VYPR

CVEs

38,104 total · page 356 of 763

  • CVE-2023-45018CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the includes/login.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45015CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'date' parameter of the bus_info.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45012CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Bus Booking System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'user_email' parameter of the bus_info.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45111CriNov 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Examination System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'email' parameter of the feed.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-44025CriNov 1, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in addify Addifyfreegifts v.1.0.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the getrulebyid function in the AddifyfreegiftsModel.php component.

  • CVE-2023-39281CriNov 1, 2023
    risk 0.64cvss 9.8epss 0.00

    A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run arbitrary code execution during the DXE phase.

  • CVE-2023-46482CriNov 1, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in wuzhicms v.4.1.0 allows a remote attacker to execute arbitrary code via the Database Backup Functionality in the coreframe/app/database/admin/index.php component.

  • CVE-2023-5766CriNov 1, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from another windows user session on the same host via a specially crafted TCP packet.

  • CVE-2023-5765CriNov 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to bypass permissions via data source switching.

  • CVE-2023-20048CriNov 1, 2023
    risk 0.66cvss 9.9epss 0.16

    A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute certain unauthorized configuration commands on a Firepower Threat Defense (FTD) device that is managed by the FMC Software.…

  • CVE-2023-1720CriNov 1, 2023
    risk 0.62cvss 9.6epss 0.01

    Lack of mime type response header in Bitrix24 22.0.300 allows authenticated remote attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege, via uploading a crafted…

  • CVE-2023-1717CriNov 1, 2023
    risk 0.62cvss 9.6epss 0.01

    Prototype pollution in bitrix/templates/bitrix24/components/bitrix/menu/left_vertical/script.js in Bitrix24 22.0.300 allows remote attackers to execute arbitrary JavaScript code in the victim’s browser, and possibly execute arbitrary PHP code on the server if the victim has…

  • CVE-2023-1716CriNov 1, 2023
    risk 0.59cvss 9.0epss 0.01

    Cross-site scripting (XSS) vulnerability in Invoice Edit Page in Bitrix24 22.0.300 allows attackers to execute arbitrary JavaScript code in the victim's browser, and possibly execute arbitrary PHP code on the server if the victim has administrator privilege.

  • CVE-2023-1715CriNov 1, 2023
    risk 0.59cvss 9.0epss 0.01

    A logic error when using mb_strpos() to check for potential XSS payload in Bitrix24 22.0.300 allows attackers to bypass XSS sanitisation via placing HTML tags at the begining of the payload.

  • CVE-2023-46485CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setTracerouteCfg function of the stecgi.cgi component.

  • CVE-2023-46484CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in TOTOlink X6000R V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the setLedCfg function.

  • CVE-2023-46249CriOct 31, 2023
    risk 0.00cvss 9.6epss 0.01

    authentik is an open-source Identity Provider. Prior to versions 2023.8.4 and 2023.10.2, when the default admin user has been deleted, it is potentially possible for an attacker to set the password of the default admin user without any authentication. authentik uses a blueprint…

  • CVE-2023-46248CriOct 31, 2023
    risk 0.59cvss 9.0epss 0.01

    Cody is an artificial intelligence (AI) coding assistant. The Cody AI VSCode extension versions 0.10.0 through 0.14.0 are vulnerable to Remote Code Execution under certain conditions. An attacker in control of a malicious repository could modify the Cody configuration file…

  • CVE-2023-46993CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.02

    In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable parameter, which can lead to command injection.

  • CVE-2023-42425CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud connection components.

  • CVE-2023-40050CriOct 31, 2023
    risk 0.64cvss 9.9epss 0.01

    Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.

  • CVE-2023-22518CriKEVOct 31, 2023
    risk 0.93cvss 9.8epss 1.00

    All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Using this account, an…

  • CVE-2023-5360CriOct 31, 2023
    risk 0.73cvss 9.8epss 0.82

    The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

  • CVE-2023-46979CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the setLedCfg function.

  • CVE-2023-46977CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.09

    TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the function loginAuth.

  • CVE-2023-46976CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFile function.

  • CVE-2023-43139CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in franfinance before v.2.0.27 allows a remote attacker to execute arbitrary code via the validation.php, and controllers/front/validation.php components.

  • CVE-2023-36263CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.00

    Prestashop opartlimitquantity 1.4.5 and before is vulnerable to SQL Injection. OpartlimitquantityAlertlimitModuleFrontController::displayAjaxPushAlertMessage()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

  • CVE-2023-47174CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.

  • CVE-2023-46356CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "CSV Feeds PRO" (csvfeeds) before 2.6.1 from Bl Modules for PrestaShop, a guest can perform SQL injection. The method `SearchApiCsv::getProducts()` has sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.

  • CVE-2023-45378CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    In the module "PrestaBlog" (prestablog) version 4.4.7 and before from HDclic for PrestaShop, a guest can perform SQL injection. The script ajax slider_positions.php has a sensitive SQL call that can be executed with a trivial http call and exploited to forge a SQL injection.

  • CVE-2023-27846CriOct 31, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop themevolty v.4.0.8 and before allow a remote attacker to gain privileges via the tvcmsblog, tvcmsvideotab, tvcmswishlist, tvcmsbrandlist, tvcmscategorychainslider, tvcmscategoryproduct, tvcmscategoryslider, tvcmspaymenticon,…

  • CVE-2023-5865CriOct 31, 2023
    risk 0.57cvss 9.8epss 0.01

    Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

  • CVE-2023-46502CriOct 30, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuilderFactory.

  • CVE-2023-43792CriOct 30, 2023
    risk 0.64cvss 9.8epss 0.01

    baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.

  • CVE-2023-47104CriOct 30, 2023
    risk 0.64cvss 9.8epss 0.01

    tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, which only considered single and double…

  • CVE-2023-5843CriOct 30, 2023
    risk 0.52cvss 9.0epss 0.02

    The Ads by datafeedr.com plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.3 via the 'dfads_ajax_load_ads' function. This allows unauthenticated attackers to execute code on the server. The parameters of the callable function are…

  • CVE-2023-5199CriOct 30, 2023
    risk 0.64cvss 9.9epss 0.01

    The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to include local file and…

  • CVE-2023-5832CriOct 30, 2023
    risk 0.00cvss 9.1epss 0.01

    Improper Input Validation in GitHub repository mintplex-labs/anything-llm prior to 0.1.0.

  • CVE-2023-45797CriOct 30, 2023
    risk 0.64cvss 9.8epss 0.01

    A Buffer overflow vulnerability in DreamSecurity MagicLine4NX versions 1.0.0.1 to 1.0.0.26 allows an attacker to remotely execute code.

  • CVE-2021-33635CriOct 29, 2023
    risk 0.64cvss 9.8epss 0.01

    When malicious images are pulled by isula pull, attackers can execute arbitrary code.

  • CVE-2023-5838CriOct 29, 2023
    risk 0.00cvss 9.8epss 0.01

    Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.

  • CVE-2023-46570CriOct 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32 function of libr/arch/p/nds32/nds32-dis.h.

  • CVE-2023-46569CriOct 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds read in radare2 v.5.8.9 and before exists in the print_insn32_fpu function of libr/arch/p/nds32/nds32-dis.h.

  • CVE-2023-46510CriOct 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in ZIONCOM (Hong Kong) Technology Limited A7000R v.4.1cu.4154 allows an attacker to execute arbitrary code via the cig-bin/cstecgi.cgi to the settings/setPasswordCfg function.

  • CVE-2023-46509CriOct 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.

  • CVE-2023-46853CriOct 27, 2023
    risk 0.00cvss 9.8epss 0.01

    In Memcached before 1.6.22, an off-by-one error exists when processing proxy requests in proxy mode, if \n is used instead of \r\n.

  • CVE-2023-46604CriKEVOct 27, 2023
    risk 0.87cvss 10.0epss 1.00

    The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the…

  • CVE-2023-5807CriOct 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TRtek Software Education Portal allows SQL Injection. This issue affects Education Portal: before 3.2023.29.

  • CVE-2023-5820CriOct 27, 2023
    risk 0.62cvss 9.6epss 0.00

    The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files…