VYPR

CVEs

38,096 total · page 323 of 762

  • CVE-2024-27488CriApr 8, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the http API interface by default and uses the secret parameter method to authenticate…

  • CVE-2024-31345CriApr 7, 2024
    risk 0.59cvss 9.1epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Poster: from n/a through 1.2.

  • CVE-2024-31286CriApr 7, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.

  • CVE-2024-31280CriApr 7, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.5.

  • CVE-2024-30415CriApr 7, 2024
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-25029CriApr 6, 2024
    risk 0.59cvss 9.0epss 0.01

    IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). The vulnerability allows any unprivileged user with network access to a target computer to run commands with full…

  • CVE-2024-29756CriApr 5, 2024
    risk 0.64cvss 9.8epss 0.00

    In afe_callback of q6afe.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-31849CriApr 5, 2024
    risk 0.64cvss 9.8epss 0.06

    A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.

  • CVE-2024-31848CriApr 5, 2024
    risk 0.64cvss 9.8epss 0.08

    A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.

  • CVE-2024-22004CriApr 5, 2024
    risk 0.65cvss 10.0epss 0.00

    Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from the Trusted Application

  • CVE-2023-48426CriApr 5, 2024
    risk 0.65cvss 10.0epss 0.00

    u-boot bug that allows for u-boot shell and interrupt over UART

  • CVE-2024-31218CriApr 5, 2024
    risk 0.57cvss 9.8epss 0.01

    Webhood is a self-hosted URL scanner used analyzing phishing and malicious sites. Webhood's backend container images in versions 0.9.0 and earlier are subject to Missing Authentication for Critical Function vulnerability. This vulnerability allows an unauthenticated attacker to…

  • CVE-2024-30849CriApr 5, 2024
    risk 0.64cvss 9.8epss 0.01

    Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via filename parameter in admin/products_photo.php.

  • CVE-2024-27448CriApr 5, 2024
    risk 0.59cvss 9.1epss 0.01

    MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to lib/mailserver.js writing arbitrary code into the routes.js file.

  • CVE-2024-27981CriApr 4, 2024
    risk 0.64cvss 9.8epss 0.01

    A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with UniFi Network Application Administrator credentials to escalate privileges to root on the host…

  • CVE-2024-21894CriApr 4, 2024
    risk 0.65cvss 9.8epss 0.19

    A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack. In certain conditions this may…

  • CVE-2024-25693CriApr 4, 2024
    risk 0.64cvss 9.9epss 0.01

    There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file system to access files or execute code outside of the intended directory. 

  • CVE-2024-26800CriApr 4, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: tls: fix use-after-free on failed backlog decryption When the decrypt request goes to the backlog and crypto_aead_decrypt returns -EBUSY, tls_do_decryption will wait until all async decryptions have completed.…

  • CVE-2024-26782CriApr 4, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: mptcp: fix double-free on socket dismantle when MPTCP server accepts an incoming connection, it clones its listener socket. However, the pointer to 'inet_opt' for the new socket has the same value as the…

  • CVE-2023-36645CriApr 4, 2024
    risk 0.59cvss 9.1epss 0.01

    SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer function.

  • CVE-2024-29006CriApr 4, 2024
    risk 0.64cvss 9.8epss 0.01

    By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead to authentication bypass and other operational problems should an attacker decide to spoof their IP address this way. Users are…

  • CVE-2024-29375CriApr 4, 2024
    risk 0.64cvss 9.8epss 0.01

    CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to the Project Description, Identifiers, Custom Triangle Name (inside Input Triangles) and Yield Curve Name parameters.

  • CVE-2024-2692CriApr 4, 2024
    risk 0.59cvss 9.0epss 0.01

    SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS.

  • CVE-2024-3272CriKEVApr 4, 2024
    risk 0.84cvss 9.8epss 0.98

    ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. This issue affects some unknown processing of the file /cgi-bin/nas_sharing.cgi of the component HTTP GET…

  • CVE-2024-26760CriApr 3, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: scsi: target: pscsi: Fix bio_put() for error case As of commit 066ff571011d ("block: turn bio_kmalloc into a simple kmalloc wrapper"), a bio allocated by bio_kmalloc() must be freed by bio_uninit() and…

  • CVE-2023-44039CriApr 3, 2024
    risk 0.59cvss 9.1epss 0.01

    In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowed to enroll a FIDO key) to register their FIDO authenticator to a victim’s account and consequently take over the account.

  • CVE-2024-30568CriApr 3, 2024
    risk 0.67cvss 9.8epss 0.47

    Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.

  • CVE-2024-25096CriApr 3, 2024
    risk 0.65cvss 10.0epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a through 3.0.7.

  • CVE-2024-24707CriApr 3, 2024
    risk 0.64cvss 9.9epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Injection.This issue affects Cwicly: from n/a through 1.4.0.2.

  • CVE-2023-25699CriApr 3, 2024
    risk 0.59cvss 9.0epss 0.01

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper.Com VideoWhisper Live Streaming Integration allows OS Command Injection.This issue affects VideoWhisper Live Streaming Integration: from n/a through 5.5.15.

  • CVE-2024-31390CriApr 3, 2024
    risk 0.64cvss 9.9epss 0.01

    : Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.

  • CVE-2024-31380CriApr 3, 2024
    risk 0.64cvss 9.9epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, refuses to patch the issue.This issue affects Oxygen Builder: from n/a through 4.9.

  • CVE-2024-27972CriApr 3, 2024
    risk 0.64cvss 9.9epss 0.02

    Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.This issue affects WP Fusion Lite: from n/a through <= 3.41.24.

  • CVE-2024-27951CriApr 3, 2024
    risk 0.59cvss 9.1epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows Upload a Web Shell to a Web Server.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.

  • CVE-2024-25918CriApr 3, 2024
    risk 0.64cvss 9.9epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.

  • CVE-2024-28515CriApr 3, 2024
    risk 0.64cvss 9.8epss 0.02

    Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary code via the lab3 of csapp,lab3/buflab-update.pl component.

  • CVE-2024-30998CriApr 3, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via the email parameter in the index.php component.

  • CVE-2021-27312CriApr 3, 2024
    risk 0.61cvss 9.4epss 0.01

    Server Side Request Forgery (SSRF) vulnerability in Gleez Cms 1.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via modules/gleez/classes/request.php.

  • CVE-2024-31011CriApr 3, 2024
    risk 0.64cvss 9.8epss 0.01

    Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolated and the suffix was not verified in admin_template.php.

  • CVE-2024-31012CriApr 3, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file.

  • CVE-2024-2879CriApr 3, 2024
    risk 0.65cvss 9.8epss 0.18

    The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…

  • CVE-2024-30166CriApr 3, 2024
    risk 0.59cvss 9.1epss 0.01

    In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack buffer over-read (of less than 256 bytes) in a TLS 1.3 server via a TLS 3.1 ClientHello.

  • CVE-2024-25864CriApr 3, 2024
    risk 0.59cvss 9.1epss 0.01

    Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the fpostit.php component.

  • CVE-2024-24724CriApr 3, 2024
    risk 0.69cvss 9.8epss 0.26

    Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.

  • CVE-2024-29432CriApr 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/datas.

  • CVE-2024-27604CriApr 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Alldata V0.4.6 is vulnerable to Command execution vulnerability. System commands can be deserialized.

  • CVE-2024-27602CriApr 2, 2024
    risk 0.59cvss 9.1epss 0.00

    Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.For example, the /api/system/v2/api-docs module.

  • CVE-2024-30621CriApr 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.

  • CVE-2024-30620CriApr 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.

  • CVE-2024-2389CriApr 2, 2024
    risk 0.76cvss 10.0epss 0.93

    In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.