VYPR

CVEs

38,096 total · page 333 of 762

  • CVE-2024-20720CriFeb 15, 2024
    risk 0.59cvss 9.1epss 0.04

    Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue…

  • CVE-2024-20719CriFeb 15, 2024
    risk 0.59cvss 9.1epss 0.01

    Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker to inject malicious scripts into every admin page. Malicious JavaScript may be executed in a victim’s…

  • CVE-2024-20738CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass authentication mechanisms and gain unauthorized access.…

  • CVE-2023-39245CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.01

    DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit this vulnerability by eavesdropping the network traffic to gain admin level…

  • CVE-2023-32484CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input validation vulnerability. A remote unauthenticated malicious user may exploit this vulnerability and escalate privileges up to the highest administrative level.…

  • CVE-2023-32462CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.02

    Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands and…

  • CVE-2023-28078CriFeb 15, 2024
    risk 0.59cvss 9.1epss 0.01

    Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible Denial of Service when a huge…

  • CVE-2024-0390CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.00

    INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability could potentially allow unauthorized access to manage and read parameters of the…

  • CVE-2022-23088CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.04

    The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a FreeBSD Wi-Fi client is in scanning mode (i.e., not associated with a SSID) a malicious beacon frame may overwrite kernel memory,…

  • CVE-2024-26264CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.01

    EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers to inject SQL commands without authentication, enabling them to read, modify, and delete database…

  • CVE-2024-26261CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.01

    The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted…

  • CVE-2024-26260CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.02

    The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without…

  • CVE-2024-24300CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs in, the content of the cookie remains unchanged.

  • CVE-2024-25223CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder.php.

  • CVE-2024-25222CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php.

  • CVE-2024-25220CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/EditTask.php.

  • CVE-2024-25217CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product.

  • CVE-2024-25216CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php.

  • CVE-2024-25215CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.

  • CVE-2024-25214CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and Password parameters at /alogin.html.

  • CVE-2024-25211CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.php.

  • CVE-2024-25210CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.php.

  • CVE-2024-25209CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php.

  • CVE-2023-6441CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UNI-PA University Marketing & Computer Internet Trade Inc. University Information System allows SQL Injection. This issue affects University Information System: before…

  • CVE-2024-23786CriFeb 14, 2024
    risk 0.61cvss 9.3epss 0.01

    Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the management page…

  • CVE-2024-24691CriFeb 14, 2024
    risk 0.63cvss 9.6epss 0.02

    Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access.

  • CVE-2024-24142CriFeb 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.

  • CVE-2024-1378CriFeb 13, 2024
    risk 0.59cvss 9.1epss 0.02

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring SMTP options. Exploitation of this vulnerability…

  • CVE-2024-1374CriFeb 13, 2024
    risk 0.59cvss 9.1epss 0.03

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring audit log forwarding. Exploitation of this…

  • CVE-2024-1372CriFeb 13, 2024
    risk 0.59cvss 9.1epss 0.02

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when configuring SAML settings. Exploitation of this vulnerability required access to the…

  • CVE-2024-1369CriFeb 13, 2024
    risk 0.59cvss 9.1epss 0.02

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting the username and password for collectd configurations. Exploitation of this…

  • CVE-2024-1359CriFeb 13, 2024
    risk 0.59cvss 9.1epss 0.02

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting up an HTTP proxy. Exploitation of this vulnerability required access to the…

  • CVE-2024-1355CriFeb 13, 2024
    risk 0.59cvss 9.1epss 0.02

    A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the actions-console docker container while setting a service URL. Exploitation of…

  • CVE-2024-21413CriKEVFeb 13, 2024
    risk 0.83cvss 9.8epss 0.95

    Microsoft Outlook Remote Code Execution Vulnerability

  • CVE-2024-21410CriKEVFeb 13, 2024
    risk 0.77cvss 9.8epss 0.13

    Microsoft Exchange Server Elevation of Privilege Vulnerability

  • CVE-2024-21403CriFeb 13, 2024
    risk 0.59cvss 9.0epss 0.01

    Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

  • CVE-2024-21401CriFeb 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability

  • CVE-2024-21376CriFeb 13, 2024
    risk 0.59cvss 9.0epss 0.01

    Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability

  • CVE-2024-21364CriFeb 13, 2024
    risk 0.60cvss 9.3epss 0.01

    Microsoft Azure Site Recovery Elevation of Privilege Vulnerability

  • CVE-2024-22923CriFeb 13, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in adv radius v.2.2.5 allows a local attacker to execute arbitrary code via a crafted script.

  • CVE-2024-23816CriFeb 13, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (All versions < V4.3), Location Intelligence Perpetual Non-Prod (9DE5110-8CA10-1AX0) (All versions…

  • CVE-2022-48623CriFeb 13, 2024
    risk 0.00cvss 9.1epss 0.01

    The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of service.

  • CVE-2024-22131CriFeb 13, 2024
    risk 0.59cvss 9.1epss 0.01

    In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a remote execution authorization can use a vulnerable interface. This allows the attacker to use the interface to invoke an application function…

  • CVE-2023-42374CriFeb 13, 2024
    risk 0.00cvss 9.8epss 0.01

    An issue in mystenlabs Sui Blockchain before v.1.6.3 allow a remote attacker to execute arbitrary code and cause a denial of service via a crafted compressed script to the Sui node component.

  • CVE-2024-23763CriFeb 12, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET request using modifiers[attribute][] parameter.

  • CVE-2024-23761CriFeb 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template.

  • CVE-2024-23759CriFeb 12, 2024
    risk 0.71cvss 9.8epss 0.48

    Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.

  • CVE-2024-25110CriFeb 12, 2024
    risk 0.01cvss 9.8epss 0.07

    The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication it may cause a remote code execution. Users are advised to…

  • CVE-2024-25108CriFeb 12, 2024
    risk 0.57cvss 9.9epss 0.01

    Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than users intended, including to the administrative and moderator functionality of the…

  • CVE-2023-6036CriFeb 12, 2024
    risk 0.64cvss 9.8epss 0.02

    The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and 'hadle_login_request'. This makes it possible for non authenticated attackers to log in as any…