VYPR

CVEs

38,124 total · page 365 of 763

  • CVE-2023-43222CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.

  • CVE-2023-43216CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.

  • CVE-2023-43187CriSep 27, 2023
    risk 0.67cvss 9.8epss 0.47

    A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers to execute arbitrary code via crafted XML-RPC requests.

  • CVE-2023-43154CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability that leads to authentication bypass and takeover of the administrator account.

  • CVE-2023-42657CriSep 27, 2023
    risk 0.66cvss 9.9epss 0.16

    In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered.  An attacker could leverage this vulnerability to perform file operations (delete, rename, rmdir, mkdir) on files and folders outside of their authorized WS_FTP folder…

  • CVE-2023-40455CriSep 27, 2023
    risk 0.65cvss 10.0epss 0.01

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.

  • CVE-2023-40436CriSep 27, 2023
    risk 0.59cvss 9.1epss 0.01

    The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14. An attacker may be able to cause unexpected system termination or read kernel memory.

  • CVE-2023-40400CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.02

    This issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS Sonoma 14. A remote user may cause an unexpected app termination or arbitrary code execution.

  • CVE-2023-40044CriKEVSep 27, 2023
    risk 0.93cvss 10.0epss 0.90

    In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.

  • CVE-2023-3767CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.02

    An OS command injection vulnerability has been found on EasyPHP Webserver affecting version 14.1. This vulnerability could allow an attacker to get full access to the system by sending a specially crafted exploit to the /index.php?zone=settings parameter.

  • CVE-2023-38586CriSep 27, 2023
    risk 0.65cvss 10.0epss 0.01

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.

  • CVE-2023-35071CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging Administration Panel allows SQL Injection. This issue affects Logging Administration Panel: before 20230915 .

  • CVE-2021-38243CriSep 27, 2023
    risk 0.64cvss 9.8epss 0.02

    xunruicms up to v4.5.1 was discovered to contain a remote code execution (RCE) vulnerability in /index.php. This vulnerability allows attackers to execute arbitrary code via a crafted GET request.

  • CVE-2023-43457CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint.

  • CVE-2023-43644CriSep 25, 2023
    risk 0.52cvss 9.1epss 0.01

    Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafted requests are sent to sing-box. This affects all SOCKS5 inbounds with user authentication and an attacker may be able to bypass authentication. Users are…

  • CVE-2023-39640CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    UpLight cookiebanner before 1.5.1 was discovered to contain a SQL injection vulnerability via the component Hook::getHookModuleExecList().

  • CVE-2023-4521CriSep 25, 2023
    risk 0.67cvss 9.8epss 0.41

    The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to perform RCE. The plugin/vendor was not compromised and the files are the result of running a PoC for a previously reported issue…

  • CVE-2023-4490CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.04

    The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

  • CVE-2023-43141CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control.

  • CVE-2023-40163CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds write vulnerability exists in the allocate_buffer_for_jpeg_decoding functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2023-39453CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    A use-after-free vulnerability exists in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can deliver this file to trigger this vulnerability.

  • CVE-2023-35002CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the pictwread functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2023-32653CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds write vulnerability exists in the dcm_pixel_data_decode functionality of Accusoft ImageGear 20.1. A specially crafted malformed file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.

  • CVE-2023-43131CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.01

    General Device Manager 2.5.2.2 is vulnerable to Buffer Overflow.

  • CVE-2022-48605CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.00

    Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability.

  • CVE-2023-41419CriSep 25, 2023
    risk 0.57cvss 9.8epss 0.02

    An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.

  • CVE-2023-41297CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.00

    Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exploitation of this vulnerability may cause service hijacking.

  • CVE-2023-41296CriSep 25, 2023
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality.

  • CVE-2023-41294CriSep 25, 2023
    risk 0.64cvss 9.8epss 0.00

    The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services.

  • CVE-2023-39407CriSep 25, 2023
    risk 0.59cvss 9.1epss 0.00

    The Watchkit has a risk of unauthorized file access.Successful exploitation of this vulnerability may affect confidentiality and integrity.

  • CVE-2023-43470CriSep 23, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in janobe Online Voting System v.1.0 allows a remote attacker to execute arbitrary code via the checklogin.php component.

  • CVE-2023-43469CriSep 23, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the ForPass.php component.

  • CVE-2023-43468CriSep 23, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the login.php component.

  • CVE-2023-43338CriSep 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr(). This vulnerability allows attackers to execute arbitrary code via a crafted input.

  • CVE-2023-43130CriSep 22, 2023
    risk 0.64cvss 9.8epss 0.03

    D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection.

  • CVE-2023-43129CriSep 22, 2023
    risk 0.64cvss 9.8epss 0.03

    D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of REMOTE_PORT parameters.

  • CVE-2023-40989CriSep 22, 2023
    risk 0.57cvss 9.8epss 0.02

    SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component.

  • CVE-2023-43270CriSep 22, 2023
    risk 0.64cvss 9.8epss 0.02

    dst-admin v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the userId parameter at /home/playerOperate.

  • CVE-2023-43144CriSep 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.

  • CVE-2023-43762CriSep 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain WithSecure products allow Unauthenticated Remote Code Execution via the web server (backend). This affects WithSecure Policy Manager 15 and Policy Manager Proxy 15.

  • CVE-2023-31719CriSep 22, 2023
    risk 0.66cvss 9.8epss 0.26

    FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.

  • CVE-2023-43128CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.03

    D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of HTTP_ST parameters.

  • CVE-2023-34576CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in updatepos.php in PrestaShop opartfaq through 1.0.3 allows remote attackers to run arbitrary SQL commands via unspedified vector.

  • CVE-2023-42810CriSep 21, 2023
    risk 0.57cvss 9.8epss 0.02

    systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter check in version 5.21.7. As a workaround, check or sanitize parameter strings that are passed to…

  • CVE-2023-42279CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Dreamer CMS v4.1.3 was discovered to contain a SQL injection vulnerability via the model-form-management-field form.

  • CVE-2023-34577CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Prestashop opartplannedpopup 1.4.11 and earlier allows remote attackers to run arbitrary SQL commands via OpartPlannedPopupModuleFrontController::prepareHook() method.

  • CVE-2023-43632CriSep 21, 2023
    risk 0.59cvss 9.0epss 0.01

    As noted in the “VTPM.md” file in the eve documentation, “VTPM is a server listening on port 8877 in EVE, exposing limited functionality of the TPM to the clients. VTPM allows clients to execute tpm2-tools binaries from a list of hardcoded options” The communication…

  • CVE-2023-43242CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter removeRuleList in form2IPQoSTcDel.

  • CVE-2023-43241CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter TXPower and GuardInt in SetWLanRadioSecurity.

  • CVE-2023-43240CriSep 21, 2023
    risk 0.65cvss 9.8epss 0.13

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter sip_address in ipportFilter.