VYPR

CVEs

38,103 total · page 345 of 763

  • CVE-2023-51025CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCfg interface of the cstecgi .cgi.

  • CVE-2023-51024CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘tz’ parameter of the setNtpCfg interface of the cstecgi .cgi.

  • CVE-2023-51023CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘host_time’ parameter of the NTPSyncWithHost interface of the cstecgi .cgi.

  • CVE-2023-50254CriDec 22, 2023
    risk 0.00cvss 9.3epss 0.02

    Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior to 6.0.7 due to a design flaw that leads to remote command execution via crafted docx document. This is a file overwrite vulnerability. Remote code execution…

  • CVE-2022-47532CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    FileRun 20220519 allows SQL Injection via the "dir" parameter in a /?module=users&section=cpanel&page=list request.

  • CVE-2023-51707CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffected.

  • CVE-2023-49689CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'JobId' parameter of the Employer/DeleteJob.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49688CriDec 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txtUser' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49681CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cmbQual' parameter of the Employer/InsertWalkin.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-49677CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cmbQual' parameter of the Employer/InsertJob.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-48722CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_results.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-48720CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-48718CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_name' parameter of the add_students.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-48716CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Student Result Management System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'class_id' parameter of the add_classes.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-48689CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'byname' parameter of the train.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-48687CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'from' parameter of the reservation.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-48685CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Railway Reservation System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'psd' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-51052CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_formauth parameter at /admin/ajax.php.

  • CVE-2023-51051CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_textauth parameter at /admin/ajax.php.

  • CVE-2023-51050CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_productauth parameter at /admin/ajax.php.

  • CVE-2023-51049CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_bbsauth parameter at /admin/ajax.php.

  • CVE-2023-51048CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php.

  • CVE-2023-6145CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in İstanbul Soft Informatics and Consultancy Limited Company Softomi Advanced C2C Marketplace Software allows SQL Injection. This issue affects Softomi Advanced C2C Marketplace…

  • CVE-2023-49778CriDec 21, 2023
    risk 0.65cvss 10.0epss 0.01

    Deserialization of Untrusted Data vulnerability in Hakan Demiray Sayfa Sayac.This issue affects Sayfa Sayac: from n/a through 2.6.

  • CVE-2023-32242CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in xtemos WoodMart - Multipurpose WooCommerce Theme.This issue affects WoodMart - Multipurpose WooCommerce Theme: from n/a through 1.0.36.

  • CVE-2023-51656CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended to upgrade to version 1.2.2, which fixes the issue.

  • CVE-2023-50477CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in nos client version 0.6.6, allows remote attackers to escalate privileges via getRPCEndpoint.js.

  • CVE-2023-50475CriDec 21, 2023
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in bcoin-org bcoin version 2.2.0, allows remote attackers to obtain sensitive information via weak hashing algorithms in the component \vendor\faye-websocket.js.

  • CVE-2023-29487CriDec 21, 2023
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to cause a denial of service (DoS) via the Threat To Process Correlation threat prevention module. NOTE: Heimdal asserts this is not a valid…

  • CVE-2023-29486CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Heimdal Thor agent versions 3.4.2 and before 3.7.0 on Windows, allows attackers to bypass USB access restrictions, execute arbitrary code, and obtain sensitive information via Next-Gen Antivirus component. NOTE: Heimdal argues that the limitation…

  • CVE-2023-29485CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to bypass network filtering, execute arbitrary code, and obtain sensitive information via DarkLayer Guard threat prevention module. NOTE: Heimdal…

  • CVE-2023-49032CriDec 21, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in LTB Self Service Password before v.1.5.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via hijack of the SMS verification code function to arbitrary phone.

  • CVE-2023-50993CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Ruijie WS6008 v1.x v2.x AC_RGOS11.9(6)W3B2_G2C6-01_10221911 and WS6108 v1.x AC_RGOS11.9(6)W3B2_G2C6-01_10221911 was discovered to contain a command injection vulnerability via the function downFiles.

  • CVE-2023-50992CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a stack overflow via the ip parameter in the setPing function.

  • CVE-2023-50990CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the rebootTime parameter in the sysScheduleRebootSet function.

  • CVE-2023-50989CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.

  • CVE-2023-50988CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the bandwidth parameter in the wifiRadioSetIndoor function.

  • CVE-2023-50987CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysTimeInfoSet function.

  • CVE-2023-50986CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the time parameter in the sysLogin function.

  • CVE-2023-50985CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the lanGw parameter in the lanCfgSet function.

  • CVE-2023-50984CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a buffer overflow via the ip parameter in the spdtstConfigAndStart function.

  • CVE-2023-50983CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.

  • CVE-2023-48434CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the reg_action.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-48433CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the login_action.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-25970CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Zendrop Zendrop – Global Dropshipping.This issue affects Zendrop – Global Dropshipping: from n/a through 1.0.0.

  • CVE-2023-49814CriDec 20, 2023
    risk 0.59cvss 9.1epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Symbiostock symbiostock.This issue affects Symbiostock: from n/a through 6.0.0.

  • CVE-2023-47990CriDec 20, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitrary SQL commands via the table parameter.

  • CVE-2023-46149CriDec 20, 2023
    risk 0.64cvss 9.9epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.

  • CVE-2023-45603CriDec 20, 2023
    risk 0.59cvss 9.0epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.This issue affects User Submitted Posts – Enable Users to Submit Posts from the Front End: from n/a through 20230902.

  • CVE-2023-40204CriDec 20, 2023
    risk 0.59cvss 9.1epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Premio Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager.This issue affects Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager: from…