VYPR

CVEs

38,101 total · page 344 of 763

  • CVE-2023-43481CriDec 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote attacker to execute arbitrary JavaScript code via the com.tcl.browser.portal.browse.activity.BrowsePageActivity component.

  • CVE-2023-50255CriDec 27, 2023
    risk 0.00cvss 9.3epss 0.01

    Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerability in deepin-compressor that can be exploited to achieve Remote Command Execution on the target system upon opening crafted archives. Users are advised to…

  • CVE-2023-6190CriDec 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in İzmir Katip Çelebi University University Information Management System allows Absolute Path Traversal. This issue affects University Information Management System: before…

  • CVE-2023-5991CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.03

    The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files on the server

  • CVE-2023-51102CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formWifiMacFilterSet.

  • CVE-2023-51101CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetUplinkInfo.

  • CVE-2023-51100CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formGetDiagnoseInfo .

  • CVE-2023-51099CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formexeCommand .

  • CVE-2023-51098CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a command injection vulnerability via the function formSetDiagnoseInfo .

  • CVE-2023-51097CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W9 V1.0.0.7(4456)_CN was discovered to contain a stack overflow via the function formSetAutoPing.

  • CVE-2023-51094CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet.

  • CVE-2023-51093CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function fromSetLocalVlanInfo.

  • CVE-2023-51092CriDec 26, 2023
    risk 0.65cvss 9.8epss 0.13

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function upgrade.

  • CVE-2023-51091CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.08

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function R7WebsSecurityHandler.

  • CVE-2023-51090CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formGetWeiXinConfig.

  • CVE-2023-51095CriDec 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy.

  • CVE-2023-51467CriDec 26, 2023
    risk 0.74cvss 9.8epss 0.96

    The vulnerability permits attackers to circumvent authentication processes, enabling them to remotely execute arbitrary code

  • CVE-2023-49954CriDec 25, 2023
    risk 0.64cvss 9.8epss 0.02

    The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address.

  • CVE-2023-31224CriDec 25, 2023
    risk 0.64cvss 9.8epss 0.01

    There is broken access control during authentication in Jamf Pro Server before 10.46.1.

  • CVE-2022-34268CriDec 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.

  • CVE-2022-34267CriDec 25, 2023
    risk 0.67cvss 9.8epss 0.42

    An issue was discovered in RWS WorldServer before 11.7.3. Adding a token parameter with the value of 02 bypasses all authentication requirements. Arbitrary Java code can be uploaded and executed via a .jar archive to the ws-api/v2/customizations/api endpoint.

  • CVE-2023-48654CriDec 25, 2023
    risk 0.64cvss 9.8epss 0.01

    One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Directory passwords on the login screen of a Windows client. It launches a Chromium based browser in Kiosk mode to provide the reset functionality. The escape…

  • CVE-2023-51771CriDec 25, 2023
    risk 0.64cvss 9.8epss 0.01

    In MicroHttpServer (aka Micro HTTP Server) through a8ab029, _ParseHeader in lib/server.c allows a one-byte recv buffer overflow via a long URI.

  • CVE-2023-7095CriDec 25, 2023
    risk 0.65cvss 9.8epss 0.14

    A vulnerability, which was classified as critical, has been found in Totolink A7100RU 7.4cu.2313_B20191024. Affected by this issue is the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument flag…

  • CVE-2023-7102CriDec 24, 2023
    risk 0.70cvss 9.8epss 0.45

    Use of a Third Party library produced a vulnerability in Barracuda Networks Inc. Barracuda ESG Appliance which allowed Parameter Injection.This issue affected Barracuda ESG Appliance, from 5.1.3.001 through 9.2.1.001, until Barracuda removed the vulnerable logic.

  • CVE-2023-51714CriDec 24, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check.

  • CVE-2023-51763CriDec 24, 2023
    risk 0.57cvss 9.8epss 0.01

    csv_builder.rb in ActiveAdmin (aka Active Admin) before 3.2.0 allows CSV injection.

  • CVE-2023-6972CriDec 23, 2023
    risk 0.57cvss 9.8epss 0.01

    The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. This makes it possible for…

  • CVE-2023-50731CriDec 22, 2023
    risk 0.59cvss 9.1epss 0.01

    MindsDB is a SQL Server for artificial intelligence. Prior to version 23.11.4.1, the `put` method in `mindsdb/mindsdb/api/http/namespaces/file.py` does not validate the user-controlled name value, which is used in a temporary file name, which is afterwards opened for writing on…

  • CVE-2023-51035CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution on the cstecgi.cgi NTPSyncWithHost interface.

  • CVE-2023-51034CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi UploadFirmwareFile interface.

  • CVE-2023-51033CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1200L V9.3.5u.6146_B20201023 is vulnerable to arbitrary command execution via the cstecgi.cgi setOpModeCfg interface.

  • CVE-2023-51022CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langFlag’ parameter of the setLanguageCfg interface of the cstecgi .cgi.

  • CVE-2023-51021CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘merge’ parameter of the setRptWizardCfg interface of the cstecgi .cgi.

  • CVE-2023-51020CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langType’ parameter of the setLanguageCfg interface of the cstecgi .cgi.

  • CVE-2023-51019CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘key5g’ parameter of the setWiFiExtenderConfig interface of the cstecgi .cgi.

  • CVE-2023-51018CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘opmode’ parameter of the setWiFiApConfig interface of the cstecgi .cgi.

  • CVE-2023-51017CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanIp parameter’ of the setLanConfig interface of the cstecgi .cgi.

  • CVE-2023-51016CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .cgi.

  • CVE-2023-51015CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINX EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘enable parameter’ of the setDmzCfg interface of the cstecgi .cgi

  • CVE-2023-51014CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanConfig interface of the cstecgi .cgi

  • CVE-2023-51013CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanNetmask parameter’ of the setLanConfig interface of the cstecgi .cgi.

  • CVE-2023-51012CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanGateway parameter’ of the setLanConfig interface of the cstecgi .cgi.

  • CVE-2023-51011CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanPriDns parameter’ of the setLanConfig interface of the cstecgi .cgi

  • CVE-2023-50147CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    There is an arbitrary command execution vulnerability in the setDiagnosisCfg function of the cstecgi .cgi of the TOTOlink A3700R router device in its firmware version V9.1.2u.5822_B20200513.

  • CVE-2023-51028CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK EX1800T 9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the apcliChannel parameter of the setWiFiExtenderConfig interface of the cstecgi.cgi.

  • CVE-2023-51027CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘apcliAuthMode’ parameter of the setWiFiExtenderConfig interface of the cstecgi .cgi.

  • CVE-2023-51026CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootScheCfg interface of the cstecgi .cgi.

  • CVE-2023-51025CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCfg interface of the cstecgi .cgi.

  • CVE-2023-51024CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘tz’ parameter of the setNtpCfg interface of the cstecgi .cgi.