VYPR

CVEs

38,096 total · page 328 of 762

  • CVE-2024-28175CriMar 13, 2024
    risk 0.52cvss 9.0epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to the improper URL protocols filtering of links specified in the `link.argocd.argoproj.io` annotations in the application summary component, an attacker can achieve cross-site scripting with elevated…

  • CVE-2024-27102CriMar 13, 2024
    risk 0.57cvss 9.9epss 0.01

    Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can potentially be used to access files and directories on the host system. The full scope of impact is exactly unknown, but…

  • CVE-2024-25250CriMar 13, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page.

  • CVE-2023-41505CriMar 13, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-28194CriMar 13, 2024
    risk 0.59cvss 9.1epss 0.01

    your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.8.0 use a hardcoded JSON Web Token (JWT) secret to sign authentication tokens. Attackers can use this well-known value to forge valid authentication tokens for arbitrary users. This…

  • CVE-2024-0799CriMar 13, 2024
    risk 0.64cvss 9.8epss 0.04

    An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.

  • CVE-2024-2172CriMar 13, 2024
    risk 0.64cvss 9.8epss 0.02

    The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability check on the mo_wpns_init() function in all versions up to, and including, 4.7.2 (for Malware Scanner) and…

  • CVE-2024-1071CriMar 13, 2024
    risk 0.74cvss 9.8epss 0.89

    The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the user supplied…

  • CVE-2023-6825CriMar 13, 2024
    risk 0.65cvss 9.9epss 0.06

    The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager_action_callback_shortcode function.…

  • CVE-2024-25153CriMar 13, 2024
    risk 0.67cvss 9.8epss 0.42

    A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s…

  • CVE-2024-2413CriMar 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Intumit SmartRobot uses a fixed encryption key for authentication. Remote attackers can use this key to encrypt a string composed of the user's name and timestamp to generate an authentication code. With this authentication code, they can obtain administrator privileges and…

  • CVE-2024-24101CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.00

    Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.

  • CVE-2024-24093CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information.

  • CVE-2024-21400CriMar 12, 2024
    risk 0.59cvss 9.0epss 0.02

    Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

  • CVE-2024-21334CriMar 12, 2024
    risk 0.65cvss 9.8epss 0.20

    Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

  • CVE-2024-1527CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the security measures of the upload functionality and potentially create a remote execution of commands via webshell.

  • CVE-2024-1301CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in Badger Meter Monitool affecting versions 4.6.3 and earlier. A remote attacker could send a specially crafted SQL query to the server via the j_username parameter and retrieve the information stored in the database.

  • CVE-2023-48788CriKEVMar 12, 2024
    risk 0.93cvss 9.8epss 0.98

    A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

  • CVE-2023-47534CriMar 12, 2024
    risk 0.62cvss 9.6epss 0.01

    A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or commands via specially crafted…

  • CVE-2023-42789CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.03

    A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiProxy 7.0.0 through 7.0.12,…

  • CVE-2024-28553CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function.

  • CVE-2024-28535CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function.

  • CVE-2024-22039CriMar 12, 2024
    risk 0.65cvss 10.0epss 0.01

    A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions < IP8), Cerberus PRO EN Fire Panel FC72x IP6 (All versions < IP6 SR3), Cerberus PRO EN Fire Panel FC72x IP7 (All versions < IP7 SR5), Cerberus PRO EN X200 Cloud Distribution IP7 (All versions <…

  • CVE-2023-41313CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.01

    The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 + or 1.2.8, which fixes this issue.

  • CVE-2022-32257CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that lacks proper access control for some of the endpoints. This could lead to unauthorized access to resources and potentially lead to…

  • CVE-2024-25995CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation.

  • CVE-2024-25331CriMar 12, 2024
    risk 0.60cvss 9.3epss 0.00

    DIR-822 Rev. B Firmware v2.02KRB09 and DIR-822-CA Rev. B Firmware v2.03WWb01 suffer from a LAN-Side Unauthenticated Remote Code Execution (RCE) vulnerability elevated from HNAP Stack-Based Buffer Overflow.

  • CVE-2024-22127CriMar 12, 2024
    risk 0.59cvss 9.1epss 0.02

    SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the attacker to run commands which can cause…

  • CVE-2023-49785CriMar 12, 2024
    risk 0.66cvss 9.1epss 0.83

    NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to server-side request forgery and cross-site scripting. This vulnerability enables read access to internal HTTP endpoints but also…

  • CVE-2024-27228CriMar 11, 2024
    risk 0.64cvss 9.8epss 0.01

    there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-27227CriMar 11, 2024
    risk 0.64cvss 9.8epss 0.00

    A malicious DNS response can trigger a number of OOB reads, writes, and other memory issues

  • CVE-2024-27207CriMar 11, 2024
    risk 0.59cvss 9.1epss 0.00

    Exported broadcast receivers allowing malicious apps to bypass broadcast protection.

  • CVE-2024-0039CriMar 11, 2024
    risk 0.64cvss 9.8epss 0.02

    In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-2184CriMar 11, 2024
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*:Satera MF740C…

  • CVE-2023-46427CriMar 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information via null pointer deference in gf_dash_setup_period component in…

  • CVE-2023-49340CriMar 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control in the web management portal.

  • CVE-2024-21899CriMar 8, 2024
    risk 0.66cvss 9.8epss 0.24

    An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security of the system via a network. We have already fixed the vulnerability in the following…

  • CVE-2024-25849CriMar 8, 2024
    risk 0.64cvss 9.8epss 0.01

    In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` .

  • CVE-2024-25845CriMar 8, 2024
    risk 0.64cvss 9.8epss 0.01

    In the module "CD Custom Fields 4 Orders" (cdcustomfields4orders) <= 1.0.0 from Cleanpresta.com for PrestaShop, a guest can perform SQL injection in affected versions.

  • CVE-2024-2044CriMar 7, 2024
    risk 0.67cvss 9.9epss 0.79

    pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server…

  • CVE-2024-0818CriMar 7, 2024
    risk 0.52cvss 9.1epss 0.01

    Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6

  • CVE-2024-0917CriMar 7, 2024
    risk 0.64cvss 9.8epss 0.02

    remote code execution in paddlepaddle/paddle 2.6.0

  • CVE-2023-42662CriMar 7, 2024
    risk 0.60cvss 9.3epss 0.00

    JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could lead to exposure of user access tokens due to improper handling of the CLI / IDE browser based SSO…

  • CVE-2023-41503CriMar 7, 2024
    risk 0.64cvss 9.8epss 0.01

    Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.

  • CVE-2023-41014CriMar 7, 2024
    risk 0.64cvss 9.8epss 0.01

    code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer."

  • CVE-2024-28222CriMar 7, 2024
    risk 0.64cvss 9.8epss 0.01

    In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.

  • CVE-2024-28213CriMar 7, 2024
    risk 0.57cvss 9.8epss 0.01

    nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization.

  • CVE-2024-28212CriMar 7, 2024
    risk 0.64cvss 9.8epss 0.01

    nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.

  • CVE-2024-28211CriMar 7, 2024
    risk 0.64cvss 9.8epss 0.01

    nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI registry by remote attacker.

  • CVE-2024-22857CriMar 7, 2024
    risk 0.64cvss 9.8epss 0.02

    Heap based buffer flow in zlog v1.1.0 to v1.2.17 in zlog_rule_new().The size of record_name is MAXLEN_PATH(1024) + 1 but file_path may have data upto MAXLEN_CFG_LINE(MAXLEN_PATH*4) + 1. So a check was missing in zlog_rule_new() while copying the record_name from file_path + 1…