VYPR

CVEs

38,103 total · page 347 of 763

  • CVE-2023-6906CriDec 18, 2023
    risk 0.64cvss 9.8epss 0.02

    A vulnerability, which was classified as critical, was found in Totolink A7100RU 7.4cu.2313_B20191024. Affected is the function main of the file /cgi-bin/cstecgi.cgi?action=login of the component HTTP POST Request Handler. The manipulation of the argument flag with the input ie8…

  • CVE-2023-50976CriDec 18, 2023
    risk 0.00cvss 9.8epss 0.01

    Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API.

  • CVE-2023-50965CriDec 17, 2023
    risk 0.64cvss 9.8epss 0.02

    In MicroHttpServer (aka Micro HTTP Server) through 4398570, _ReadStaticFiles in lib/middleware.c allows a stack-based buffer overflow and potentially remote code execution via a long URI.

  • CVE-2021-42796CriDec 16, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitrary commands to be executed.

  • CVE-2020-17485CriDec 16, 2023
    risk 0.64cvss 9.8epss 0.02

    A Remote Code Execution vulnerability exist in Uffizio's GPS Tracker all versions. The web server can be compromised by uploading and executing a web/reverse shell. An attacker could then run commands, browse system files, and browse local resources

  • CVE-2023-50469CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.09

    Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 was discovered to contain a buffer overflow via the ApCliEncrypType parameter at /apply.cgi.

  • CVE-2023-4020CriDec 15, 2023
    risk 0.59cvss 9.0epss 0.01

    An unvalidated input in a library function responsible for communicating between secure and non-secure memory in Silicon Labs TrustZone implementation allows reading/writing of memory in the secure region of memory from the non-secure region of memory.

  • CVE-2023-50723CriDec 15, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone who can edit an arbitrary wiki page in an XWiki installation can gain programming right through several cases of missing escaping in the code for displaying…

  • CVE-2023-50722CriDec 15, 2023
    risk 0.55cvss 9.6epss 0.01

    XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, there is a reflected XSS or also direct remote code execution vulnerability in the code for displaying configurable admin sections. The code that can be passed…

  • CVE-2023-50721CriDec 15, 2023
    risk 0.64cvss 9.9epss 0.79

    XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the search administration interface doesn't properly escape the id and label of search user interface extensions, allowing the injection of XWiki syntax…

  • CVE-2023-50918CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    app/Controller/AuditLogsController.php in MISP before 2.4.182 mishandles ACLs for audit logs.

  • CVE-2023-50917CriDec 15, 2023
    risk 0.06cvss 9.8epss 0.38

    MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.

  • CVE-2023-50089CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.04

    A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70. When using HTTP for SOAP authentication, command execution occurs during the process after successful authentication.

  • CVE-2023-46116CriDec 15, 2023
    risk 0.00cvss 9.3epss 0.01

    Tutanota (Tuta Mail) is an encrypted email provider. Tutanota allows users to open links in emails in external applications. Prior to version 3.118.12, it correctly blocks the `file:` URL scheme, which can be used by malicious actors to gain code execution on a victims computer,…

  • CVE-2023-33220CriDec 15, 2023
    risk 0.59cvss 9.1epss 0.01

    During the retrofit validation process, the firmware doesn't properly check the boundaries while copying some attributes to check. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the targeted device

  • CVE-2023-33219CriDec 15, 2023
    risk 0.59cvss 9.1epss 0.01

    The handler of the retrofit validation command doesn't properly check the boundaries when performing certain validation operations. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the targeted device

  • CVE-2023-33218CriDec 15, 2023
    risk 0.59cvss 9.1epss 0.01

    The Parameter Zone Read and Parameter Zone Write command handlers allow performing a Stack buffer overflow. This could potentially lead to a Remote Code execution on the targeted device.

  • CVE-2023-6553CriDec 15, 2023
    risk 0.75cvss 9.8epss 0.98

    The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that…

  • CVE-2023-48392CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard-coded encryption key. An unauthenticated remote attacker can generate valid token parameter and exploit this vulnerability to access system with arbitrary user account, including…

  • CVE-2023-48390CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Multisuns EasyLog web+ has a code injection vulnerability. An unauthenticated remote attacker can exploit this vulnerability to inject code and access the system to perform arbitrary system operations or disrupt service.

  • CVE-2023-48388CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

  • CVE-2023-48384CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    ArmorX Global Technology Corporation ArmorX Spam has insufficient validation for user input within a special function. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.

  • CVE-2023-46279CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.02

    Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the latest version, which fixes the issue.

  • CVE-2023-29234CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.07

    A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4. Users are recommended to upgrade to the latest version, which fixes the issue.

  • CVE-2023-48376CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    SmartStar Software CWS is a web-based integration platform, its file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt…

  • CVE-2023-48372CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    ITPison OMICARD EDM 's SMS-related function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.

  • CVE-2023-48371CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    ITPison OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.

  • CVE-2023-48050CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Cams Biometrics Zkteco, eSSL, Cams Biometrics Integration Module with HR Attendance (aka odoo-biometric-attendance) v. 13.0 through 16.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the db parameter in the…

  • CVE-2023-40954CriDec 15, 2023
    risk 0.00cvss 9.8epss 0.01

    A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain…

  • CVE-2023-48049CriDec 15, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in Cybrosys Techno Solutions Website Blog Search (aka website_search_blog) v. 13.0 through 13.0.1.0.1 allows a remote attacker to execute arbitrary code and to gain privileges via the name parameter in controllers/main.py component.

  • CVE-2023-45894CriDec 14, 2023
    risk 0.65cvss 10.0epss 0.01

    The Remote Application Server in Parallels RAS before 19.2.23975 does not segment virtualized applications from the server, which allows a remote attacker to achieve remote code execution via standard kiosk breakout techniques.

  • CVE-2023-47261CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.02

    Dokmee ECM 7.4.6 allows remote code execution because the response to a GettingStarted/SaveSQLConnectionAsync /#/gettingstarted request contains a connection string for privileged SQL Server database access, and xp_cmdshell can be enabled.

  • CVE-2023-50563CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Semcms v4.8 was discovered to contain a SQL injection vulnerability via the AID parameter at SEMCMS_Function.php.

  • CVE-2023-50073CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    EmpireCMS v7.5 was discovered to contain a SQL injection vulnerability via the ftppassword parameter at SetEnews.php.

  • CVE-2023-46141CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.

  • CVE-2023-0757CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.

  • CVE-2023-49708CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQLi vulnerability in Starshop component for Joomla.

  • CVE-2023-49707CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQLi vulnerability in S5 Register module for Joomla.

  • CVE-2023-48925CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Buy Addons bavideotab before version 1.0.6, allows attackers to escalate privileges and obtain sensitive information via the component BaVideoTabSaveVideoModuleFrontController::run().

  • CVE-2023-46348CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL njection vulnerability in SunnyToo sturls before version 1.1.13, allows attackers to escalate privileges and obtain sensitive information via StUrls::hookActionDispatcher and StUrls::getInstanceId methods.

  • CVE-2023-40630CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated LFI/SSRF in JCDashboards component for Joomla.

  • CVE-2023-40629CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQLi vulnerability in LMS Lite component for Joomla.

  • CVE-2023-48085CriDec 14, 2023
    risk 0.70cvss 9.8epss 0.76

    Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.

  • CVE-2023-48084CriDec 14, 2023
    risk 0.66cvss 9.8epss 0.34

    Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.

  • CVE-2023-44709CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    PlutoSVG commit 336c02997277a1888e6ccbbbe674551a0582e5c4 and before was discovered to contain an integer overflow via the component plutosvg_load_from_memory.

  • CVE-2023-49937CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. Because of a double free, attackers can cause a denial of service or possibly execute arbitrary code. The fixed versions are 22.05.11, 23.02.7, and 23.11.1.

  • CVE-2023-49934CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in SchedMD Slurm 23.11.x. There is SQL Injection against the SlurmDBD database. The fixed version is 23.11.1.

  • CVE-2023-31546CriDec 14, 2023
    risk 0.66cvss 9.6epss 0.49

    Cross Site Scripting (XSS) vulnerability in DedeBIZ v6.0.3 allows attackers to run arbitrary code via the search feature.

  • CVE-2023-40921CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters.

  • CVE-2023-49363CriDec 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Rockoa <2.3.3 is vulnerable to SQL Injection. The problem exists in the indexAction method in reimpAction.php.