VYPR

CVEs

38,103 total · page 349 of 763

  • CVE-2023-49436CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.

  • CVE-2023-49435CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AX9 V22.03.01.46 is vulnerable to command injection.

  • CVE-2023-49434CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetNetControlList.

  • CVE-2023-49433CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetVirtualServerCfg.

  • CVE-2023-49432CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg.

  • CVE-2023-49431CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.

  • CVE-2023-49430CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'list' parameter at /goform/SetStaticRouteCfg.

  • CVE-2023-49429CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AX9 V22.03.01.46 was discovered to contain a SQL command injection vulnerability in the 'setDeviceInfo' feature through the 'mac' parameter at /goform/setModules.

  • CVE-2023-49437CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList.

  • CVE-2023-49428CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.03

    Tenda AX12 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'mac' parameter at /goform/SetOnlineDevName.

  • CVE-2023-49426CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg.

  • CVE-2023-49425CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the deviceList parameter at /goform/setMacFilterCfg .

  • CVE-2023-39169CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The affected devices use publicly available default credentials with administrative privileges.

  • CVE-2023-49424CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX12 V22.03.01.46 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.

  • CVE-2023-39172CriDec 7, 2023
    risk 0.59cvss 9.1epss 0.01

    The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic.

  • CVE-2023-35039CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Restriction of Excessive Authentication Attempts vulnerability in Be Devious Web Development Password Reset with Code for WordPress REST API allows Authentication Abuse.This issue affects Password Reset with Code for WordPress REST API: from n/a through 0.0.15.

  • CVE-2023-50164CriDec 7, 2023
    risk 0.63cvss 9.8epss 0.81

    An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. Users are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or…

  • CVE-2023-48860CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK N300RT version 3.2.4-B20180730.0906 has a post-authentication RCE due to incorrect access control, allows attackers can bypass front-end security restrictions and execute arbitrary code.

  • CVE-2023-48823CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    A Blind SQL injection issue in ajax.php in GaatiTrack Courier Management System 1.0 allows an unauthenticated attacker to inject a payload via the email parameter during login.

  • CVE-2023-41913CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.02

    strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message.

  • CVE-2023-5761CriDec 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'url' parameter in versions 1.4.0 to 1.4.6.1 (free) and versions 1.4.0 to 1.5.0 (pro) due to insufficient escaping on the user supplied parameter and…

  • CVE-2023-46353CriDec 6, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "Product Tag Icons Pro" (ticons) before 1.8.4 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The method TiconProduct::getTiconByProductAndTicon() has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL…

  • CVE-2023-36655CriDec 6, 2023
    risk 0.64cvss 9.8epss 0.01

    The login REST API in ProLion CryptoSpike 3.0.15P2 (when LDAP or Active Directory is used as the users store) allows a remote blocked user to login and obtain an authentication token by specifying a username with different uppercase/lowercase character combination.

  • CVE-2023-46773CriDec 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Permission management vulnerability in the PMS module. Successful exploitation of this vulnerability may cause privilege escalation.

  • CVE-2023-48849CriDec 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Ruijie EG Series Routers version EG_3.0(1)B11P216 and before allows unauthenticated attackers to remotely execute arbitrary code due to incorrect filtering.

  • CVE-2023-22524CriDec 6, 2023
    risk 0.66cvss 9.8epss 0.25

    Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.

  • CVE-2023-48930CriDec 6, 2023
    risk 0.64cvss 9.8epss 0.01

    xinhu xinhuoa 2.2.1 contains a File upload vulnerability.

  • CVE-2023-6448CriKEVDec 5, 2023
    risk 0.76cvss 9.8epss 0.02

    Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.

  • CVE-2023-6269CriDec 5, 2023
    risk 0.65cvss 10.0epss 0.02

    An argument injection vulnerability has been identified in the administrative web interface of the Atos Unify OpenScape products "Session Border Controller" (SBC) and "Branch", before version V10 R3.4.0, and OpenScape "BCF" before versions V10R10.12.00 and V10R11.05.02. This…

  • CVE-2023-49070CriDec 5, 2023
    risk 0.74cvss 9.8epss 0.95

    Pre-auth RCE in Apache Ofbiz 18.12.09. It's due to XML-RPC no longer maintained still present. This issue affects Apache OFBiz: before 18.12.10.  Users are recommended to upgrade to version 18.12.10

  • CVE-2023-33083CriDec 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory corruption in WLAN Host while processing RRM beacon on the AP.

  • CVE-2023-33082CriDec 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory corruption while sending an Assoc Request having BTM Query or BTM Response containing MBO IE.

  • CVE-2023-33054CriDec 5, 2023
    risk 0.59cvss 9.1epss 0.00

    Cryptographic issue in GPS HLOS Driver while downloading Qualcomm GNSS assistance data.

  • CVE-2023-48692CriDec 5, 2023
    risk 0.59cvss 9.0epss 0.03

    Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions…

  • CVE-2023-48316CriDec 5, 2023
    risk 0.64cvss 9.8epss 0.04

    Azure RTOS NetX Duo is a TCP/IP network stack designed specifically for deeply embedded real-time and IoT applications. An attacker can cause remote code execution due to memory overflow vulnerabilities in Azure RTOS NETX Duo. The affected components include processes/functions…

  • CVE-2023-49291CriDec 5, 2023
    risk 0.54cvss 9.3epss 0.01

    tj-actions/branch-names is a Github action to retrieve branch or tag names with support for all events. The `tj-actions/branch-names` GitHub Actions improperly references the `github.event.pull_request.head.ref` and `github.head_ref` context variables within a GitHub Actions…

  • CVE-2023-40082CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    In modify_for_next_stage of fdt.rs, there is a possible way to render KASLR ineffective due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40078CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to paired device escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2023-35690CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In RGXDestroyHWRTData of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-24052CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via the change password functionality as it does not prompt for the current password.

  • CVE-2023-24051CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    A client side rate limit issue discovered in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges via brute force style attacks.

  • CVE-2023-24049CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to gain escalated privileges on the device via poor credential management.

  • CVE-2023-21403CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In RGXDestroyZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21402CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In MMU_UnmapPages of mmu_common.c, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21401CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In DevmemIntChangeSparse of devicemem_server.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21263CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In OSMMapPMRGeneric of pmr_os.c, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21228CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-21218CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-21217CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In PMRWritePMPageList of TBD, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21216CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for…