VYPR

CVEs

38,124 total · page 377 of 763

  • CVE-2023-39023CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compass.core.executor.DefaultExecutorManager.configure. This vulnerability is exploited via passing an unchecked argument.

  • CVE-2023-39022CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. This vulnerability is exploited via passing an unchecked argument.

  • CVE-2023-39021CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply. This vulnerability is exploited via passing an unchecked argument.

  • CVE-2023-39020CriJul 28, 2023
    risk 0.57cvss 9.8epss 0.01

    stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument.

  • CVE-2023-39018CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple third parties because there are no…

  • CVE-2023-39017CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple parties because it is…

  • CVE-2023-39016CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLManager.createPool. This vulnerability is exploited via passing an unchecked argument.

  • CVE-2023-39015CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    webmagic-extension v0.9.0 and below was discovered to contain a code injection vulnerability via the component us.codecraft.webmagic.downloader.PhantomJSDownloader.

  • CVE-2023-39013CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Duke v1.2 and below was discovered to contain a code injection vulnerability via the component no.priv.garshol.duke.server.CommonJTimer.init.

  • CVE-2023-39010CriJul 28, 2023
    risk 0.57cvss 9.8epss 0.01

    BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability is exploited by loading a crafted camera calibration file.

  • CVE-2023-38992CriJul 28, 2023
    risk 0.63cvss 9.8epss 0.73

    jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.

  • CVE-2023-37754CriJul 28, 2023
    risk 0.66cvss 9.8epss 0.30

    PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail.

  • CVE-2023-38604CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in watchOS 9.6, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute…

  • CVE-2023-38598CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.6, macOS Big Sur 11.7.9, iOS 15.7.8 and iPadOS 15.7.8, macOS Monterey 12.6.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary…

  • CVE-2023-37285CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, macOS Big Sur 11.7.9, macOS Monterey 12.6.8, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2023-36495CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.6, macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, tvOS 16.6, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2023-34425CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    The issue was addressed with improved memory handling. This issue is fixed in watchOS 9.6, macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, macOS Big Sur 11.7.9, iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2023-33745CriJul 27, 2023
    risk 0.64cvss 9.8epss 0.01

    TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Privilege Management: from the shell available after an adb connection, simply entering the su command provides root access (without requiring a password).

  • CVE-2023-33744CriJul 27, 2023
    risk 0.64cvss 9.8epss 0.01

    TeleAdapt RoomCast TA-2400 1.0 through 3.1 suffers from Use of a Hard-coded Password (PIN): 385521, 843646, and 592671.

  • CVE-2023-33743CriJul 27, 2023
    risk 0.64cvss 9.8epss 0.01

    TeleAdapt RoomCast TA-2400 1.0 through 3.1 is vulnerable to Improper Access Control; specifically, Android Debug Bridge (adb) is available.

  • CVE-2023-3975CriJul 27, 2023
    risk 0.00cvss 9.8epss 0.02

    OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0.

  • CVE-2023-3974CriJul 27, 2023
    risk 0.00cvss 9.8epss 0.01

    OS Command Injection in GitHub repository jgraph/drawio prior to 21.4.0.

  • CVE-2023-3956CriJul 27, 2023
    risk 0.57cvss 9.8epss 0.01

    The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data, modification of data and loss of data due to a missing capability check on the 'events_receiver' function in versions up to, and including, 0.0.9.18. This makes it possible for unauthenticated…

  • CVE-2023-31465CriJul 26, 2023
    risk 0.67cvss 9.8epss 0.46

    An issue was discovered in FSMLabs TimeKeeper 8.0.17 through 8.0.28. By intercepting requests from various timekeeper streams, it is possible to find the getsamplebacklog call. Some query parameters are passed directly in the URL and named arg[x], with x an integer starting from…

  • CVE-2023-33308CriJul 26, 2023
    risk 0.64cvss 9.8epss 0.02

    A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted…

  • CVE-2023-26859CriJul 26, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privileges via the ajaxOrderTracking.php component.

  • CVE-2023-38673CriJul 26, 2023
    risk 0.56cvss 9.6epss 0.02

    PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.

  • CVE-2023-38647CriJul 26, 2023
    risk 0.57cvss 9.8epss 0.02

    An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoader. This unbounded deserialization can likely lead to remote code…

  • CVE-2023-37677CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the component admin_editor.php.

  • CVE-2023-34798CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2022-46898CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal via the "restore SQL data" filename. The Vocera Report Console contains a websocket function that allows for the restoration of the database from a ZIP archive that expects…

  • CVE-2023-35982CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-35981CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-35980CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.02

    There are buffer overflow vulnerabilities in multiple underlying services that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of…

  • CVE-2023-37895CriJul 25, 2023
    risk 0.57cvss 9.8epss 0.03

    Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-beanutils", which contains a class that…

  • CVE-2023-35088CriJul 25, 2023
    risk 0.57cvss 9.8epss 0.02

    Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0.  In the toAuditCkSql method, the groupId, streamId, auditId, and dt are…

  • CVE-2023-35078CriKEVJul 25, 2023
    risk 0.90cvss 9.8epss 1.00

    An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

  • CVE-2023-35066CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software E-Invoice Approval System allows SQL Injection. This issue affects E-Invoice Approval System: before v.20230701.

  • CVE-2023-3046CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Scienta allows SQL Injection. This issue affects Scienta: before 20230630.1953.

  • CVE-2023-32637CriJul 25, 2023
    risk 0.64cvss 9.8epss 0.01

    GBrowse accepts files with any formats uploaded and places them in the area accessible through unauthenticated web requests. Therefore, anyone who can upload files through the product may execute arbitrary code on the server.

  • CVE-2023-32232CriJul 25, 2023
    risk 0.64cvss 9.9epss 0.01

    An issue was discovered in Vasion PrinterLogic Client for Windows before 25.0.0.836. During client installation and repair, a PrinterLogic binary is called by the installer to configure the device. This window is not hidden, and is running with elevated privileges. A standard…

  • CVE-2023-32231CriJul 25, 2023
    risk 0.64cvss 9.9epss 0.01

    An issue was discovered in Vasion PrinterLogic Client for Windows before 25.0.0.818. During installation, binaries gets executed out of a subfolder in C:\Windows\Temp. A standard user can create the folder and path file ahead of time and obtain elevated code execution.

  • CVE-2023-26045CriJul 24, 2023
    risk 0.58cvss 10.0epss 0.01

    NodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment syntax in the user export code path, combined with a path traversal vulnerability, a specially crafted payload could invoke the…

  • CVE-2023-34478CriJul 24, 2023
    risk 0.57cvss 9.8epss 0.02

    Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests. Mitigation: Update to Apache Shiro…

  • CVE-2023-37917CriJul 21, 2023
    risk 0.52cvss 9.1epss 0.01

    KubePi is an opensource kubernetes management panel. A normal user has permission to create/update users, they can become admin by editing the `isadmin` value in the request. As a result any user may take administrative control of KubePi. This issue has been addressed in version…

  • CVE-2022-46295CriJul 21, 2023
    risk 0.57cvss 9.8epss 0.01

    Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a…

  • CVE-2022-46294CriJul 21, 2023
    risk 0.57cvss 9.8epss 0.01

    Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a…

  • CVE-2022-46293CriJul 21, 2023
    risk 0.57cvss 9.8epss 0.01

    Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a…

  • CVE-2022-46292CriJul 21, 2023
    risk 0.57cvss 9.8epss 0.01

    Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a…

  • CVE-2022-46291CriJul 21, 2023
    risk 0.57cvss 9.8epss 0.01

    Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a…