VYPR

CVEs

38,096 total · page 334 of 762

  • CVE-2024-24797CriFeb 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue affects ERE Recently Viewed – Essential Real Estate Add-On: from n/a through 1.3.

  • CVE-2024-25100CriFeb 12, 2024
    risk 0.65cvss 10.0epss 0.01

    Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program allows Object Injection.This issue affects Coupon Referral Program: from n/a before 1.8.4.

  • CVE-2024-25722CriFeb 11, 2024
    risk 0.00cvss 9.8epss 0.01

    qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.

  • CVE-2024-25718CriFeb 11, 2024
    risk 0.57cvss 9.8epss 0.01

    In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry.

  • CVE-2024-25714CriFeb 11, 2024
    risk 0.00cvss 9.8epss 0.01

    In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first difference is spotted in the two signatures. (The fix uses gnutls_memcmp, which has constant-time execution.)

  • CVE-2024-23724CriFeb 11, 2024
    risk 0.59cvss 9.0epss 0.03

    Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profile picture that contains JavaScript code to interact with the API on localhost TCP port 3001. NOTE: The discoverer reports that "The…

  • CVE-2024-25316CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2.

  • CVE-2024-25315CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2.

  • CVE-2024-25314CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.

  • CVE-2024-25307CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1."

  • CVE-2024-25302CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.

  • CVE-2023-6677CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Financial Technology Online Collection allows SQL Injection. This issue affects Online Collection: before v.1.0.2.

  • CVE-2024-25678CriFeb 9, 2024
    risk 0.00cvss 9.8epss 0.00

    In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.

  • CVE-2024-25675CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related to app/Controller/JobsController.php and app/View/Events/export.ctp.

  • CVE-2024-25674CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME type.

  • CVE-2024-21762CriKEVFeb 9, 2024
    risk 0.88cvss 9.8epss 0.83

    A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through…

  • CVE-2024-24308CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, relayPoint.php, and shippingConfirmation.php.

  • CVE-2023-50026CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain sensitive information via the method HsAccessoriesGroupProductAbstract::getAcce…

  • CVE-2023-46350CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and obtain sensitive information via the methods…

  • CVE-2023-46687CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root context from a remote computer.

  • CVE-2024-24825CriFeb 9, 2024
    risk 0.52cvss 9.1epss 0.01

    DIRAC is a distributed resource framework. In affected versions any user could get a token that has been requested by another user/agent. This may expose resources to unintended parties. This issue has been addressed in release version 8.0.37. Users are advised to upgrade. There…

  • CVE-2024-25106CriFeb 8, 2024
    risk 0.59cvss 9.1epss 0.00

    OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulnerability allows any authenticated user…

  • CVE-2024-24830CriFeb 8, 2024
    risk 0.64cvss 9.9epss 0.01

    OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any authenticated regular user ('member') to…

  • CVE-2023-47132CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.

  • CVE-2024-24393CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability index.php in Pichome v.1.1.01 allows a remote attacker to execute arbitrary code via crafted POST request.

  • CVE-2023-40266CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.

  • CVE-2024-24496CriFeb 8, 2024
    risk 0.68cvss 9.8epss 0.20

    An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.

  • CVE-2024-24495CriFeb 8, 2024
    risk 0.67cvss 9.8epss 0.01

    SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request.

  • CVE-2024-22836CriFeb 8, 2024
    risk 0.69cvss 9.8epss 0.30

    An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company locale when installing an app to execute system commands on the hosting server.

  • CVE-2024-24321CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.02

    An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.

  • CVE-2024-24213CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/query. NOTE: the vendor's position is that this is an intended feature; also, it exists in the Supabase dashboard product, not the Supabase PostgreSQL product.…

  • CVE-2023-50061CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    PrestaShop Op'art Easy Redirect >= 1.3.8 and <= 1.3.12 is vulnerable to SQL Injection via Oparteasyredirect::hookActionDispatcher().

  • CVE-2024-25191CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.

  • CVE-2024-25190CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.

  • CVE-2024-25189CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authentication via a timing side channel.

  • CVE-2023-42282CriFeb 8, 2024
    risk 0.57cvss 9.8epss 0.02

    The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

  • CVE-2024-1207CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.03

    The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all versions up to, and including, 9.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…

  • CVE-2024-24216CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/repo/model.php.

  • CVE-2024-24091CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.

  • CVE-2024-24202CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and ZenTao Max v4.10 allows attackers to execute arbitrary code via uploading a crafted .txt file.

  • CVE-2024-24021CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list.

  • CVE-2024-24017CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /common/dict/list

  • CVE-2024-24014CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/author/list

  • CVE-2024-24003CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutMaterialCount() function of jshERP does not filter `column` and `order` parameters well enough, and an attacker can construct malicious payload…

  • CVE-2024-22394CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication.  This issue affects only firmware version SonicOS 7.1.1-7040.

  • CVE-2024-24026CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.

  • CVE-2024-24025CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.

  • CVE-2024-24024CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownload(). An attacker can pass in specially crafted filePath and fieName parameters to perform arbitrary File download.

  • CVE-2024-24023CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/bookContent/list.

  • CVE-2024-24018CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/dataPerm/list