VYPR

CVEs

38,124 total · page 375 of 763

  • CVE-2022-40510CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.

  • CVE-2023-3898CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mAyaNet E-Commerce Software allows SQL Injection. This issue affects E-Commerce Software: before 1.1.

  • CVE-2023-3572CriAug 8, 2023
    risk 0.65cvss 10.0epss 0.01

    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device.

  • CVE-2023-3526CriAug 8, 2023
    risk 0.63cvss 9.6epss 0.02

    In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context…

  • CVE-2023-39976CriAug 8, 2023
    risk 0.00cvss 9.8epss 0.01

    log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered.

  • CVE-2023-37483CriAug 8, 2023
    risk 0.64cvss 9.8epss 0.05

    SAP PowerDesigner - version 16.7, has improper access control which might allow an unauthenticated attacker to run arbitrary queries against the back-end database via Proxy.

  • CVE-2023-39526CriAug 7, 2023
    risk 0.52cvss 9.1epss 0.02

    PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through SQL injection and arbitrary file write in the back office. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no…

  • CVE-2023-38940CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the ssid parameter in the form_fast_setting_wifi_set function.

  • CVE-2023-38939CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda F1202 V1.2.0.9 and FH1202 V1.2.0.9 were discovered to contain a stack overflow via the mit_ssid parameter in the formWrlsafeset function.

  • CVE-2023-38938CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda F1202 V1.2.0.9, PA202 V1.1.2.5, PW201A V1.1.2.5 and FH1202 V1.2.0.9 were discovered to contain a stack overflow via the page parameter at /L7Im.

  • CVE-2023-38937CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, AC9 V3.0 V15.03.06.42_multi and AC10 v4.0 V16.03.10.13 were discovered to contain a stack overflow via the list parameter in the…

  • CVE-2023-38936CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6, AC9 V3.0 V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the speed_dir parameter in the…

  • CVE-2023-38935CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC1206 V15.03.06.23, AC8 V4 V16.03.34.06, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and AC9 V3.0 V15.03.06.42_multi were discovered to contain a tack overflow via the list parameter in the formSetQosBand function.

  • CVE-2023-38934CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda F1203 V2.0.1.6, FH1203 V2.0.1.6 and FH1205 V2.0.0.7(775) was discovered to contain a stack overflow via the deviceId parameter in the formSetDeviceName function.

  • CVE-2023-38933CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, FH1203 V2.0.1.6 and AC9 V3.0 V15.03.06.42_multi, and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the formSetClientState function.

  • CVE-2023-38932CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda F1202 V1.2.0.9, PA202 V1.1.2.5, PW201A V1.1.2.5 and FH1202 V1.2.0.9 were discovered to contain a stack overflow via the page parameter in the SafeEmailFilter function.

  • CVE-2023-38931CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V1.0 V15.03.06.23, AC1206 V15.03.06.23, AC8 v4 V16.03.34.06, AC6 V2.0 V15.03.06.23, AC7 V1.0 V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0 V15.03.06.28, AC10 v4.0 V16.03.10.13 and FH1203 V2.0.1.6 were discovered to contain a stack overflow via the list parameter in the…

  • CVE-2023-38930CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC7 V1.0,V15.03.06.44, F1203 V2.0.1.6, AC5 V1.0,V15.03.06.28, AC9 V3.0,V15.03.06.42_multi and FH1205 V2.0.0.7(775) were discovered to contain a stack overflow via the deviceId parameter in the addWifiMacFilter function.

  • CVE-2023-38929CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda 4G300 v1.01.42 was discovered to contain a stack overflow via the page parameter at /VirtualSer.

  • CVE-2023-38928CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Netgear R7100LG 1.0.0.78 was discovered to contain a command injection vulnerability via the password parameter at usb_remote_invite.cgi.

  • CVE-2023-38044CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

  • CVE-2023-34477CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

  • CVE-2023-34476CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

  • CVE-2023-23758CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

  • CVE-2023-23757CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.

  • CVE-2023-32090CriAug 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials

  • CVE-2023-4188CriAug 5, 2023
    risk 0.00cvss 9.1epss 0.01

    SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

  • CVE-2023-36095CriAug 5, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include from_math_prompt and from_colored_object_prompt.

  • CVE-2023-33367CriAug 5, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing unauthenticated attackers to write PHP files on the server's root directory, resulting in remote code execution.

  • CVE-2023-39344CriAug 4, 2023
    risk 0.00cvss 10.0epss 0.02

    social-media-skeleton is an uncompleted social media project. A SQL injection vulnerability in the project allows UNION based injections, which indirectly leads to remote code execution. Commit 3cabdd35c3d874608883c9eaf9bf69b2014d25c1 contains a fix for this issue.

  • CVE-2023-39551CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    PHPGurukul Online Security Guards Hiring System v.1.0 is vulnerable to SQL Injection via osghs/admin/search.php.

  • CVE-2023-38702CriAug 4, 2023
    risk 0.64cvss 9.9epss 0.01

    Knowage is an open source analytics and business intelligence suite. Starting in the 6.x.x branch and prior to version 8.1.8, the endpoint `/knowage/restful-services/dossier/importTemplateFile` allows authenticated users to upload `template file` on the server, but does not need…

  • CVE-2023-39107CriAug 4, 2023
    risk 0.59cvss 9.1epss 0.01

    An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to overwrite root-owned files by using hardlinks.

  • CVE-2023-38699CriAug 4, 2023
    risk 0.52cvss 9.1epss 0.00

    MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0, a call to requests with `verify=False` disables SSL certificate checks. This rule enforces always verifying SSL certificates for methods in the Requests…

  • CVE-2023-38692CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.03

    CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command injection vulnerability in the installation function in module management. The vulnerability has been fixed in v1.3.1. There are no known workarounds aside from…

  • CVE-2023-33379CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Connected IO v2.1.0 and prior has a misconfiguration in their MQTT broker used for management and device communication, which allows devices to connect to the broker and issue commands to other device, impersonating Connected IO management platform and sending commands to all of…

  • CVE-2023-33378CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Connected IO v2.1.0 and prior has an argument injection vulnerability in its AT command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices.

  • CVE-2023-33377CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.02

    Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, enabling attackers to execute arbitrary OS commands on devices.

  • CVE-2023-33376CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Connected IO v2.1.0 and prior has an argument injection vulnerability in its iptables command message in its communication protocol, enabling attackers to execute arbitrary OS commands on devices.

  • CVE-2023-33375CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Connected IO v2.1.0 and prior has a stack-based buffer overflow vulnerability in its communication protocol, enabling attackers to take control over devices.

  • CVE-2023-33374CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS commands for devices to execute. Attackers abusing this dangerous functionality may issue all devices OS commands to execute, resulting in…

  • CVE-2023-33373CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.00

    Connected IO v2.1.0 and prior keeps passwords and credentials in clear-text format, allowing attackers to exfiltrate the credentials and use them to impersonate the devices.

  • CVE-2023-33372CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.01

    Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication using MQTT. An attacker who gained access to these credentials is able to connect to the MQTT broker and send messages on behalf of devices,…

  • CVE-2023-39143CriAug 4, 2023
    risk 0.70cvss 9.8epss 0.80

    PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).

  • CVE-2023-38686CriAug 4, 2023
    risk 0.53cvss 9.3epss 0.00

    Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent does not verify SMTP servers' certificates. This makes Sydent's emails vulnerable to interception via a man-in-the-middle (MITM) attack.…

  • CVE-2023-37470CriAug 4, 2023
    risk 0.65cvss 10.0epss 0.01

    Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vulnerability could potentially allow remote code execution on one's Metabase server. The core issue…

  • CVE-2023-36480CriAug 4, 2023
    risk 0.57cvss 9.8epss 0.02

    The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 some of the messages received from the server contain Java objects that the client deserializes when it…

  • CVE-2023-29689CriAug 4, 2023
    risk 0.70cvss 9.8epss 0.53

    PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI) flaw. This vulnerability allows a malicious attacker to send customized commands to the server and execute arbitrary code on the affected system.

  • CVE-2023-38941CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.02

    django-sspanel v2022.2.2 was discovered to contain a remote command execution (RCE) vulnerability via the component sspanel/admin_view.py -> GoodsCreateView._post.

  • CVE-2023-36139CriAug 4, 2023
    risk 0.64cvss 9.8epss 0.00

    In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts.