VYPR

CVEs

38,096 total · page 324 of 762

  • CVE-2024-31004CriApr 2, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.

  • CVE-2024-31002CriApr 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.

  • CVE-2024-29276CriApr 2, 2024
    risk 0.66cvss 9.8epss 0.33

    An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess method in WorkFlowDesignerController.class component.

  • CVE-2024-26665CriApr 2, 2024
    risk 0.59cvss 9.1epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: tunnels: fix out of bounds access when building IPv6 PMTU error If the ICMPv6 error is built from a non-linear skb we get the following splat, BUG: KASAN: slab-out-of-bounds in do_csum+0x220/0x240 Read of…

  • CVE-2024-1863CriApr 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Sante PACS Server Token Endpoint SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2023-51573CriApr 1, 2024
    risk 0.67cvss 9.8epss 0.46

    Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Voltronic Power ViewPower Pro. Authentication is not required to…

  • CVE-2023-51572CriApr 1, 2024
    risk 0.67cvss 9.8epss 0.38

    Voltronic Power ViewPower Pro getMacAddressByIp Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower Pro. Authentication is not required to exploit this…

  • CVE-2023-51570CriApr 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Voltronic Power ViewPower Pro Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic Power ViewPower Pro. Authentication is not required to exploit this…

  • CVE-2024-29433CriApr 1, 2024
    risk 0.64cvss 9.8epss 0.01

    A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data.

  • CVE-2024-30867CriApr 1, 2024
    risk 0.64cvss 9.8epss 0.01

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_virtual_site_info.php.

  • CVE-2024-30858CriApr 1, 2024
    risk 0.64cvss 9.8epss 0.01

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php.

  • CVE-2024-30865CriApr 1, 2024
    risk 0.64cvss 9.8epss 0.01

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_user_login.php.

  • CVE-2024-21473CriApr 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Memory corruption while redirecting log file to any file location with any file name.

  • CVE-2024-30868CriApr 1, 2024
    risk 0.64cvss 9.8epss 0.01

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.

  • CVE-2023-51803CriApr 1, 2024
    risk 0.57cvss 9.8epss 0.01

    LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring.

  • CVE-2024-31115CriMar 31, 2024
    risk 0.65cvss 10.0epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress.This issue affects Chauffeur Taxi Booking System for WordPress: from n/a through 7.2.

  • CVE-2024-31114CriMar 31, 2024
    risk 0.59cvss 9.1epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in biplob018 Shortcode Addons.This issue affects Shortcode Addons: from n/a through 3.2.5.

  • CVE-2023-46808CriMar 31, 2024
    risk 0.65cvss 9.9epss 0.02

    An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. Successful exploitation may lead to execution of commands in the context of non-root user.

  • CVE-2024-2086CriMar 30, 2024
    risk 0.58cvss 10.0epss 0.01

    The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability…

  • CVE-2024-28288CriMar 30, 2024
    risk 0.64cvss 9.8epss 0.01

    Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vulnerability. An attacker can use this vulnerability to log in to the device and disrupt the business of the enterprise.

  • CVE-2024-29667CriMar 29, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote attacker to escalate privileges and obtain sensitive information via the ids parameter.

  • CVE-2024-3094CriMar 29, 2024
    risk 0.65cvss 10.0epss 0.86

    Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify…

  • CVE-2024-31032CriMar 29, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code via the manager/ipping.php component.

  • CVE-2024-29640CriMar 29, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the action_query_qrcode component.

  • CVE-2023-49232CriMar 29, 2024
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to brute-force the password reset PINs of administrative users.

  • CVE-2024-30247CriMar 29, 2024
    risk 0.65cvss 10.0epss 0.02

    NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command injection vulnerability in NextCloudPi allows command execution as the root user via the NextCloudPi web-panel. Due to a security misconfiguration this can be…

  • CVE-2023-49231CriMar 29, 2024
    risk 0.67cvss 9.8epss 0.43

    An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an unauthenticated attacker to receive an administrative API token.

  • CVE-2024-30502CriMar 29, 2024
    risk 0.61cvss 9.3epss 0.02

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.This issue affects WP Travel Engine: from n/a through 5.7.9.

  • CVE-2024-29202CriMar 29, 2024
    risk 0.65cvss 9.9epss 0.06

    JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Celery container runs with…

  • CVE-2024-29201CriMar 29, 2024
    risk 0.65cvss 9.9epss 0.06

    JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Celery container runs with root…

  • CVE-2024-23538CriMar 29, 2024
    risk 0.64cvss 9.9epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue.

  • CVE-2024-30635CriMar 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability located in the funcpara1 parameter in the formSetCfm function.

  • CVE-2024-30510CriMar 29, 2024
    risk 0.65cvss 10.0epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Salon Booking System Salon booking system.This issue affects Salon booking system: from n/a through 9.5.

  • CVE-2024-30500CriMar 29, 2024
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in CubeWP CubeWP – All-in-One Dynamic Content Framework.This issue affects CubeWP – All-in-One Dynamic Content Framework: from n/a through 1.1.12.

  • CVE-2024-30498CriMar 29, 2024
    risk 0.61cvss 9.3epss 0.02

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4.

  • CVE-2024-30490CriMar 29, 2024
    risk 0.61cvss 9.3epss 0.02

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.

  • CVE-2024-30630CriMar 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the time parameter from saveParentControlInfo function.

  • CVE-2024-30628CriMar 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the page parameter from fromAddressNat function.

  • CVE-2024-30622CriMar 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1205 v2.0.0.7(775) has a stack overflow vulnerability in the mitInterface parameter from fromAddressNat function.

  • CVE-2023-6191CriMar 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egehan Security WebPDKS allows SQL Injection. This issue affects WebPDKS: through 20240329. NOTE: The vendor was contacted early about this disclosure but did not respond in…

  • CVE-2024-2411CriMar 29, 2024
    risk 0.57cvss 9.8epss 0.02

    The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the 'modal' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution…

  • CVE-2024-2409CriMar 29, 2024
    risk 0.57cvss 9.8epss 0.01

    The MasterStudy LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.1. This is due to insufficient validation checks within the _register_user() function called by the 'wp_ajax_nopriv_stm_lms_register' AJAX action. This makes…

  • CVE-2023-50969CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Thales Imperva SecureSphere WAF 14.7.0.40 allows remote attackers to bypass WAF rules via a crafted POST request, a different vulnerability than CVE-2021-45468.

  • CVE-2024-28713CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Mblog Blog system v.3.5.0 allows an attacker to execute arbitrary code via a crafted file to the theme management feature.

  • CVE-2024-30602CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.

  • CVE-2024-30589CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability in the entrys parameter of the fromAddressNat function.

  • CVE-2024-30587CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.

  • CVE-2024-30584CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.

  • CVE-2023-6437CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TP-Link TP-Link EX20v AX1800, Tp-Link Archer C5v AC1200, Tp-Link TD-W9970, Tp-Link TD-W9970v3, TP-Link VX220-G2u, TP-Link VN020-G2u allows authenticated OS Command…

  • CVE-2024-30596CriMar 28, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the formSetDeviceName function.