VYPR

CVEs

38,098 total · page 342 of 762

  • CVE-2023-51154CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.

  • CVE-2023-50867CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the signupAction.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-50866CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginAction.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-50865CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'city' parameter of the hotelSearch.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-50864CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelId' parameter of the hotelDetails.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-50863CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the generateReceipt.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-50862CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the booking.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-50753CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the user/update_profile.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-50752CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'e' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-50743CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the registration.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49666CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'custmer_details' parameter of the submit_material_list.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49665CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'quantity[]' parameter of the submit_delivery_list.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49658CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'bank_details' parameter of the party_submit.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49639CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'customer_details' parameter of the buyer_invoice_submit.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49633CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'buyer_address' parameter of the buyer_detail_submit.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49625CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partylist_edit_submit.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49624CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter of the material_bill.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49622CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'itemnameid' parameter of the material_bill.php?action=itemRelation resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49442CriJan 3, 2024
    risk 0.67cvss 9.8epss 0.39

    Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.

  • CVE-2023-50090CriJan 3, 2024
    risk 0.64cvss 9.8epss 0.01

    Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request.

  • CVE-2023-50253CriJan 3, 2024
    risk 0.00cvss 9.6epss 0.01

    Laf is a cloud development platform. In the Laf version design, the log uses communication with k8s to quickly retrieve logs from the container without the need for additional storage. However, in version 1.0.0-beta.13 and prior, this interface does not verify the permissions of…

  • CVE-2023-39655CriJan 3, 2024
    risk 0.62cvss 9.6epss 0.01

    A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an…

  • CVE-2023-51784CriJan 3, 2024
    risk 0.57cvss 9.8epss 0.02

    Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.10.0 or cherry-pick [1] to solve it.…

  • CVE-2023-52314CriJan 3, 2024
    risk 0.55cvss 9.6epss 0.01

    PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbitrary commands on the operating system.

  • CVE-2023-52311CriJan 3, 2024
    risk 0.55cvss 9.6epss 0.01

    PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary commands on the operating system.

  • CVE-2023-52310CriJan 3, 2024
    risk 0.55cvss 9.6epss 0.01

    PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the operating system.

  • CVE-2023-50921CriJan 3, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7,…

  • CVE-2023-46308CriJan 3, 2024
    risk 0.57cvss 9.8epss 0.01

    In Plotly plotly.js before 2.25.2, plot API calls have a risk of __proto__ being polluted in expandObjectPaths or nestedProperty.

  • CVE-2023-48418CriJan 2, 2024
    risk 0.65cvss 10.0epss 0.00

    In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a     possible way to access adb before SUW completion due to an insecure default     value. This could lead to local escalation of privilege with no additional     execution privileges needed. User…

  • CVE-2023-6339CriJan 2, 2024
    risk 0.65cvss 10.0epss 0.00

    Google Nest WiFi Pro root code-execution & user-data compromise

  • CVE-2024-21623CriJan 2, 2024
    risk 0.00cvss 9.8epss 0.01

    OTCLient is an alternative tibia client for otserv. Prior to commit db560de0b56476c87a2f967466407939196dd254, the /mehah/otclient "`Analysis - SonarCloud`" workflow is vulnerable to an expression injection in Actions, allowing an attacker to run commands remotely on the runner,…

  • CVE-2023-47458CriJan 2, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.

  • CVE-2023-48419CriJan 2, 2024
    risk 0.65cvss 10.0epss 0.00

    An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege 

  • CVE-2023-4280CriJan 2, 2024
    risk 0.60cvss 9.3epss 0.00

    An unvalidated input in Silicon Labs TrustZone implementation in v4.3.x and earlier of the Gecko SDK allows an attacker to access the trusted region of memory from the untrusted region.

  • CVE-2023-6436CriJan 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ekol Informatics Website Template allows SQL Injection. This issue affects Website Template: through 20231215.

  • CVE-2023-33032CriJan 2, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in TZ Secure OS while requesting a memory allocation from TA region.

  • CVE-2023-33030CriJan 2, 2024
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in HLOS while running playready use-case.

  • CVE-2023-33025CriJan 2, 2024
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.

  • CVE-2023-32874CriJan 2, 2024
    risk 0.64cvss 9.8epss 0.01

    In Modem IMS Stack, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161803; Issue ID: MOLY01161803…

  • CVE-2023-5877CriJan 1, 2024
    risk 0.64cvss 9.8epss 0.01

    The affiliate-toolkit WordPress plugin before 3.4.3 lacks authorization and authentication for requests to it's affiliate-toolkit-starter/tools/atkp_imagereceiver.php endpoint, allowing unauthenticated visitors to make requests to arbitrary URL's, including RFC1918 private…

  • CVE-2023-51469CriDec 31, 2023
    risk 0.60cvss 9.3epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestres do WP Checkout Mestres WP.This issue affects Checkout Mestres WP: from n/a through 7.1.9.6.

  • CVE-2023-51423CriDec 31, 2023
    risk 0.60cvss 9.3epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create…

  • CVE-2023-49777CriDec 31, 2023
    risk 0.59cvss 9.1epss 0.01

    Deserialization of Untrusted Data vulnerability in YITH YITH WooCommerce Product Add-Ons.This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.3.0.

  • CVE-2023-52182CriDec 31, 2023
    risk 0.64cvss 9.9epss 0.01

    Deserialization of Untrusted Data vulnerability in ARI Soft ARI Stream Quiz – WordPress Quizzes Builder.This issue affects ARI Stream Quiz – WordPress Quizzes Builder: from n/a through 1.3.0.

  • CVE-2023-52181CriDec 31, 2023
    risk 0.65cvss 10.0epss 0.01

    Deserialization of Untrusted Data vulnerability in Presslabs Theme per user.This issue affects Theme per user: from n/a through 1.0.1.

  • CVE-2023-39157CriDec 31, 2023
    risk 0.59cvss 9.0epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.10.

  • CVE-2023-52262CriDec 30, 2023
    risk 0.00cvss 9.8epss 0.01

    outdoorbits little-backup-box (aka Little Backup Box) before f39f91c allows remote attackers to execute arbitrary code because the PHP extract function is used for untrusted input.

  • CVE-2023-50651CriDec 30, 2023
    risk 0.64cvss 9.8epss 0.03

    TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.

  • CVE-2023-50589CriDec 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Grupo Embras GEOSIAP ERP v2.2.167.02 was discovered to contain a SQL injection vulnerability via the codLogin parameter on the login page.

  • CVE-2023-51136CriDec 30, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formRebootSchedule.