VYPR

CVEs

38,124 total · page 371 of 763

  • CVE-2019-13690CriAug 25, 2023
    risk 0.62cvss 9.6epss 0.00

    Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

  • CVE-2023-40799CriAug 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC23 Vv16.03.07.45_cn is vulnerable to Buffer Overflow via sub_450A4C function.

  • CVE-2023-32757CriAug 25, 2023
    risk 0.64cvss 9.8epss 0.01

    e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.

  • CVE-2023-39699CriAug 25, 2023
    risk 0.64cvss 9.8epss 0.01

    IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. This vulnerability allows attackers to include or execute files from the local file system of the targeted server.

  • CVE-2023-4420CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.00

    A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK LMS5xx. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive…

  • CVE-2023-4419CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    The LMS5xx uses hard-coded credentials, which potentially allow low-skilled unauthorized remote attackers to reconfigure settings and /or disrupt the functionality of the device.

  • CVE-2023-40904CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg.

  • CVE-2023-40902CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list and bindnum at /goform/SetIpMacBind.

  • CVE-2023-40901CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at url /goform/setMacFilterCfg.

  • CVE-2023-40900CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetNetControlList.

  • CVE-2023-40899CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg.

  • CVE-2023-40898CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter timeZone at /goform/SetSysTimeCfg.

  • CVE-2023-40897CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter mac at /goform/GetParentControlInfo.

  • CVE-2023-40896CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list and bindnum at /goform/SetIpMacBind.

  • CVE-2023-40895CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetVirtualServerCfg.

  • CVE-2023-40894CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter list at /goform/SetStaticRouteCfg.

  • CVE-2023-40893CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter time at /goform/PowerSaveSet.

  • CVE-2023-40892CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter schedStartTime and schedEndTime at /goform/openSchedWifi.

  • CVE-2023-40891CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC8 v4 US_AC8V4.0si_V16.03.34.06_cn was discovered to contain a stack overflow via parameter firewallEn at /goform/SetFirewallCfg.

  • CVE-2023-39834CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.02

    PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.

  • CVE-2023-40573CriAug 24, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki supports scheduled jobs that contain Groovy scripts. Currently, the job checks the content author of the job for programming right. However, modifying or adding a job…

  • CVE-2023-40572CriAug 24, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The create action is vulnerable to a CSRF attack, allowing script and thus remote code execution when targeting a user with script/programming right, thus compromising the…

  • CVE-2023-41028CriAug 23, 2023
    risk 0.59cvss 9.0epss 0.01

    A stack-based buffer overflow exists in Juplink RX4-1500, a WiFi router, in versions 1.0.2 through 1.0.5. An authenticated attacker can exploit this vulnerability to achieve code execution as root.

  • CVE-2023-40177CriAug 23, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can use the content field of their user profile page to execute arbitrary scripts with programming rights, thus effectively performing rights escalation.…

  • CVE-2023-40176CriAug 23, 2023
    risk 0.58cvss 9.0epss 0.80

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can exploit a stored XSS through their user profile by setting the payload as the value of the time zone user preference. Even though the time zone is…

  • CVE-2023-4041CriAug 23, 2023
    risk 0.64cvss 9.8epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Out-of-bounds Write, Download of Code Without Integrity Check vulnerability in Silicon Labs Gecko Bootloader on ARM (Firmware Update File Parser modules) allows Code Injection, Authentication Bypass.This…

  • CVE-2023-4404CriAug 23, 2023
    risk 0.64cvss 9.8epss 0.01

    The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.7.0.12 due to insufficient restriction on the 'update_core_user' function. This makes it possible for unauthenticated attackers to specify their user…

  • CVE-2020-24113CriAug 22, 2023
    risk 0.59cvss 9.1epss 0.01

    Directory Traversal vulnerability in Contacts File Upload Interface in Yealink W60B version 77.83.0.85, allows attackers to gain sensitive information and cause a denial of service (DoS).

  • CVE-2023-36281CriAug 22, 2023
    risk 0.57cvss 9.8epss 0.03

    An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ or a template.

  • CVE-2022-48565CriAug 22, 2023
    risk 0.64cvss 9.8epss 0.05

    An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.

  • CVE-2022-48522CriAug 22, 2023
    risk 0.64cvss 9.8epss 0.03

    In Perl 5.34.0, function S_find_uninit_var in sv.c has a stack-based crash that can lead to remote code execution or local privilege escalation.

  • CVE-2022-48174CriAug 22, 2023
    risk 0.64cvss 9.8epss 0.03

    There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.

  • CVE-2022-45611CriAug 22, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via capture of user login information.

  • CVE-2022-36648CriAug 22, 2023
    risk 0.65cvss 10.0epss 0.02

    The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers to crash the host qemu and potentially execute code on the host via execute a malformed program in the guest OS. Note: This has been…

  • CVE-2021-33390CriAug 22, 2023
    risk 0.64cvss 9.8epss 0.01

    dpic 2021.04.10 has a use-after-free in thedeletestringbox() function in dpic.y. A different vulnerablility than CVE-2021-32421.

  • CVE-2021-33388CriAug 22, 2023
    risk 0.64cvss 9.8epss 0.01

    dpic 2021.04.10 has a Heap Buffer Overflow in themakevar() function in dpic.y

  • CVE-2021-32292CriAug 22, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.

  • CVE-2023-25915CriAug 21, 2023
    risk 0.64cvss 9.9epss 0.01

    Due to improper input validation, an authenticated remote attacker could execute arbitrary commands on the target system.

  • CVE-2023-4373CriAug 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature.

  • CVE-2023-39660CriAug 21, 2023
    risk 0.57cvss 9.8epss 0.02

    An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.

  • CVE-2023-38961CriAug 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflwo vulnerability in JerryScript Project jerryscript v.3.0.0 allows a remote attacker to execute arbitrary code via the scanner_is_context_needed component in js-scanner-until.c.

  • CVE-2023-38035CriKEVAug 21, 2023
    risk 0.93cvss 9.8epss 1.00

    A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

  • CVE-2023-32002CriAug 21, 2023
    risk 0.64cvss 9.8epss 0.02

    The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. Please note…

  • CVE-2023-31447CriAug 21, 2023
    risk 0.64cvss 9.8epss 0.01

    user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to modify the content of the code segment, insert shellcode, and execute arbitrary code.

  • CVE-2020-28715CriAug 21, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in kdmserver service in LeEco LeTV X43 version V2401RCN02C080080B04121S, allows attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS).

  • CVE-2023-39939CriAug 21, 2023
    risk 0.59cvss 9.1epss 0.01

    SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it.

  • CVE-2023-39751CriAug 21, 2023
    risk 0.64cvss 9.8epss 0.09

    TP-Link TL-WR941ND V6 were discovered to contain a buffer overflow via the pSize parameter at /userRpm/PingIframeRpm.

  • CVE-2023-39750CriAug 21, 2023
    risk 0.65cvss 9.8epss 0.14

    D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the f_ipv6_enable parameter at /bsc_ipv6. This vulnerability is exploited via a crafted POST request.

  • CVE-2023-39749CriAug 21, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the component /adv_resource. This vulnerability is exploited via a crafted GET request.

  • CVE-2023-39747CriAug 21, 2023
    risk 0.64cvss 9.8epss 0.09

    TP-Link WR841N V8, TP-Link TL-WR940N V2, and TL-WR941ND V5 were discovered to contain a buffer overflow via the radiusSecret parameter at /userRpm/WlanSecurityRpm.