VYPR

CVEs

38,124 total · page 364 of 763

  • CVE-2023-4659CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.00

    Cross-Site Request Forgery vulnerability, whose exploitation could allow an attacker to perform different actions on the platform as an administrator, simply by changing the token value to "admin". It is also possible to perform POST, GET and DELETE requests without any token…

  • CVE-2023-3744CriOct 2, 2023
    risk 0.64cvss 9.9epss 0.01

    Server-Side Request Forgery vulnerability in SLims version 9.6.0. This vulnerability could allow an authenticated attacker to send requests to internal services or upload the contents of relevant files via the "scrape_image.php" file in the imageURL parameter.

  • CVE-2023-20819CriOct 2, 2023
    risk 0.64cvss 9.8epss 0.01

    In CDMA PPP protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privilege needed. User interaction is not needed for exploitation. Patch ID: MOLY01068234; Issue ID:…

  • CVE-2023-5201CriSep 30, 2023
    risk 0.64cvss 9.9epss 0.02

    The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server. This requires the [php]…

  • CVE-2023-5227CriSep 30, 2023
    risk 0.57cvss 9.8epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository thorsten/phpmyfaq prior to 3.1.8.

  • CVE-2023-43909CriSep 29, 2023
    risk 0.59cvss 9.1epss 0.01

    Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.

  • CVE-2023-5288CriSep 29, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote unauthorized attacker may connect to the SIM1012, interact with the device and change configuration settings. The adversary may also reset the SIM and in the worst case upload a new firmware version to the device.

  • CVE-2023-43654CriSep 28, 2023
    risk 0.64cvss 10.0epss 0.42

    TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper input validation, enabling third parties to invoke remote HTTP download requests and write files to the disk. This issue could be taken advantage of to…

  • CVE-2023-44166CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    The 'age' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-44164CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    The 'Email' parameter of the process_login.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-44163CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    The 'search' parameter of the process_search.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-43739CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    The 'bookisbn' parameter of the cart.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-5185CriSep 28, 2023
    risk 0.59cvss 9.1epss 0.01

    Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of profile/i.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

  • CVE-2023-5053CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.

  • CVE-2023-5004CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.

  • CVE-2023-43013CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.

  • CVE-2023-30415CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php.

  • CVE-2023-43869CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-619L B1 2.02 is vulnerable to Buffer Overflow via formSetWAN_Wizard56 function.

  • CVE-2023-44273CriSep 28, 2023
    risk 0.57cvss 9.8epss 0.01

    Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.

  • CVE-2023-38870CriSep 28, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1. The cash book has a feature to list accomplishments by category, and the 'category_id' parameter is vulnerable to SQL Injection.

  • CVE-2023-41449CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.

  • CVE-2023-44080CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request to the branchList component.

  • CVE-2023-4523CriSep 27, 2023
    risk 0.61cvss 9.4epss 0.00

    Real Time Automation 460 Series products with versions prior to v8.9.8 are vulnerable to cross-site scripting, which could allow an attacker to run any JavaScript reference from the URL string. If this were to occur, the gateway's HTTP interface would redirect to the main page,…

  • CVE-2023-20252CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the Security Assertion Markup Language (SAML) APIs of Cisco Catalyst SD-WAN Manager Software could allow an unauthenticated, remote attacker to gain unauthorized access to the application as an arbitrary user. This vulnerability is due to improper…

  • CVE-2023-5183CriSep 27, 2023
    risk 0.64cvss 9.9epss 0.02

    Unsafe deserialization of untrusted JSON allows execution of arbitrary code on affected releases of the Illumio PCE. Authentication to the API is required to exploit this vulnerability. The flaw exists within the network_traffic API endpoint. An attacker can leverage this…

  • CVE-2023-5176CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox <…

  • CVE-2023-5175CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepath, leading to a potentially exploitable crash. This vulnerability affects Firefox < 118.

  • CVE-2023-5174CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations…

  • CVE-2023-5172CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 118.

  • CVE-2023-5168CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This…

  • CVE-2023-4737CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hedef Tracking Admin Panel allows SQL Injection. This issue affects Admin Panel: before 1.2.

  • CVE-2023-44206CriSep 27, 2023
    risk 0.59cvss 9.1epss 0.01

    Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

  • CVE-2023-44172CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.

  • CVE-2023-44171CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.

  • CVE-2023-44170CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.

  • CVE-2023-44169CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.

  • CVE-2023-44152CriSep 27, 2023
    risk 0.59cvss 9.1epss 0.01

    Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.

  • CVE-2023-44023CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

  • CVE-2023-44022CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan function.

  • CVE-2023-44021CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the formSetClientState function.

  • CVE-2023-44020CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function.

  • CVE-2023-44019CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the mac parameter in the GetParentControlInfo function.

  • CVE-2023-44018CriSep 27, 2023
    risk 0.65cvss 9.8epss 0.16

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the domain parameter in the add_white_node function.

  • CVE-2023-44017CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the timeZone parameter in the fromSetSysTime function.

  • CVE-2023-44016CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.

  • CVE-2023-44015CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the schedEndTime parameter in the setSchedWifi function.

  • CVE-2023-44014CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain multiple stack overflows in the formSetMacFilterCfg function via the macFilterType and deviceList parameters.

  • CVE-2023-44013CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10U v1.0 US_AC10UV1.0RTL_V15.03.06.49_multi_TDE01 was discovered to contain a stack overflow via the list parameter in the fromSetIpMacBind function.

  • CVE-2023-43291CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.02

    Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.

  • CVE-2023-43234CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath and $filename parameters.