VYPR

CVEs

38,124 total · page 368 of 763

  • CVE-2023-4897CriSep 11, 2023
    risk 0.00cvss 9.8epss 0.01

    Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.

  • CVE-2023-35681CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    In eatt_l2cap_reconfig_completed of eatt_impl.h, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40946CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    Schoolmate 1.3 is vulnerable to SQL Injection in the variable $username from SESSION in ValidateLogin.php.

  • CVE-2023-40945CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php.

  • CVE-2023-40944CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    Schoolmate 1.3 is vulnerable to SQL Injection in the variable $schoolname from Database at ~\header.php.

  • CVE-2023-40150CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    Softneta MedDream PACS does not perform an authentication check and performs some dangerous functionality, which could result in unauthenticated remote code execution.0

  • CVE-2023-41256CriSep 11, 2023
    risk 0.59cvss 9.1epss 0.01

    Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.3 are vulnerable to authentication bypass that could allow an unauthorized attacker to obtain user access.

  • CVE-2023-31069CriSep 11, 2023
    risk 0.67cvss 9.8epss 0.04

    An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML source code of the login page.

  • CVE-2023-31068CriSep 11, 2023
    risk 0.67cvss 9.8epss 0.05

    An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\UserDesktop\themes.

  • CVE-2023-31067CriSep 11, 2023
    risk 0.67cvss 9.8epss 0.05

    An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on some directories under %PROGRAMFILES(X86)%\TSplus\Clients\www.

  • CVE-2020-19559CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Diebold Aglis XFS for Opteva v.4.1.61.1 allows a remote attacker to execute arbitrary code via a crafted payload to the ResolveMethod() parameter.

  • CVE-2020-19320CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the curTime parameter on login.

  • CVE-2020-19319CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow vulnerability in DLINK 619L version B 2.06beta via the FILECODE parameter on login.

  • CVE-2023-30058CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    novel-plus 3.6.2 is vulnerable to SQL Injection.

  • CVE-2023-36140CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    In PHPJabbers Cleaning Business Software 1.0, there is no encryption on user passwords allowing an attacker to gain access to all user accounts.

  • CVE-2023-42471CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.03

    The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to…

  • CVE-2023-42470CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.02

    The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execution is enabled in the WebView, and…

  • CVE-2023-40039CriSep 11, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on ARRIS TG852G, TG862G, and TG1672G devices. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame.

  • CVE-2023-42277CriSep 8, 2023
    risk 0.57cvss 9.8epss 0.01

    hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath.

  • CVE-2023-42276CriSep 8, 2023
    risk 0.57cvss 9.8epss 0.01

    hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonArray.

  • CVE-2023-42268CriSep 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show.

  • CVE-2023-39320CriSep 8, 2023
    risk 0.64cvss 9.8epss 0.02

    The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as…

  • CVE-2023-41615CriSep 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Zoo Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the Admin sign-in page via the username and password fields.

  • CVE-2023-37759CriSep 8, 2023
    risk 0.67cvss 9.8epss 0.07

    Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an Admin account via a crafted POST request.

  • CVE-2021-27715CriSep 8, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in MoFi Network MOFI4500-4GXeLTE-V2 3.5.6-xnet-5052 allows attackers to bypass the authentication and execute arbitrary code via crafted HTTP request.

  • CVE-2023-40029CriSep 7, 2023
    risk 0.57cvss 9.9epss 0.01

    Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. As a result, the full secret body is stored in`kubectl.kubernetes.io/last-applied-configuration` annotation. pull request #7139…

  • CVE-2023-30908CriSep 7, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote authentication bypass issue exists in a OneView API.

  • CVE-2023-40942CriSep 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0BR_V15.03.06.42_multi_TD01 was discovered stack overflow via parameter 'firewall_value' at url /goform/SetFirewallCfg.

  • CVE-2023-39424CriSep 7, 2023
    risk 0.64cvss 9.9epss 0.01

    A vulnerability in RDPngFileUpload.dll, as used in the IRM Next Generation booking system, allows a remote attacker to upload arbitrary content (such as a web shell component) to the SQL database and execute it with SYSTEM privileges. This vulnerability requires authentication…

  • CVE-2023-39420CriSep 7, 2023
    risk 0.64cvss 9.9epss 0.01

    The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user to connect to customers with an "admin" account and a corresponding password computed daily by a routine inside the DLL file. Once reverse-engineered, this routine can help an…

  • CVE-2023-40397CriSep 6, 2023
    risk 0.64cvss 9.8epss 0.02

    The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.5. A remote attacker may be able to cause arbitrary javascript code execution.

  • CVE-2023-39967CriSep 6, 2023
    risk 0.65cvss 10.0epss 0.01

    WireMock is a tool for mocking HTTP services. When certain request URLs like “@127.0.0.1:1234" are used in WireMock Studio configuration fields, the request might be forwarded to an arbitrary service reachable from WireMock’s instance. There are 3 identified potential attack…

  • CVE-2020-10131CriSep 6, 2023
    risk 0.64cvss 9.8epss 0.02

    SearchBlox before Version 9.2.1 is vulnerable to CSV macro injection in "Featured Results" parameter.

  • CVE-2023-41330CriSep 6, 2023
    risk 0.57cvss 9.8epss 0.02

    knplabs/knp-snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. ## Issue On March 17th the vulnerability CVE-2023-28115 was disclosed, allowing an attacker to gain remote code execution through PHAR deserialization. Version 1.4.2…

  • CVE-2023-20238CriSep 6, 2023
    risk 0.66cvss 10.0epss 0.15

    A vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to forge the credentials required to access an affected system. This…

  • CVE-2023-0925CriSep 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 by default) and two RMI interfaces (listening on a single, dynamically assigned TCP high port). Port 2099 serves as a Java…

  • CVE-2021-36023CriSep 6, 2023
    risk 0.59cvss 9.1epss 0.02

    Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.

  • CVE-2023-41149CriSep 6, 2023
    risk 0.64cvss 9.8epss 0.01

    F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploited, an attacker who can access the product may execute an arbitrary OS command on the server where the product is running.

  • CVE-2023-4589CriSep 6, 2023
    risk 0.59cvss 9.1epss 0.00

    Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An attacker with an administrator account could perform software updates without proper integrity verification mechanisms. In this scenario, the update process…

  • CVE-2023-4634CriSep 6, 2023
    risk 0.73cvss 9.8epss 0.86

    The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the…

  • CVE-2023-4485CriSep 6, 2023
    risk 0.64cvss 9.8epss 0.01

    ARDEREG ​Sistema SCADA Central versions 2.203 and prior login page are vulnerable to an unauthenticated blind SQL injection attack. An attacker could manipulate the application's SQL query logic to extract sensitive information or perform unauthorized actions within the…

  • CVE-2023-41507CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters.

  • CVE-2023-4310CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.02

    BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote…

  • CVE-2023-41508CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.

  • CVE-2023-39361CriSep 5, 2023
    risk 0.71cvss 9.8epss 0.89

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an…

  • CVE-2023-41009CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.02

    File Upload vulnerability in adlered bolo-solo v.2.6 allows a remote attacker to execute arbitrary code via a crafted script to the authorization field in the header.

  • CVE-2023-39654CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    abupy up to v0.4.0 was discovered to contain a SQL injection vulnerability via the component abupy.MarketBu.ABuSymbol.search_to_symbol_dict.

  • CVE-2023-4531CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestav Software E-commerce Software allows SQL Injection. This issue affects E-commerce Software: before 20230901 .

  • CVE-2023-4178CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass by Spoofing vulnerability in Neutron Neutron Smart VMS allows Authentication Bypass. This issue affects Neutron Smart VMS: before b1130.1.0.1.

  • CVE-2023-4034CriSep 5, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection. This issue affects Smartrise Document Management System: before Hvl-2.0.