VYPR

CVEs

38,124 total · page 373 of 763

  • CVE-2023-38861CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.02

    An issue in Wavlink WL_WNJ575A3 v.R75A3_V1410_220513 allows a remote attacker to execute arbitrary code via username parameter of the set_sys_adm function in adm.cgi.

  • CVE-2023-39662CriAug 15, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.

  • CVE-2023-39661CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.

  • CVE-2023-39659CriAug 15, 2023
    risk 0.57cvss 9.8epss 0.02

    An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool._run component.

  • CVE-2023-38915CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in Wolf-leo EasyAdmin8 v.1.0 allows a remote attacker to execute arbtirary code via the upload type function.

  • CVE-2023-38896CriAug 15, 2023
    risk 0.57cvss 9.8epss 0.02

    An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colored_object_prompt functions.

  • CVE-2023-38889CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).

  • CVE-2023-38860CriAug 15, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.

  • CVE-2023-35082CriKEVAug 15, 2023
    risk 0.90cvss 9.8epss 1.00

    An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

  • CVE-2023-21287CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.01

    In multiple locations, there is a possible code execution due to type confusion. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-40020CriAug 14, 2023
    risk 0.00cvss 9.9epss 0.00

    PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v3/admin.controller.ts` did not correctly verify whether the user was an administrator (High Level) or moderator (Low Level) causing the request to continue…

  • CVE-2023-21242CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.01

    In isServerCertChainValid of InsecureEapNetworkHandler.java, there is a possible way to trust an imposter server due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-20965CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.01

    In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-3435CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.01

    The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.

  • CVE-2023-39293CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.02

    A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.

  • CVE-2023-39292CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations.

  • CVE-2023-29468CriAug 14, 2023
    risk 0.65cvss 9.8epss 0.10

    The Texas Instruments (TI) WiLink WL18xx MCP driver does not limit the number of information elements (IEs) of type XCC_EXT_1_IE_ID or XCC_EXT_2_IE_ID that can be parsed in a management frame. Using a specially crafted frame, a buffer overflow can be triggered that can…

  • CVE-2023-32748CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.01

    The Linux DVS server component of Mitel MiVoice Connect through 19.3 SP2 (22.24.1500.0) could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.

  • CVE-2023-40359CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.01

    xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e., neither alphanumeric nor underscore), aka a pointer/overflow issue. This can only occur for xterm installations that are configured at compile time to use a certain…

  • CVE-2023-4322CriAug 14, 2023
    risk 0.00cvss 9.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.

  • CVE-2023-30187CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.02

    An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.

  • CVE-2023-30186CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.02

    A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.

  • CVE-2023-37847CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.01

    novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.

  • CVE-2023-3267CriAug 14, 2023
    risk 0.59cvss 9.1epss 0.02

    When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. The username is passed without sanitization into CMD running as NT/Authority System. An authenticated attacker can leverage this vulnerability to execute…

  • CVE-2023-3266CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.01

    A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checks if LDAP authentication is selected.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel…

  • CVE-2023-3265CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta-characters from the username, allowing an attacker to login into the application with the default user "cyberpower" by appending a non-printable character.An unauthenticated attacker…

  • CVE-2023-3259CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.01

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to authentication bypass. By manipulating the IP address field in the "iBootPduSiteAuth" cookie, a malicious agent can direct the device to connect to a rouge database.Successful exploitation…

  • CVE-2023-39403CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

  • CVE-2023-39402CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

  • CVE-2023-39401CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

  • CVE-2023-39400CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

  • CVE-2023-39399CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

  • CVE-2023-39398CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

  • CVE-2023-39385CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnerability may cause unauthorized access.

  • CVE-2021-46895CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Vulnerability of defects introduced in the design process in the Multi-Device Task Center. Successful exploitation of this vulnerability will cause the hopped app to bypass the app lock and reset the device that initiates the hop.

  • CVE-2023-39405CriAug 13, 2023
    risk 0.64cvss 9.8epss 0.00

    Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation of this vulnerability may cause other apps to be executed with escalated privileges.

  • CVE-2023-3452CriAug 12, 2023
    risk 0.57cvss 9.8epss 0.07

    The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and including, 3.0.4 via the 'wp_abspath' parameter. This allows unauthenticated attackers to include and execute arbitrary remote code on the server, provided that allow_url_include is…

  • CVE-2021-28411CriAug 11, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi version 3.4.0, allows remote attackers to escalate privileges.

  • CVE-2021-27523CriAug 11, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in open-falcon dashboard version 0.2.0, allows remote attackers to gain, modify, and delete sensitive information via crafted POST request to register interface.

  • CVE-2021-26505CriAug 11, 2023
    risk 0.57cvss 9.8epss 0.01

    Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code via hello.utils.extend function.

  • CVE-2020-36082CriAug 11, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute arbitrary code and escalate privileges via crafted webshell file to upload module.

  • CVE-2020-36034CriAug 11, 2023
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows remote attacker to execute arbitrary code, escalate privilieges, and gain sensitive information via crafted payload to id parameter in manage_user.php.

  • CVE-2020-27544CriAug 11, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in FoldingAtHome Client Advanced Control GUI before commit 9b619ae64443997948a36dda01b420578de1af77, allows remote attackers to execute arbitrary code via crafted payload to function parse_message in file Connection.py.

  • CVE-2020-27514CriAug 11, 2023
    risk 0.59cvss 9.1epss 0.01

    Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog version 2.1.15, allows remote attackers to delete arbitrary files and cause a denial of service (DoS).

  • CVE-2023-40267CriAug 11, 2023
    risk 0.57cvss 9.8epss 0.01

    GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.

  • CVE-2023-40260CriAug 11, 2023
    risk 0.59cvss 9.1epss 0.01

    EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication) requirement if the first factor (username and password) is known, because the first factor is sufficient to change an account's email address, and the product would then send MFA codes…

  • CVE-2023-3824CriAug 11, 2023
    risk 0.62cvss 9.4epss 0.22

    In PHP version 8.0.* before 8.0.30,  8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or RCE.

  • CVE-2023-40256CriAug 11, 2023
    risk 0.64cvss 9.8epss 0.00

    A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed untrusted clients to interact with the RabbitMQ service. This was caused by improper validation of the client certificate due to misconfiguration of the RabbitMQ service. Exploiting…

  • CVE-2023-39806CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.01

    iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.

  • CVE-2023-39805CriAug 10, 2023
    risk 0.64cvss 9.8epss 0.01

    iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.