 0.59cvss 9.1epss 0.01

    lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email addresses as case insensitive, allowing the creation of multiple accounts with the same email address…

  • CVE-2024-1601CriApr 16, 2024
    risk 0.03cvss 9.8epss 0.40

    An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, allowing an attacker to delete all discussions and message data. The vulnerability is exploitable via a crafted HTTP POST request to the `/delete_discussion`…

  • CVE-2024-0404CriApr 16, 2024
    risk 0.00cvss 9.1epss 0.01

    A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository, allowing unauthorized creation of high-privileged accounts. By intercepting and modifying the HTTP request during the account creation process via an…

  • CVE-2024-31650CriApr 15, 2024
    risk 0.62cvss 9.6epss 0.01

    A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter.

  • CVE-2024-28557CriApr 15, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to update-admin.php.

  • CVE-2024-28556CriApr 15, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin-manage-user.php.

  • CVE-2024-24486CriApr 15, 2024
    risk 0.59cvss 9.1epss 0.01

    An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA command.

  • CVE-2024-28056CriApr 15, 2024
    risk 0.57cvss 9.8epss 0.02

    Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed from an Amplify project, a Condition property is removed but "Effect":"Allow" remains present, and…

  • CVE-2023-48710CriApr 15, 2024
    risk 0.00cvss 9.8epss 0.01

    iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is no sensitive files stored in that folder natively, but there could be from a third-party module. The…

  • CVE-2024-3781CriApr 15, 2024
    risk 0.59cvss 9.1epss 0.01

    Command injection vulnerability in the operating system. Improper neutralisation of special elements in Active Directory integration allows the intended command to be modified when sent to a downstream component in WBSAirback 21.02.04.

  • CVE-2024-23486CriApr 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker with access to the product's login page may obtain configured credentials.

  • CVE-2024-3701CriApr 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services.

  • CVE-2024-32128CriApr 15, 2024
    risk 0.61cvss 9.3epss 0.02

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Realtyna Realtyna Organic IDX plugin.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.4.

  • CVE-2024-3777CriApr 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password.

  • CVE-2024-29844CriApr 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the password. There is no warning or…

  • CVE-2024-29836CriApr 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthenticated attacker to update and add user profiles within the application, and gain full access of the site.

  • CVE-2024-3765CriApr 14, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability classified as critical was found in Xiongmai AHB7804R-MH-V2, AHB8004T-GL, AHB8008T-GL, AHB7004T-GS-V3, AHB7004T-MHV2, AHB8032F-LME and XM530_R80X30-PQ_8M. Affected by this vulnerability is an unknown functionality of the component Sofia Service. The manipulation…

  • CVE-2024-28878CriApr 12, 2024
    risk 0.62cvss 9.6epss 0.00

    IO-1020 Micro ELD downloads source code or an executable from an adjacent location and executes the code without sufficiently verifying the origin or integrity of the code.

  • CVE-2024-3704CriApr 12, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection Vulnerability has been found on OpenGnsys product affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to inject malicious SQL code into login page to bypass it or even retrieve all the information stored in the database.

  • CVE-2023-51409CriApr 12, 2024
    risk 0.70cvss 10.0epss 0.63

    Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.

  • CVE-2024-31818CriApr 12, 2024
    risk 0.64cvss 9.8epss 0.02

    Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.php component.

  • CVE-2024-28718CriApr 12, 2024
    risk 0.57cvss 9.8epss 0.01

    An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component.

  • CVE-2024-3400CriKEVApr 12, 2024
    risk 0.94cvss 10.0epss 1.00

    A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root…

  • CVE-2024-22718CriApr 11, 2024
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id parameter in the application URL.

  • CVE-2024-31678CriApr 11, 2024
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Loan Management System v1.0 is vulnerable to SQL Injection via the "password" parameter in the "login.php" file.

  • CVE-2024-21508CriApr 11, 2024
    risk 0.57cvss 9.8epss 0.03

    Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

  • CVE-2024-29937CriApr 11, 2024
    risk 0.64cvss 9.8epss 0.02

    NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.

  • CVE-2024-27683CriApr 11, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacker can send a POST request to trigger the vulnerablilify.

  • CVE-2024-25912CriApr 11, 2024
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.

  • CVE-2024-31997CriApr 10, 2024
    risk 0.63cvss 9.9epss 0.74

    XWiki Platform is a generic wiki platform. Prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, parameters of UI extensions are always interpreted as Velocity code and executed with programming rights. Any user with edit right on any document like the user's own profile can create…

  • CVE-2024-31996CriApr 10, 2024
    risk 0.58cvss 10.0epss 0.02

    XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of escaping tool that is used in XWiki doesn't escape `{`, which, when used in certain places, allows XWiki syntax injection and thereby…

  • CVE-2024-31988CriApr 10, 2024
    risk 0.55cvss 9.6epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 13.9-rc-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, when the realtime editor is installed in XWiki, it allows arbitrary remote code execution with the interaction of an admin user with programming right.…

  • CVE-2024-31987CriApr 10, 2024
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who can edit any page like their profile can create a custom skin with a template override that is executed with programming right, thus…

  • CVE-2024-31986CriApr 10, 2024
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, by creating a document with a special crafted documented reference and an `XWiki.SchedulerJobClass` XObject, it is possible to execute arbitrary code on the…

  • CVE-2024-31984CriApr 10, 2024
    risk 0.64cvss 9.9epss 0.83

    XWiki Platform is a generic wiki platform. Starting in version 7.2-rc-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, by creating a document with a specially crafted title, it is possible to trigger remote code execution in the (Solr-based) search in XWiki. This allows…

  • CVE-2024-31983CriApr 10, 2024
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. In multilingual wikis, translations can be edited by any user who has edit right, circumventing the rights that are normally required for authoring translations (script right for user-scope translations, wiki admin for translations on…