VYPR

CVEs

38,103 total · page 350 of 763

  • CVE-2023-21215CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In DevmemIntAcquireRemoteCtx of devicemem_server.c, there is a possible arbitrary code execution due to a race condition. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-21166CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In RGXBackingZSBuffer of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21164CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In DevmemIntMapPMR of devicemem_server.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21163CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In PMR_ReadBytes of pmr.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21162CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In RGXUnbackingZSBuffer of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-5952CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    The Welcart e-Commerce WordPress plugin before 2.9.5 unserializes user input from cookies, which could allow unautehtniacted users to perform PHP Object Injection when a suitable gadget is present on the blog

  • CVE-2023-48967CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Ssolon <= 2.6.0 and <=2.5.12 is vulnerable to Deserialization of Untrusted Data.

  • CVE-2023-48910CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.

  • CVE-2023-48800CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_417338 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.

  • CVE-2023-48799CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK-X6000R Firmware-V9.4.0cu.852_B20230719 is vulnerable to Command Execution.

  • CVE-2023-49093CriDec 4, 2023
    risk 0.64cvss 9.8epss 0.02

    HtmlUnit is a GUI-less browser for Java programs. HtmlUnit is vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage. This vulnerability has been patched in version 3.9.0

  • CVE-2023-49946CriDec 3, 2023
    risk 0.59cvss 9.1epss 0.01

    In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform other unauthorized actions.

  • CVE-2023-48887CriDec 1, 2023
    risk 0.57cvss 9.8epss 0.02

    A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request.

  • CVE-2023-48886CriDec 1, 2023
    risk 0.64cvss 9.8epss 0.01

    A deserialization vulnerability in NettyRpc v1.2 allows attackers to execute arbitrary commands via sending a crafted RPC request.

  • CVE-2023-48801CriDec 1, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R_Firmware V9.4.0cu.852_B20230719, the shttpd file sub_415534 function obtains fields from the front-end, connects them through the snprintf function, and passes them to the CsteSystem function, resulting in a command execution vulnerability.

  • CVE-2023-44382CriDec 1, 2023
    risk 0.59cvss 9.1epss 0.01

    October is a Content Management System (CMS) and web platform to assist with development workflow. An authenticated backend user with the `editor.cms_pages`, `editor.cms_layouts`, or `editor.cms_partials` permissions who would normally not be permitted to provide PHP code to be…

  • CVE-2023-48842CriDec 1, 2023
    risk 0.64cvss 9.8epss 0.04

    D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at hedwig.cgi.

  • CVE-2023-49371CriDec 1, 2023
    risk 0.64cvss 9.8epss 0.04

    RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit.

  • CVE-2023-5636CriDec 1, 2023
    risk 0.64cvss 9.8epss 0.02

    Unrestricted Upload of File with Dangerous Type vulnerability in ArslanSoft Education Portal allows Command Injection. This issue affects Education Portal: before v1.1.

  • CVE-2023-5634CriDec 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ArslanSoft Education Portal allows SQL Injection. This issue affects Education Portal: before v1.1.

  • CVE-2023-43455CriDec 1, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the command parameter of the setting/setTracerouteCfg component.

  • CVE-2023-43454CriDec 1, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the hostName parameter of the switchOpMode component.

  • CVE-2023-43453CriDec 1, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter of the setDiagnosisCfg component.

  • CVE-2023-5908CriNov 30, 2023
    risk 0.59cvss 9.1epss 0.01

    KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.

  • CVE-2023-47207CriNov 30, 2023
    risk 0.65cvss 9.8epss 0.17

    In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute code with local administrator privileges.

  • CVE-2023-39226CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an unauthenticated attacker to execute arbitrary code through a single UDP packet.

  • CVE-2023-48812CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48811CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function that when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48810CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48808CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48807CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48806CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48805CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48804CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48803CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-48802CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a command execution vulnerability.

  • CVE-2023-6418CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via videos.php in the id parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server…

  • CVE-2023-6417CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via update.php in the id parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server…

  • CVE-2023-6416CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via signup2.php in the emailadd parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the…

  • CVE-2023-6415CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via signin.php in the user parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server…

  • CVE-2023-6414CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via perfil.php in the id and user parameters. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to…

  • CVE-2023-6413CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via photos.php in the id and user parameters. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to…

  • CVE-2023-6412CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via photo.php in multiple parameters. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server…

  • CVE-2023-6411CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via home.php in the update parameter. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the server…

  • CVE-2023-6410CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via editprofile.php in multiple parameters. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted SQL query to the…

  • CVE-2023-6026CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A Path traversal vulnerability has been reported in elijaa/phpmemcachedadmin affecting version 1.3.0. This vulnerability allows an attacker to delete files stored on the server due to lack of proper verification of user-supplied input.

  • CVE-2023-49733CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.

  • CVE-2022-45135CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.

  • CVE-2023-47418CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.02

    Remote Code Execution (RCE) vulnerability in o2oa version 8.1.2 and before, allows attackers to create a new interface in the service management function to execute JavaScript.

  • CVE-2023-47463CriNov 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the gl_nas_sys authentication function.