VYPR

CVEs

38,103 total · page 348 of 763

  • CVE-2023-42495CriDec 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

  • CVE-2023-6723CriDec 13, 2023
    risk 0.65cvss 10.0epss 0.01

    An unrestricted file upload vulnerability has been identified in Repbox, which allows an attacker to upload malicious files via the transforamationfileupload function, due to the lack of proper file type validation controls, resulting in a full system compromise.

  • CVE-2023-6718CriDec 13, 2023
    risk 0.61cvss 9.4epss 0.01

    An authentication bypass vulnerability has been found in Repox, which allows a remote user to send a specially crafted POST request, due to the lack of any authentication method, resulting in the alteration or creation of users.

  • CVE-2023-47577CriDec 13, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 allows for unauthorized password changes due to no check for current password.

  • CVE-2023-43364CriDec 12, 2023
    risk 0.57cvss 9.8epss 0.03

    main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.

  • CVE-2023-36019CriDec 12, 2023
    risk 0.64cvss 9.6epss 0.16

    Microsoft Power Platform Connector Spoofing Vulnerability

  • CVE-2013-2513CriDec 12, 2023
    risk 0.64cvss 9.8epss 0.02

    The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.

  • CVE-2023-6593CriDec 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the application to execute entries in a SQL data source without restriction.

  • CVE-2023-46456CriDec 12, 2023
    risk 0.66cvss 9.8epss 0.25

    In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionality.

  • CVE-2023-46454CriDec 12, 2023
    risk 0.66cvss 9.8epss 0.23

    In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality.

  • CVE-2023-50424CriDec 12, 2023
    risk 0.52cvss 9.1epss 0.01

    SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) - versions < 0.17.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the…

  • CVE-2023-50423CriDec 12, 2023
    risk 0.52cvss 9.1epss 0.01

    SAP BTP Security Services Integration Library ([Python] sap-xssec) - versions < 4.1.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.

  • CVE-2023-50422CriDec 12, 2023
    risk 0.52cvss 9.1epss 0.01

    SAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) - versions below 2.17.0 and versions from 3.0.0 to before 3.3.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated…

  • CVE-2023-49583CriDec 12, 2023
    risk 0.59cvss 9.1epss 0.01

    SAP BTP Security Services Integration Library ([Node.js] @sap/xssec - versions < 3.6.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.

  • CVE-2023-36649CriDec 12, 2023
    risk 0.59cvss 9.1epss 0.01

    Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate other users in web management and the REST API by reading JWT tokens from logs (as a Granafa authenticated user) or from the Loki…

  • CVE-2023-50245CriDec 11, 2023
    risk 0.57cvss 9.8epss 0.01

    OpenEXR-viewer is a viewer for OpenEXR files with detailed metadata probing. Versions prior to 0.6.1 have a memory overflow vulnerability. This issue is fixed in version 0.6.1.

  • CVE-2023-49418CriDec 11, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLink A7000R V9.1.0u.6115_B20201022has a stack overflow vulnerability via setIpPortFilterRules.

  • CVE-2023-49417CriDec 11, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLink A7000R V9.1.0u.6115_B20201022 has a stack overflow vulnerability via setOpModeCfg.

  • CVE-2023-6181CriDec 11, 2023
    risk 0.64cvss 9.8epss 0.00

    An oversight in BCB handling of reboot reason that allows for persistent code execution

  • CVE-2023-48425CriDec 11, 2023
    risk 0.64cvss 9.8epss 0.00

    U-Boot vulnerability resulting in persistent Code Execution 

  • CVE-2023-48424CriDec 11, 2023
    risk 0.64cvss 9.8epss 0.00

    U-Boot shell vulnerability resulting in Privilege escalation in a production device

  • CVE-2023-48417CriDec 11, 2023
    risk 0.64cvss 9.8epss 0.00

    Missing Permission checks resulting in unauthorized access and Manipulation in KeyChainActivity Application

  • CVE-2023-50429CriDec 9, 2023
    risk 0.59cvss 9.1epss 0.01

    IzyBat Orange casiers before 20230803_1 allows getEnsemble.php ensemble SQL injection.

  • CVE-2023-47254CriDec 9, 2023
    risk 0.64cvss 9.8epss 0.02

    An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands and escalate privileges via any account created within the web interface.

  • CVE-2023-46932CriDec 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Heap Buffer Overflow vulnerability in GPAC version 2.3-DEV-rev617-g671976fcc-master, allows attackers to execute arbitrary code and cause a denial of service (DoS) via str2ulong class in src/media_tools/avilib.c in gpac/MP4Box.

  • CVE-2023-46498CriDec 8, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information and execute arbitrary code via the /deleteCustomer/route.json file.

  • CVE-2023-48423CriDec 8, 2023
    risk 0.64cvss 9.8epss 0.00

    In dhcp4_SetPDNAddress of dhcp4_Main.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-49443CriDec 8, 2023
    risk 0.64cvss 9.8epss 0.01

    DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords. This vulnerability allows attackers to gain access to the application via a bruteforce attack.

  • CVE-2023-49007CriDec 8, 2023
    risk 0.64cvss 9.8epss 0.09

    In Netgear Orbi RBR750 firmware before V7.2.6.21, there is a stack-based buffer overflow in /usr/sbin/httpd.

  • CVE-2023-48929CriDec 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' parameter in the group_status.asp resource allows an attacker to escalate privileges and obtain sensitive information.

  • CVE-2023-43742CriDec 8, 2023
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an unauthenticated attacker to obtain an administrative session via a protection mechanism failure in the…

  • CVE-2023-5008CriDec 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Student Information System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'regno' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.

  • CVE-2023-4122CriDec 7, 2023
    risk 0.64cvss 9.9epss 0.01

    Student Information System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'photo' parameter of my-profile page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

  • CVE-2023-35618CriDec 7, 2023
    risk 0.63cvss 9.6epss 0.03

    Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

  • CVE-2023-49411CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E V16.01.0.12(4843) contains a stack overflow vulnerability via the function formDeleteMeshNode.

  • CVE-2023-49409CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AX3 V16.03.12.11 was discovered to contain a Command Execution vulnerability via the function /goform/telnet.

  • CVE-2023-49408CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the function set_device_name.

  • CVE-2023-49406CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda W30E V16.01.0.12(4843) was discovered to contain a Command Execution vulnerability via the function /goform/telnet.

  • CVE-2023-49405CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function UploadCfg.

  • CVE-2023-49404CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formAdvancedSetListSet.

  • CVE-2023-40302CriDec 7, 2023
    risk 0.59cvss 9.1epss 0.01

    NETSCOUT nGeniusPULSE 3.8 has Weak File Permissions Vulnerability

  • CVE-2023-40301CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    NETSCOUT nGeniusPULSE 3.8 has a Command Injection Vulnerability.

  • CVE-2023-40300CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    NETSCOUT nGeniusPULSE 3.8 has a Hardcoded Cryptographic Key.

  • CVE-2023-50002CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formRebootMeshNode.

  • CVE-2023-50001CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formUpgradeMeshOnline.

  • CVE-2023-50000CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function formResetMeshNode.

  • CVE-2023-49999CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition.

  • CVE-2023-49410CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function via the function set_wan_status.

  • CVE-2023-49403CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setFixTools.

  • CVE-2023-49402CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W30E V16.01.0.12(4843) was discovered to contain a stack overflow via the function localMsg.