VYPR

CVEs

38,103 total · page 353 of 763

  • CVE-2023-41101CriNov 17, 2023
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not validate the length of the query string of GET requests. This leads to a stack-based buffer overflow in versions 9.x and earlier, and to a heap-based buffer…

  • CVE-2023-38316CriNov 17, 2023
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests. Affected OpenNDS Captive Portal before version 10.1.2…

  • CVE-2023-48659CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.176. app/Controller/AppController.php mishandles parameter parsing.

  • CVE-2023-48658CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php lacks a checkParam function for alphanumerics, underscore, dash, period, and space.

  • CVE-2023-48657CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles filters.

  • CVE-2023-48656CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.176. app/Model/AppModel.php mishandles order clauses.

  • CVE-2023-48655CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MISP before 2.4.176. app/Controller/Component/IndexFilterComponent.php does not properly filter out query parameters.

  • CVE-2023-48648CriNov 17, 2023
    risk 0.57cvss 9.8epss 0.01

    Concrete CMS before 8.5.13 and 9.x before 9.2.2 allows unauthorized access because directories can be created with insecure permissions. File creation functions (such as the Mkdir() function) gives universal access (0777) to created folders by default. Excessive permissions can…

  • CVE-2023-48031CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    OpenSupports v4.11.0 is vulnerable to Unrestricted Upload of File with Dangerous Type. In the comment function, an attacker can bypass security restrictions and upload a .bat file by manipulating the file's magic bytes to masquerade as an allowed type. This can enable the…

  • CVE-2023-45387CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 5.0.0 from MyPrestaModules for PrestaShop, a guest can perform SQL injection via `exportProduct::_addDataToDb().`

  • CVE-2023-48078CriNov 17, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in add.php in Simple CRUD Functionality v1.0 allows attackers to run arbitrary SQL commands via the 'title' parameter.

  • CVE-2023-6014CriNov 16, 2023
    risk 0.57cvss 9.8epss 0.01

    An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.

  • CVE-2023-6019CriNov 16, 2023
    risk 0.73cvss 9.8epss 0.75

    A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here:…

  • CVE-2023-6018CriNov 16, 2023
    risk 0.61cvss 9.8epss 0.48

    An attacker can overwrite any file on the server hosting MLflow without any authentication.

  • CVE-2023-6016CriNov 16, 2023
    risk 0.66cvss 9.8epss 0.31

    An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.

  • CVE-2023-47674CriNov 16, 2023
    risk 0.64cvss 9.8epss 0.01

    Missing authentication for critical function vulnerability in First Corporation's DVRs allows a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB,…

  • CVE-2023-47213CriNov 16, 2023
    risk 0.64cvss 9.8epss 0.01

    First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated attacker to rewrite or obtain the configuration information of the affected device. Note that updates are provided only for Late model of CFR-4EABC, CFR-4EAB, CFR-8EAB, CFR-16EAB,…

  • CVE-2023-47003CriNov 16, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlock_ItemIsDeleted.

  • CVE-2021-35437CriNov 16, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in LMXCMS v.1.4 allows attacker to execute arbitrary code via the TagsAction.class.

  • CVE-2023-48365CriKEVNov 15, 2023
    risk 0.82cvss 9.6epss 0.47

    Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP…

  • CVE-2023-41442CriNov 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute arbitrary code via a crafted request to the MQTT component.

  • CVE-2023-47445CriNov 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page.

  • CVE-2023-47678CriNov 15, 2023
    risk 0.59cvss 9.1epss 0.01

    An improper access control vulnerability exists in RT-AC87U all versions. An attacker may read or write files that are not intended to be accessed by connecting to a target device via tftp.

  • CVE-2023-47308CriNov 15, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design for PrestaShop, a guest can perform SQL injection in affected versions. The method `NewsletterpopsendVerificationModuleFrontController::checkEmailSubscription()`…

  • CVE-2023-43979CriNov 15, 2023
    risk 0.64cvss 9.8epss 0.01

    ETS Soft ybc_blog before v4.4.0 was discovered to contain a SQL injection vulnerability via the component Ybc_blogBlogModuleFrontController::getPosts().

  • CVE-2023-39337CriNov 15, 2023
    risk 0.59cvss 9.1epss 0.02

    A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access and extract sensitive information, including device and environment configuration details, as well as secrets. This vulnerability…

  • CVE-2023-39335CriNov 15, 2023
    risk 0.64cvss 9.8epss 0.02

    A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate any existing user during the device enrollment process. This issue poses a significant security risk, as it enables unauthorized…

  • CVE-2023-45616CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.02

    There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful…

  • CVE-2023-45615CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-45614CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-34060CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.01

    VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network access to the…

  • CVE-2023-31273CriNov 14, 2023
    risk 0.65cvss 10.0epss 0.01

    Protection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2023-20596CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leading to arbitrary code execution.

  • CVE-2022-23821CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.

  • CVE-2023-36553CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.02

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 and 4.10.0 and 4.9.0 and 4.7.2…

  • CVE-2023-36397CriNov 14, 2023
    risk 0.65cvss 9.8epss 0.18

    Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

  • CVE-2023-36028CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.03

    Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

  • CVE-2023-34991CriNov 14, 2023
    risk 0.66cvss 9.8epss 0.29

    A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.0 through 8.4.2 and 8.3.0 through 8.3.2 and 8.2.2 allows attacker to execute unauthorized code or commands via…

  • CVE-2023-6126CriNov 14, 2023
    risk 0.00cvss 9.8epss 0.01

    Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.

  • CVE-2023-46601CriNov 14, 2023
    risk 0.62cvss 9.6epss 0.01

    A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in making the SQLServer connection. This could allow an attacker to query the database directly to access information that the user should not have access to.

  • CVE-2023-44373CriNov 14, 2023
    risk 0.59cvss 9.1epss 0.01

    Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell. Follow-up of CVE-2022-36323.

  • CVE-2023-43505CriNov 14, 2023
    risk 0.62cvss 9.6epss 0.01

    A vulnerability has been identified in COMOS (All versions). The affected application lacks proper access controls in SMB shares. This could allow an attacker to access files that the user should not have access to.

  • CVE-2023-43504CriNov 14, 2023
    risk 0.62cvss 9.6epss 0.01

    A vulnerability has been identified in COMOS (All versions < V10.4.4). Ptmcast executable used for testing cache validation service in affected application is vulnerable to Structured Exception Handler (SEH) based buffer overflow. This could allow an attacker to execute…

  • CVE-2023-31247CriNov 14, 2023
    risk 0.59cvss 9.0epss 0.02

    A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-28391CriNov 14, 2023
    risk 0.59cvss 9.0epss 0.01

    A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-28379CriNov 14, 2023
    risk 0.59cvss 9.0epss 0.02

    A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-27882CriNov 14, 2023
    risk 0.59cvss 9.0epss 0.02

    A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-25181CriNov 14, 2023
    risk 0.59cvss 9.0epss 0.02

    A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send a malicious packet to trigger this vulnerability.

  • CVE-2023-45878CriNov 14, 2023
    risk 0.69cvss 9.8epss 0.63

    GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path, and gibbonPersonID parameters. The img parameter is expected to be a base64 encoded image. If the…

  • CVE-2023-43902CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the Forgot Your Password function of eMudhra emSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.