VYPR

CVEs

38,124 total · page 366 of 763

  • CVE-2023-43239CriSep 21, 2023
    risk 0.65cvss 9.8epss 0.13

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter flag_5G in showMACfilterMAC.

  • CVE-2023-43238CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter nvmacaddr in form2Dhcpip.cgi.

  • CVE-2023-43237CriSep 21, 2023
    risk 0.65cvss 9.8epss 0.13

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter macCloneMac in setMAC.

  • CVE-2023-43236CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-816 A2 v1.10CNB05 was discovered to contain a stack overflow via parameter statuscheckpppoeuser in dir_setWanWifi.

  • CVE-2023-43235CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DIR-823G v1.0.2B05 was discovered to contain a stack overflow via parameter StartTime and EndTime in SetWifiDownSettings.

  • CVE-2023-4291CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a remote code execution (RCE) vulnerability via manipulated parameters of the web interface without authentication. This could lead to a full compromise of the FDS101 device. …

  • CVE-2015-5467CriSep 21, 2023
    risk 0.64cvss 9.8epss 0.01

    web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter.

  • CVE-2023-43135CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    There is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend management.

  • CVE-2023-39675CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    SimpleImportProduct Prestashop Module v6.2.9 was discovered to contain a SQL injection vulnerability via the key parameter at send.php.

  • CVE-2023-36109CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.02

    Buffer Overflow vulnerability in JerryScript version 3.0, allows remote attackers to execute arbitrary code via ecma_stringbuilder_append_raw component at /jerry-core/ecma/base/ecma-helpers-string.c.

  • CVE-2023-34575CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in PrestaShop opartsavecart through 2.0.7 allows remote attackers to run arbitrary SQL commands via OpartSaveCartDefaultModuleFrontController::initContent() and OpartSaveCartDefaultModuleFrontController::displayAjaxSendCartByEmail() methods.

  • CVE-2023-42322CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information.

  • CVE-2023-43134CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    There is an unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend management.

  • CVE-2023-43375CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonascita, annoscaddoc, giornonascita, giornoscaddoc, lingua_cli, mesenascita, and mesescaddoc parameters.

  • CVE-2023-43374CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.04

    Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/personalizza.php.

  • CVE-2023-43373CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.04

    Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.

  • CVE-2023-43371CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/creaprezzi.php.

  • CVE-2023-40619CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple places. An example is the functionality to manage tables in…

  • CVE-2023-5074CriSep 20, 2023
    risk 0.69cvss 9.8epss 0.70

    Use of a static key to protect a JWT token used in user authentication can allow an for an authentication bypass in D-Link D-View 8 v2.0.1.28

  • CVE-2023-2262CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited, a threat actor could potentially leverage this vulnerability to perform a remote code execution. To exploit this vulnerability, a threat actor would have to…

  • CVE-2023-42464CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.02

    A Type Confusion vulnerability was found in the Spotlight RPC functions in afpd in Netatalk 3.1.x before 3.1.17. When parsing Spotlight RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the…

  • CVE-2023-43207CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.03

    D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function config_upload_handler. This vulnerability allows attackers to execute arbitrary commands via the configRestore parameter.

  • CVE-2023-43206CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.03

    D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function web_cert_download_handler. This vulnerability allows attackers to execute arbitrary commands via the certDownload parameter.

  • CVE-2023-43204CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.03

    D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function sub_2EF50. This vulnerability allows attackers to execute arbitrary commands via the manual-time-string parameter.

  • CVE-2023-43203CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a stack overflow vulnerability in the function update_users.

  • CVE-2023-43202CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.03

    D-LINK DWL-6610 FW_v_4.3.0.8B003C was discovered to contain a command injection vulnerability in the function pcap_download_handler. This vulnerability allows attackers to execute arbitrary commands via the update.device.packet-capture.tftp-file-name parameter.

  • CVE-2023-43201CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the hi_up parameter in the qos_ext.asp function.

  • CVE-2023-43200CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the id parameter in the yyxz.data function.

  • CVE-2023-43199CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the prev parameter in the H5/login.cgi function.

  • CVE-2023-43198CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the popupId parameter in the H5/hi_block.asp function.

  • CVE-2023-43197CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the fn parameter in the tgfile.asp function.

  • CVE-2023-43196CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DI-7200GV2.E1 v21.04.09E1 was discovered to contain a stack overflow via the zn_jb parameter in the arp_sys.asp function.

  • CVE-2023-0118CriSep 20, 2023
    risk 0.59cvss 9.1epss 0.01

    An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on the underlying operating system.

  • CVE-2019-19450CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.06

    paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '<unichar code="' followed by arbitrary Python code, a similar issue to CVE-2019-17626.

  • CVE-2023-2163CriSep 20, 2023
    risk 0.00cvss 10.0epss 0.04

    Incorrect verifier pruning in BPF in Linux Kernel >=5.4 leads to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape.

  • CVE-2023-4088CriSep 20, 2023
    risk 0.60cvss 9.3epss 0.00

    Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to execute a malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS)…

  • CVE-2023-38888CriSep 20, 2023
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.

  • CVE-2023-42793CriKEVSep 19, 2023
    risk 0.93cvss 9.8epss 1.00

    In JetBrains TeamCity before 2023.05.4 authentication bypass leading to RCE on TeamCity Server was possible

  • CVE-2022-47558CriSep 19, 2023
    risk 0.61cvss 9.4epss 0.01

    Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of this vulnerability can allow an attacker to modify critical files that could allow the creation of new users, delete or modify existing users, modify…

  • CVE-2022-47555CriSep 19, 2023
    risk 0.61cvss 9.3epss 0.01

    Operating system command injection in ekorCCP and ekorRCI, which could allow an authenticated attacker to execute commands, create new users with elevated privileges or set up a backdoor.

  • CVE-2023-0773CriSep 19, 2023
    risk 0.59cvss 9.1epss 0.01

    The vulnerability exists in Uniview IP Camera due to identification and authentication failure at its web-based management interface. A remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation…

  • CVE-2023-41387CriSep 19, 2023
    risk 0.59cvss 9.1epss 0.01

    A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if an app uses…

  • CVE-2022-28357CriSep 19, 2023
    risk 0.64cvss 9.8epss 0.01

    NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.

  • CVE-2021-26837CriSep 19, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information.

  • CVE-2023-42454CriSep 18, 2023
    risk 0.58cvss 10.0epss 0.01

    SQLpage is a SQL-only webapp builder. Someone using SQLpage versions prior to 0.11.1, whose SQLpage instance is exposed publicly, with a database connection string specified in the `sqlpage/sqlpage.json` configuration file (not in an environment variable), with the web_root is…

  • CVE-2023-41084CriSep 18, 2023
    risk 0.65cvss 10.0epss 0.01

    Session management within the web application is incorrect and allows attackers to steal session cookies to perform a multitude of actions that the web app allows on the device.

  • CVE-2023-33831CriSep 18, 2023
    risk 0.65cvss 9.8epss 0.26

    A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.

  • CVE-2023-42320CriSep 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service via the mac parameter in the GetParentControlInfo function.

  • CVE-2023-42359CriSep 18, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Exam Form Submission in PHP with Source Code v.1.0 allows a remote attacker to escalate privileges via the val-username parameter in /index.php.

  • CVE-2023-4994CriSep 16, 2023
    risk 0.64cvss 9.9epss 0.01

    The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server.