VYPR

CVEs

38,096 total · page 329 of 762

  • CVE-2023-51786CriMar 7, 2024
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privileges and obtain sensitive information via Incorrect Access Control.

  • CVE-2023-49989CriMar 7, 2024
    risk 0.64cvss 9.8epss 0.01

    Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php.

  • CVE-2024-27307CriMar 6, 2024
    risk 0.57cvss 9.8epss 0.01

    JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. This may lead to denial of service, remote…

  • CVE-2024-27304CriMar 6, 2024
    risk 0.57cvss 9.8epss 0.01

    pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the…

  • CVE-2024-27302CriMar 6, 2024
    risk 0.52cvss 9.1epss 0.01

    go-zero is a web and rpc framework. Go-zero allows user to specify a CORS Filter with a configurable allows param - which is an array of domains allowed in CORS policy. However, the `isOriginAllowed` uses `strings.HasSuffix` to check the origin, which leads to bypass via a…

  • CVE-2024-24767CriMar 6, 2024
    risk 0.52cvss 9.1epss 0.01

    CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, CasaOS doesn't defend against password brute force attacks, which leads to having full access to the server. The web application lacks control over the…

  • CVE-2023-50716CriMar 6, 2024
    risk 0.62cvss 9.6epss 0.01

    eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.13.0, 2.12.2, 2.11.3, 2.10.3, and 2.6.7, an invalid DATA_FRAG Submessage causes a bad-free error, and the Fast-DDS process…

  • CVE-2024-2005CriMar 6, 2024
    risk 0.59cvss 9.0epss 0.00

    In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected. Blue Planet® has released software updates that address this vulnerability for the affected products.…

  • CVE-2024-26580CriMar 6, 2024
    risk 0.52cvss 9.1epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can use the specific payload to read from an arbitrary file. Users are advised to upgrade to Apache InLong's 1.11.0 or cherry-pick [1] to…

  • CVE-2023-38945CriMar 6, 2024
    risk 0.64cvss 9.8epss 0.01

    Multilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Multilaser RE163V v12.03.01.08_pt allows attackers to bypass the access control and gain complete access to the application via supplying a crafted URL.

  • CVE-2023-38944CriMar 6, 2024
    risk 0.65cvss 9.8epss 0.16

    An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers to bypass the access control and gain complete access to the application via modifying a HTTP header.

  • CVE-2024-27764CriMar 5, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.

  • CVE-2024-24276CriMar 5, 2024
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the chat name, message preview, username and group name components.

  • CVE-2024-24275CriMar 5, 2024
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the global search function.

  • CVE-2024-2056CriMar 5, 2024
    risk 0.65cvss 9.8epss 0.17

    Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service is running, running as the root user, is bound to the loopback interface, and is listening on TCP port 7050. Security…

  • CVE-2024-2055CriMar 5, 2024
    risk 0.64cvss 9.8epss 0.01

    The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication by default, and runs as the root user.

  • CVE-2024-22253CriMar 5, 2024
    risk 0.61cvss 9.3epss 0.01

    VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.…

  • CVE-2024-22252CriMar 5, 2024
    risk 0.61cvss 9.3epss 0.04

    VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.…

  • CVE-2024-27565CriMar 5, 2024
    risk 0.64cvss 9.8epss 0.01

    A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force the application to make arbitrary requests.

  • CVE-2023-7103CriMar 5, 2024
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass by Primary Weakness vulnerability in ZKSoftware Biometric Security Solutions UFace 5 allows Authentication Bypass. This issue affects UFace 5: through 12022024.

  • CVE-2024-26339CriMar 5, 2024
    risk 0.59cvss 9.1epss 0.01

    swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a.

  • CVE-2024-21815CriMar 5, 2024
    risk 0.59cvss 9.1epss 0.00

    Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751…

  • CVE-2023-49970CriMar 5, 2024
    risk 0.64cvss 9.8epss 0.01

    Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket.

  • CVE-2023-49547CriMar 5, 2024
    risk 0.64cvss 9.8epss 0.01

    Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login.

  • CVE-2021-47107CriMar 4, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix READDIR buffer overflow If a client sends a READDIR count argument that is too small (say, zero), then the buffer size calculation in the new init_dirlist helper functions results in an underflow,…

  • CVE-2024-27198CriKEVMar 4, 2024
    risk 0.93cvss 9.8epss 1.00

    In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

  • CVE-2021-47103CriMar 4, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: inet: fully convert sk->sk_rx_dst to RCU rules syzbot reported various issues around early demux, one being included in this changelog [1] sk->sk_rx_dst is using RCU protection without clearly documenting it.…

  • CVE-2023-43553CriMar 4, 2024
    risk 0.64cvss 9.8epss 0.00

    Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.

  • CVE-2023-43552CriMar 4, 2024
    risk 0.64cvss 9.8epss 0.00

    Memory corruption while processing MBSSID beacon containing several subelement IE.

  • CVE-2023-28582CriMar 4, 2024
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in Data Modem while verifying hello-verify message during the DTLS handshake.

  • CVE-2023-28578CriMar 4, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Core Services while executing the command for removing a single event listener.

  • CVE-2024-20018CriMar 4, 2024
    risk 0.64cvss 9.8epss 0.01

    In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00348479; Issue ID: MSV-1019.

  • CVE-2024-20017CriMar 4, 2024
    risk 0.67cvss 9.8epss 0.47

    In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation Patch ID: WCNCR00350938; Issue ID: MSV-1132.

  • CVE-2024-25847CriMar 3, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain sensitive information via Send::__construct() and…

  • CVE-2024-24302CriMar 3, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the postProcess() method.

  • CVE-2023-52515CriMar 2, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: Do not call scsi_done() from srp_abort() After scmd_eh_abort_handler() has called the SCSI LLD eh_abort_handler callback, it performs one of the following actions: * Call scsi_queue_insert(). * Call…

  • CVE-2024-27747CriMar 1, 2024
    risk 0.69cvss 9.8epss 0.24

    File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component.

  • CVE-2024-27746CriMar 1, 2024
    risk 0.68cvss 9.8epss 0.13

    SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component.

  • CVE-2023-49543CriMar 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions without authenticating.

  • CVE-2024-21767CriMar 1, 2024
    risk 0.61cvss 9.4epss 0.01

    A remote attacker may be able to bypass access control of Commend WS203VICM by creating a malicious request.

  • CVE-2023-7244CriMar 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds write in their primary analyses function for Ethercat communication packets. This could allow an attacker to cause arbitrary code…

  • CVE-2023-7243CriMar 1, 2024
    risk 0.64cvss 9.8epss 0.01

    Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds write while analyzing specific Ethercat datagrams. This could allow an attacker to cause arbitrary code execution.

  • CVE-2024-27298CriMar 1, 2024
    risk 0.58cvss 10.0epss 0.01

    parse-server is a Parse Server for Node.js / Express. This vulnerability allows SQL injection when Parse Server is configured to use the PostgreSQL database. The vulnerability has been fixed in 6.5.0 and 7.0.0-alpha.20.

  • CVE-2024-1624CriMar 1, 2024
    risk 0.61cvss 9.4epss 0.02

    An OS Command Injection vulnerability affecting documentation server on 3DEXPERIENCE from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x, SIMULIA Abaqus from Release 2022 through Release 2024, SIMULIA Isight from Release 2022 through Release 2024 and CATIA…

  • CVE-2024-25091CriMar 1, 2024
    risk 0.59cvss 9.1epss 0.00

    Protection mechanism failure issue exists in RevoWorks SCVX prior to scvimage4.10.21_1013 (when using 'VirusChecker' or 'ThreatChecker' feature) and RevoWorks Browser prior to 2.2.95 (when using 'VirusChecker' or 'ThreatChecker' feature). If data containing malware is saved in…

  • CVE-2024-25293CriMar 1, 2024
    risk 0.61cvss 9.3epss 0.01

    mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.

  • CVE-2024-22891CriMar 1, 2024
    risk 0.64cvss 9.8epss 0.02

    Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.

  • CVE-2024-26548CriFeb 29, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in vivotek Network Camera v.FD8166A-VVTK-0204j allows a remote attacker to execute arbitrary code via a crafted payload to the upload_file.cgi component.

  • CVE-2024-25180CriFeb 29, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after installing a test…

  • CVE-2024-0864CriFeb 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) attack via an improper input validation in a file_upload.php file which serves as an example. By default, Laragon is not vulnerable until a user decides to use…