VYPR

CVEs

38,124 total · page 370 of 763

  • CVE-2023-41563CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter mac at url /goform/GetParentControlInfo.

  • CVE-2023-41562CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter time at url /goform/PowerSaveSet.

  • CVE-2023-41561CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter startIp and endIp at url /goform/SetPptpServerCfg.

  • CVE-2023-41560CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0 V15.03.06.42_multi was discovered to contain a stack overflow via parameter firewallEn at url /goform/SetFirewallCfg.

  • CVE-2023-41559CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter page at url /goform/NatStaticSetting.

  • CVE-2023-41558CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter timeZone at url /goform/SetSysTimeCfg.

  • CVE-2023-41557CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44 and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter entrys and mitInterface at url /goform/addressNat.

  • CVE-2023-41556CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter list at url /goform/SetIpMacBind.

  • CVE-2023-41555CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44 was discovered to contain a stack overflow via parameter security_5g at url /goform/WifiBasicSet.

  • CVE-2023-41554CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0 V15.03.06.42_multi was discovered to contain a stack overflow via parameter wpapsk_crypto at url /goform/WifiExtraSet.

  • CVE-2023-41553CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter list at url /goform/SetStaticRouteCfg.

  • CVE-2023-41552CriAug 30, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0 V15.03.06.44 and Tenda AC9 V3.0 V15.03.06.42_multi were discovered to contain a stack overflow via parameter ssid at url /goform/fast_setting_wifi_set.

  • CVE-2023-4596CriAug 30, 2023
    risk 0.58cvss 9.8epss 0.14

    The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated…

  • CVE-2023-41265CriKEVAug 29, 2023
    risk 0.87cvss 9.6epss 0.88

    An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their…

  • CVE-2020-18912CriAug 29, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in Earcms Ear App v.20181124 allows a remote attacker to execute arbitrary code via the uload/index-uplog.php.

  • CVE-2021-3262CriAug 29, 2023
    risk 0.64cvss 9.8epss 0.01

    TripSpark VEO Transportation-2.2.x-XP_BB-20201123-184084 NovusEDU-2.2.x-XP_BB-20201123-184084 allows unsafe data inputs in POST body parameters from end users without sanitizing using server-side logic. It was possible to inject custom SQL commands into the "Student Busing…

  • CVE-2023-34039CriAug 29, 2023
    risk 0.72cvss 9.8epss 0.67

    Aria Operations for Networks contains an Authentication Bypass vulnerability due to a lack of unique cryptographic key generation. A malicious actor with network access to Aria Operations for Networks could bypass SSH authentication to gain access to the Aria Operations for…

  • CVE-2023-40890CriAug 29, 2023
    risk 0.64cvss 9.8epss 0.02

    A stack-based buffer overflow vulnerability exists in the lookup_sequence function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR…

  • CVE-2023-40889CriAug 29, 2023
    risk 0.64cvss 9.8epss 0.02

    A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digitally input the malicious QR code, or…

  • CVE-2023-40787CriAug 29, 2023
    risk 0.65cvss 9.8epss 0.18

    In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection.

  • CVE-2023-23770CriAug 29, 2023
    risk 0.61cvss 9.4epss 0.01

    Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.

  • CVE-2023-41361CriAug 29, 2023
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.

  • CVE-2023-41360CriAug 29, 2023
    risk 0.00cvss 9.1epss 0.01

    An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.

  • CVE-2023-41359CriAug 29, 2023
    risk 0.00cvss 9.1epss 0.01

    An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.

  • CVE-2023-39650CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.04

    Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.

  • CVE-2023-39652CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    theme volty tvcmsvideotab up to v4.0.0 was discovered to contain a SQL injection vulnerability via the component TvcmsVideoTabConfirmDeleteModuleFrontController::run().

  • CVE-2023-41109CriAug 28, 2023
    risk 0.69cvss 9.8epss 0.65

    SmartNode SN200 (aka SN200) 3.21.2-23021 allows unauthenticated OS Command Injection.

  • CVE-2023-39560CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.05

    ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php.

  • CVE-2023-40846CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 US_AC6V1.0BR_V15.03.05.16_multi_TD01.bin is vulnerable to Buffer Overflow via function sub_90998.

  • CVE-2023-40767CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40766CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40765CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40764CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40763CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40762CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40761CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Yacht Listing Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40760CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40759CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40758CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40757CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40756CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    User enumeration is found in PHPJabbers Callback Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.

  • CVE-2023-40749CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.04

    PHPJabbers Food Delivery Script v3.0 is vulnerable to SQL Injection in the "column" parameter of index.php.

  • CVE-2023-40748CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.03

    PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php.

  • CVE-2023-38029CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Saho’s attendance devices ADM100 and ADM-100FP has insufficient filtering for special characters and file type within their file uploading function. A unauthenticate remote attacker authenticated can upload and execute arbitrary files to perform arbitrary system commands or…

  • CVE-2023-38028CriAug 28, 2023
    risk 0.59cvss 9.1epss 0.01

    Saho’s attendance devices ADM100 and ADM-100FP have insufficient authentication. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication to read system information and operate user's data, but can’t control system or disrupt service.

  • CVE-2023-38027CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.02

    SpotCam Co., Ltd. SpotCam Sense’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute command injection attack to perform arbitrary system commands or disrupt service.

  • CVE-2023-38026CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    SpotCam Co., Ltd. SpotCam FHD 2 has a vulnerability of using hard-coded uBoot credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

  • CVE-2023-38025CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.02

    SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of OS command injection. An remote unauthenticated attacker can exploit this vulnerability to execute command injection attack to arbitrary system commands or disrupt service.

  • CVE-2023-38024CriAug 28, 2023
    risk 0.64cvss 9.8epss 0.01

    SpotCam Co., Ltd. SpotCam FHD 2’s hidden Telnet function has a vulnerability of using hard-coded Telnet credentials. An remote unauthenticated attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.

  • CVE-2023-40571CriAug 25, 2023
    risk 0.64cvss 9.8epss 0.01

    weblogic-framework is a tool for detecting weblogic vulnerabilities. Versions 0.2.3 and prior do not verify the returned data packets, and there is a deserialization vulnerability which may lead to remote code execution. When weblogic-framework gets the command echo, it directly…