VYPR

CVEs

38,124 total · page 362 of 763

  • CVE-2023-34365CriOct 11, 2023
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the libutils.so nvram_restore functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to a buffer overflow. An attacker can send a network request to trigger this vulnerability.

  • CVE-2023-34346CriOct 11, 2023
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the httpd gwcfg.cgi get functionality of Yifan YF325 v1.0_20221108. A specially crafted network packet can lead to command execution. An attacker can send a network request to trigger this vulnerability.

  • CVE-2023-32645CriOct 11, 2023
    risk 0.68cvss 9.8epss 0.54

    A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability.

  • CVE-2023-24479CriOct 11, 2023
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass vulnerability exists in the httpd nvram.cgi functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability.

  • CVE-2023-44118CriOct 11, 2023
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of undefined permissions in the MeeTime module.Successful exploitation of this vulnerability will affect availability and confidentiality.

  • CVE-2023-44116CriOct 11, 2023
    risk 0.64cvss 9.8epss 0.00

    Vulnerability of access permissions not being strictly verified in the APPWidget module.Successful exploitation of this vulnerability may cause some apps to run without being authorized.

  • CVE-2023-44107CriOct 11, 2023
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of defects introduced in the design process in the screen projection module.Successful exploitation of this vulnerability may affect service availability and integrity.

  • CVE-2023-44105CriOct 11, 2023
    risk 0.64cvss 9.8epss 0.00

    Vulnerability of permissions not being strictly verified in the window management module.Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2023-37538CriOct 11, 2023
    risk 0.60cvss 9.3epss 0.00

    HCL Digital Experience is susceptible to cross site scripting (XSS). One subcomponent is vulnerable to reflected XSS. In reflected XSS, an attacker must induce a victim to click on a crafted URL from some delivery mechanism (email, other web site).

  • CVE-2023-5521CriOct 11, 2023
    risk 0.00cvss 9.8epss 0.01

    Incorrect Authorization in GitHub repository tiann/kernelsu prior to v0.6.9.

  • CVE-2023-44981CriOct 11, 2023
    risk 0.59cvss 9.1epss 0.02

    Authorization Bypass Through User-Controlled Key vulnerability in Apache ZooKeeper. If SASL Quorum Peer authentication is enabled in ZooKeeper (quorum.auth.enableSasl=true), the authorization is done by verifying that the instance part in SASL authentication ID is listed in…

  • CVE-2023-44106CriOct 11, 2023
    risk 0.64cvss 9.8epss 0.00

    API permission management vulnerability in the Fwk-Display module.Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2023-4309CriOct 10, 2023
    risk 0.65cvss 10.0epss 0.01

    Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated…

  • CVE-2023-36434CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows IIS Server Elevation of Privilege Vulnerability

  • CVE-2023-35349CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.03

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-36550CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.02

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

  • CVE-2023-36548CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.02

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

  • CVE-2023-36547CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.02

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

  • CVE-2023-34993CriOct 10, 2023
    risk 0.65cvss 9.8epss 0.18

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

  • CVE-2023-34992CriOct 10, 2023
    risk 0.70cvss 10.0epss 0.80

    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.

  • CVE-2020-27636CriOct 10, 2023
    risk 0.59cvss 9.1epss 0.01

    In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.

  • CVE-2020-27635CriOct 10, 2023
    risk 0.59cvss 9.1epss 0.01

    In PicoTCP 1.7.0, TCP ISNs are improperly random.

  • CVE-2020-27634CriOct 10, 2023
    risk 0.59cvss 9.1epss 0.02

    In Contiki 4.5, TCP ISNs are improperly random.

  • CVE-2020-27633CriOct 10, 2023
    risk 0.59cvss 9.1epss 0.01

    In FNET 4.6.3, TCP ISNs are improperly random.

  • CVE-2020-27631CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.01

    In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random.

  • CVE-2020-27630CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.01

    In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.

  • CVE-2023-30806CriOct 10, 2023
    risk 0.69cvss 9.8epss 0.66

    The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /cgi-bin/login.cgi endpoint. This…

  • CVE-2023-30805CriOct 10, 2023
    risk 0.69cvss 9.8epss 0.66

    The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /LogInOut.php endpoint. This is…

  • CVE-2023-30803CriOct 10, 2023
    risk 0.65cvss 9.8epss 0.18

    The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can bypass authentication and access administrative functionality by sending HTTP requests using a crafted Y-forwarded-for…

  • CVE-2023-4966CriKEVOct 10, 2023
    risk 0.90cvss 9.4epss 1.00

    Sensitive information disclosure in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA  virtual server.

  • CVE-2023-30801CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.01

    All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentials. As of 4.5.5, this issue has not been fixed. A remote attacker can use the default credentials…

  • CVE-2023-41373CriOct 10, 2023
    risk 0.65cvss 9.9epss 0.02

    A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security…

  • CVE-2023-43625CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Simcenter Amesim (All versions < V2021.1). The affected application contains a SOAP endpoint that could allow an unauthenticated remote attacker to perform DLL injection and execute arbitrary code in the context of the affected application…

  • CVE-2023-36380CriOct 10, 2023
    risk 0.64cvss 9.8epss 0.00

    A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)), CP-8050 MASTER MODULE (All versions < CPCI85 V05.11 (only with activated debug support)). The affected devices contain a hard-coded ID in the SSH…

  • CVE-2023-43899CriOct 9, 2023
    risk 0.64cvss 9.8epss 0.01

    hansun CMS v1.0 was discovered to contain a SQL injection vulnerability via the component /ajax/ajax_login.ashx.

  • CVE-2023-43271CriOct 9, 2023
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the driving recorder through ftp and other protocols.

  • CVE-2023-44467CriOct 9, 2023
    risk 0.57cvss 9.8epss 0.01

    langchain_experimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the CVE-2023-36258 fix and execute arbitrary code via __import__ in Python code, which is not prohibited by pal_chain/base.py.

  • CVE-2023-5365CriOct 9, 2023
    risk 0.64cvss 9.8epss 0.01

    HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure.

  • CVE-2023-44393CriOct 9, 2023
    risk 0.00cvss 9.3epss 0.01

    Piwigo is an open source photo gallery application. Prior to version 14.0.0beta4, a reflected cross-site scripting (XSS) vulnerability is in the` /admin.php?page=plugins&tab=new&installstatus=ok&plugin_id=[here]` page. This vulnerability can be exploited by an attacker to inject…

  • CVE-2023-45199CriOct 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.

  • CVE-2023-45311CriOct 6, 2023
    risk 0.57cvss 9.8epss 0.02

    fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was…

  • CVE-2023-45239CriOct 6, 2023
    risk 0.00cvss 9.8epss 0.02

    A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled, allows an attacker who can control the username, rem-addr, or NAC address sent to tac_plus to inject shell commands and gain remote code execution on the…

  • CVE-2023-44807CriOct 6, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the cancelPing function.

  • CVE-2023-38703CriOct 6, 2023
    risk 0.00cvss 9.8epss 0.02

    PJSIP is a free and open source multimedia communication library written in C with high level API in C, C++, Java, C#, and Python languages. SRTP is a higher level media transport which is stacked upon a lower level media transport such as UDP and ICE. Currently a higher level…

  • CVE-2023-36465CriOct 6, 2023
    risk 0.52cvss 9.1epss 0.01

    Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. The `templates` module doesn't enforce the correct permissions, allowing any logged-in user to access to…

  • CVE-2023-4530CriOct 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Turna Advertising Administration Panel allows SQL Injection. This issue affects Advertising Administration Panel: before 1.1.

  • CVE-2023-43269CriOct 5, 2023
    risk 0.64cvss 9.8epss 0.01

    pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability.

  • CVE-2023-44024CriOct 5, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in KnowBand Module One Page Checkout, Social Login & Mailchimp (supercheckout) v.8.0.3 and before allows a remote attacker to execute arbitrary code via a crafted request to the updateCheckoutBehaviour function in the supercheckout.php component.

  • CVE-2023-43983CriOct 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Presto Changeo attributegrid up to 2.0.3 was discovered to contain a SQL injection vulnerability via the component disable_json.php.

  • CVE-2023-43981CriOct 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Presto Changeo testsitecreator up to 1.1.1 was discovered to contain a deserialization vulnerability via the component delete_excluded_folder.php.