VYPR

CVEs

38,104 total · page 357 of 763

  • CVE-2023-45499CriOct 27, 2023
    risk 0.67cvss 9.8epss 0.08

    VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded credentials.

  • CVE-2023-45498CriOct 27, 2023
    risk 0.68cvss 9.8epss 0.20

    VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain a command injection vulnerability.

  • CVE-2023-42406CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.02

    SQL injection vulnerability in D-Link Online behavior audit gateway DAR-7000 V31R02B1413C allows a remote attacker to obtain sensitive information and execute arbitrary code via the editrole.php component.

  • CVE-2018-17879CriOct 26, 2023
    risk 0.65cvss 9.8epss 0.22

    An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. There are several injection points in various scripts.

  • CVE-2018-17878CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in certain ABUS TVIP cameras allows attackers to gain control of the program via crafted string sent to sprintf() function.

  • CVE-2018-17558CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.03

    Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM.1.6.18, TVIP10050 LM.1.6.18, TVIP11550 MG.1.6.03, TVIP21050 MG.1.6.03, and…

  • CVE-2023-46747CriKEVOct 26, 2023
    risk 0.92cvss 9.8epss 0.97

    Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of…

  • CVE-2023-46665CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative privileges.

  • CVE-2023-39726CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.

  • CVE-2023-5754CriOct 26, 2023
    risk 0.59cvss 9.1epss 0.00

    Sielco PolyEco1000 uses a weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system.

  • CVE-2023-46661CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests.

  • CVE-2023-44267CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Art Gallery v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'lnm' parameter of the header.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-46435CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Packers and Movers Management System v1.0 is vulnerable to SQL Injection via mpms/?p=services/view_service&id.

  • CVE-2023-43208CriKEVOct 26, 2023
    risk 0.91cvss 9.8epss 0.83

    NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.

  • CVE-2023-42769CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.

  • CVE-2023-45869CriOct 26, 2023
    risk 0.59cvss 9.0epss 0.01

    ILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a highly privileged account accesses an XSS payload. The injected commands are executed via the exec() function in the execQuoted() method of the ilUtil class…

  • CVE-2023-31422CriOct 26, 2023
    risk 0.59cvss 9.0epss 0.01

    An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana version 8.10.0 when logging in the JSON layout or when the pattern layout is configured to log the %meta pattern. Elastic has…

  • CVE-2023-30967CriOct 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system.

  • CVE-2023-46584CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in PHPGurukul Nipah virus (NiV) " Testing Management System v.1.0 allows a remote attacker to escalate privileges via a crafted request to the new-user-testing.php endpoint.

  • CVE-2023-46233CriOct 25, 2023
    risk 0.52cvss 9.1epss 0.01

    crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry standard. This is because it both defaults to SHA1, a cryptographic…

  • CVE-2023-46133CriOct 25, 2023
    risk 0.52cvss 9.1epss 0.00

    CryptoES is a cryptography algorithms library compatible with ES6 and TypeScript. Prior to version 2.1.0, CryptoES PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry standard. This is because it both defaults…

  • CVE-2023-45137CriOct 25, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.platform:xwiki-platform-web` starting in version 3.1-milestone-2 and prior to version 13.4-rc-1, as well as `org.xwiki.platform:xwiki-platform-web-templates` prior…

  • CVE-2023-46424CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_422BD4 function.

  • CVE-2023-46423CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_417094 function.

  • CVE-2023-46422CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411994 function.

  • CVE-2023-46421CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_411D00 function.

  • CVE-2023-46420CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41590C function.

  • CVE-2023-46419CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415730 function.

  • CVE-2023-46418CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_412688 function.

  • CVE-2023-46417CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_415498 function.

  • CVE-2023-46416CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ The 41A414 function.

  • CVE-2023-46415CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_41E588 function.

  • CVE-2023-46414CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a remote command execution (RCE) vulnerability via the sub_ 41D494 function.

  • CVE-2023-46413CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_4155DC function.

  • CVE-2023-46412CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_41D998 function.

  • CVE-2023-46411CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_415258 function.

  • CVE-2023-46410CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 416F60 function.

  • CVE-2023-46409CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ 41CC04 function.

  • CVE-2023-46408CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X6000R v9.4.0cu.652_B20230116 was discovered to contain a command execution vulnerability via the sub_ The 41DD80 function.

  • CVE-2023-45136CriOct 25, 2023
    risk 0.56cvss 9.6epss 0.05

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When document names are validated according to a name strategy (disabled by default), XWiki starting in version 12.0-rc-1 and prior to versions 12.10.12 and 15.5-rc-1 is…

  • CVE-2023-45135CriOct 25, 2023
    risk 0.52cvss 9.0epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In `org.xwiki.platform:xwiki-platform-web` versions 7.2-milestone-2 until 14.10.12 and `org.xwiki.platform:xwiki-platform-web-templates` prior to versions 14.10.12 and…

  • CVE-2023-45134CriOct 25, 2023
    risk 0.52cvss 9.0epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.platform:xwiki-platform-web` starting in version 3.1-milestone-1 and prior to 13.4-rc-1, `org.xwiki.platform:xwiki-platform-web-templates` prior to versions…

  • CVE-2023-5746CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.02

    A vulnerability regarding use of externally-controlled format string is found in the cgi component. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.5-0185 may be affected:…

  • CVE-2023-5731CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 119.

  • CVE-2023-5730CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox <…

  • CVE-2023-46574CriOct 25, 2023
    risk 0.69cvss 9.8epss 0.65

    An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.

  • CVE-2023-46564CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDMZ.

  • CVE-2023-46563CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formIpQoS.

  • CVE-2023-46562CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formDosCfg.

  • CVE-2023-46560CriOct 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK X2000R Gh v1.0.0-B20230221.0948.web was discovered to contain a stack overflow via the function formTcpipSetup.