VYPR

CVEs

38,095 total · page 322 of 762

  • CVE-2024-31982CriApr 10, 2024
    risk 0.61cvss 10.0epss 0.35

    XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's database search allows remote code execution through the search text. This allows remote code execution for any visitor of a public wiki…

  • CVE-2024-31981CriApr 10, 2024
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, remote code execution is possible via PDF export templates. This vulnerability has been patched in XWiki 14.10.20, 15.5.4 and 15.10-rc-1. If PDF templates…

  • CVE-2024-31819CriApr 10, 2024
    risk 0.61cvss 9.8epss 0.16

    An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.php component.

  • CVE-2024-31465CriApr 10, 2024
    risk 0.63cvss 9.9epss 0.76

    XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9-rc-1, any user with edit right on any page can execute any code on the server by adding an object of type `XWiki.SearchSuggestSourceClass` to their user…

  • CVE-2024-29500CriApr 10, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows attackers to execute arbitrary code via running a ClickOnce application instance.

  • CVE-2024-3157CriApr 10, 2024
    risk 0.62cvss 9.6epss 0.01

    Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High)

  • CVE-2021-47215CriApr 10, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: kTLS, Fix crash in RX resync flow For the TLS RX resync flow, we maintain a list of TLS contexts that require some attention, to communicate their resync information to the HW. Here we fix list…

  • CVE-2024-31461CriApr 10, 2024
    risk 0.52cvss 9.1epss 0.01

    Plane, an open-source project management tool, has a Server-Side Request Forgery (SSRF) vulnerability in versions prior to 0.17-dev. This issue may allow an attacker to send arbitrary requests from the server hosting the application, potentially leading to unauthorized access to…

  • CVE-2024-31214CriApr 10, 2024
    risk 0.04cvss 9.6epss 0.18

    Traccar is an open source GPS tracking system. Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded through the device image upload API. Attackers have full control over the file contents, full control over the directory where the file is stored, full control…

  • CVE-2024-3568CriApr 10, 2024
    risk 0.56cvss 9.6epss 0.02

    The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkpoint()` function of the `TFPreTrainedModel()` class. Attackers can execute arbitrary code and commands by crafting a malicious…

  • CVE-2024-3098CriApr 10, 2024
    risk 0.57cvss 9.8epss 0.01

    A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the `safe_eval` function, allowing for prompt injection leading to arbitrary code execution. This issue arises due to insufficient validation of input, which can be…

  • CVE-2024-3025CriApr 10, 2024
    risk 0.00cvss 9.9epss 0.01

    mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input in the logo filename functionality. Attackers can exploit this vulnerability by manipulating the logo filename to reference files outside of the restricted…

  • CVE-2024-2952CriApr 10, 2024
    risk 0.57cvss 9.8epss 0.01

    BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The vulnerability arises from the `hf_chat_template` method processing the `chat_template` parameter from the `tokenizer_config.json` file through the Jinja template engine…

  • CVE-2024-2221CriApr 10, 2024
    risk 0.00cvss 9.8epss 0.02

    qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload` endpoint, specifically through the `snapshot` parameter. This vulnerability allows attackers to upload and overwrite any file on the…

  • CVE-2024-2195CriApr 10, 2024
    risk 0.64cvss 9.8epss 0.02

    A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endpoint, affecting versions >= 3.0.0. The vulnerability resides in the `run_search_api` function of the `aim/web/api/runs/views.py`…

  • CVE-2024-2029CriApr 10, 2024
    risk 0.57cvss 9.8epss 0.03

    A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/localai, specifically within the `audioToWav` function used for converting audio files to WAV format for transcription. The vulnerability arises due to the lack of sanitization of user-supplied…

  • CVE-2024-1741CriApr 10, 2024
    risk 0.59cvss 9.1epss 0.01

    lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates using an old authorization token. Despite being removed from an organization, these members can still perform operations on…

  • CVE-2024-1740CriApr 10, 2024
    risk 0.59cvss 9.1epss 0.01

    In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, create, modify, and delete logs by re-using an old authorization token. The lunary web application communicates with the server using an 'Authorization' token in…

  • CVE-2024-1643CriApr 10, 2024
    risk 0.52cvss 9.1epss 0.01

    By knowing an organization's ID, an attacker can join the organization without permission and gain the ability to read and modify all data within that organization. This vulnerability allows unauthorized access and modification of sensitive information, posing a significant…

  • CVE-2024-1600CriApr 10, 2024
    risk 0.02cvss 9.3epss 0.33

    A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route. An attacker can exploit this vulnerability by crafting a URL that includes directory traversal sequences (`../../`) followed by the desired…

  • CVE-2024-1520CriApr 10, 2024
    risk 0.04cvss 9.8epss 0.48

    An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to improper validation of user-supplied input in the 'discussion_id' parameter. Attackers can exploit this vulnerability by injecting malicious OS…

  • CVE-2024-1511CriApr 10, 2024
    risk 0.64cvss 9.8epss 0.01

    The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of user-supplied file paths. This flaw allows an unauthenticated attacker to read, write, and in certain configurations execute arbitrary files on the server by…

  • CVE-2024-3566CriApr 10, 2024
    risk 0.64cvss 9.8epss 0.07

    A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

  • CVE-2024-23080CriApr 10, 2024
    risk 0.59cvss 9.1epss 0.01

    Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::wordBased(Locale). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a…

  • CVE-2024-20758CriApr 10, 2024
    risk 0.59cvss 9.0epss 0.01

    Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution on the underlying filesystem. Exploitation of this issue does not require user interaction, but…

  • CVE-2024-3120CriApr 10, 2024
    risk 0.52cvss 9.0epss 0.02

    A stack-buffer overflow vulnerability exists in all versions of sngrep since v1.4.1. The flaw is due to inadequate bounds checking when copying 'Content-Length' and 'Warning' headers into fixed-size buffers in the sip_validate_packet and sip_parse_extra_headers functions within…

  • CVE-2024-3119CriApr 10, 2024
    risk 0.52cvss 9.0epss 0.02

    A buffer overflow vulnerability exists in all versions of sngrep since v0.4.2, due to improper handling of 'Call-ID' and 'X-Call-ID' SIP headers. The functions sip_get_callid and sip_get_xcallid in sip.c use the strncpy function to copy header contents into fixed-size buffers…

  • CVE-2024-3136CriApr 9, 2024
    risk 0.57cvss 9.8epss 0.05

    The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the…

  • CVE-2024-2804CriApr 9, 2024
    risk 0.64cvss 9.8epss 0.01

    The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up to, and including, 2.0.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

  • CVE-2024-1813CriApr 9, 2024
    risk 0.64cvss 9.8epss 0.01

    The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted input in the job_board_applicant_list_columns_value function. This makes it possible for unauthenticated attackers to…

  • CVE-2024-24576CriApr 9, 2024
    risk 0.60cvss 10.0epss 0.20

    Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly escape arguments when invoking batch files (with the `bat` and `cmd` extensions) on Windows using the `Command`. An attacker able to…

  • CVE-2024-29990CriApr 9, 2024
    risk 0.60cvss 9.0epss 0.18

    Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

  • CVE-2024-31866CriApr 9, 2024
    risk 0.57cvss 9.8epss 0.01

    Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are…

  • CVE-2024-31864CriApr 9, 2024
    risk 0.57cvss 9.8epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver. This issue affects Apache Zeppelin: before 0.11.1. Users are…

  • CVE-2023-45590CriApr 9, 2024
    risk 0.63cvss 9.6epss 0.02

    An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4 allows attacker to execute unauthorized code or commands via tricking a FortiClientLinux user into visiting a malicious website

  • CVE-2023-6320CriApr 9, 2024
    risk 0.59cvss 9.1epss 0.04

    A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A series of specially crafted requests can lead to command execution as the dbus user. An attacker can make authenticated requests to…

  • CVE-2023-6319CriApr 9, 2024
    risk 0.60cvss 9.1epss 0.06

    A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make…

  • CVE-2023-6318CriApr 9, 2024
    risk 0.60cvss 9.1epss 0.05

    A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated…

  • CVE-2023-1083CriApr 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware updates.

  • CVE-2024-22949CriApr 8, 2024
    risk 0.59cvss 9.1epss 0.01

    JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /chart/annotations/CategoryLineAnnotation. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The…

  • CVE-2024-23086CriApr 8, 2024
    risk 0.64cvss 9.8epss 0.01

    Apfloat v1.10.1 was discovered to contain a stack overflow via the component org.apfloat.internal.DoubleModMath::modPow(double. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The…

  • CVE-2024-23078CriApr 8, 2024
    risk 0.59cvss 9.1epss 0.01

    JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the…

  • CVE-2024-31224CriApr 8, 2024
    risk 0.00cvss 9.8epss 0.01

    GPT Academic provides interactive interfaces for large language models. A vulnerability was found in gpt_academic versions 3.64 through 3.73. The server deserializes untrustworthy data from the client, which may risk remote code execution. Any device that exposes the GPT…

  • CVE-2024-31815CriApr 8, 2024
    risk 0.59cvss 9.1epss 0.01

    In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh

  • CVE-2024-31807CriApr 8, 2024
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.

  • CVE-2022-43216CriApr 8, 2024
    risk 0.59cvss 9.1epss 0.00

    AbrhilSoft Employee's Portal before v5.6.2 was discovered to contain a SQL injection vulnerability in the login page.

  • CVE-2024-26811CriApr 8, 2024
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate payload size in ipc response If installing malicious ksmbd-tools, ksmbd.mountd can return invalid ipc response to ksmbd kernel server. ksmbd should validate payload size of ipc response from…

  • CVE-2023-52538CriApr 8, 2024
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-31022CriApr 8, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in CandyCMS version 1.0.0, allows remote attackers to execute arbitrary code via the install.php component.

  • CVE-2024-27488CriApr 8, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate…