VYPR

CVEs

38,124 total · page 384 of 763

  • CVE-2023-3110CriJun 21, 2023
    risk 0.62cvss 9.6epss 0.00

    Description: A vulnerability in SiLabs Unify Gateway 1.3.1 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.

  • CVE-2023-0972CriJun 21, 2023
    risk 0.62cvss 9.6epss 0.00

    Description: A vulnerability in SiLabs Z/IP Gateway 7.18.01 and earlier allows an unauthenticated attacker within Z-Wave range to overflow a stack buffer, leading to arbitrary code execution.

  • CVE-2023-0971CriJun 21, 2023
    risk 0.62cvss 9.6epss 0.00

    A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.

  • CVE-2023-33584CriJun 21, 2023
    risk 0.68cvss 9.8epss 0.14

    Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields…

  • CVE-2023-34340CriJun 21, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Authentication vulnerability in Apache Software Foundation Apache Accumulo. This issue affects Apache Accumulo: 2.1.0. Accumulo 2.1.0 contains a defect in the user authentication process that may succeed when invalid credentials are provided. Users are advised to…

  • CVE-2023-34563CriJun 20, 2023
    risk 0.65cvss 9.8epss 0.14

    netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication.

  • CVE-2023-35885CriJun 20, 2023
    risk 0.70cvss 9.8epss 0.75

    CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.

  • CVE-2023-35166CriJun 20, 2023
    risk 0.62cvss 9.9epss 0.62

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension. This has been patched in XWiki 15.1-rc-1 and 14.10.5.

  • CVE-2023-34600CriJun 20, 2023
    risk 0.66cvss 9.8epss 0.24

    Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection.

  • CVE-2023-34541CriJun 20, 2023
    risk 0.57cvss 9.8epss 0.01

    Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.

  • CVE-2020-21489CriJun 20, 2023
    risk 0.57cvss 9.8epss 0.01

    File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component.

  • CVE-2020-21474CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in NucleusCMS v.3.71 allows a remote attacker to execute arbitrary code via the /nucleus/plugins/skinfiles/?dir=rsd parameter.

  • CVE-2020-21174CriJun 20, 2023
    risk 0.57cvss 9.8epss 0.01

    File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.

  • CVE-2020-20735CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in LJCMS v.4.3.R60321 allows a remote attacker to execute arbitrary code via the ljcms/index.php parameter.

  • CVE-2020-20718CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in PluckCMS v.4.7.10 dev versions allows a remote attacker to execute arbitrary code via a crafted image file to the the save_file() parameter.

  • CVE-2020-20703CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.02

    Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.

  • CVE-2020-20413CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in WUZHICMS v.4.1.0 allows a remote attacker to execute arbitrary code via the checktitle() function in admin/content.php.

  • CVE-2023-35854CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.06

    Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is…

  • CVE-2023-34159CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.00

    Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerability may lead to privilege escalation, which affects availability and confidentiality.

  • CVE-2023-31411CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. The lack of authentication in the API allows the attacker to potentially compromise the functionality of the EventCam App.

  • CVE-2023-31410CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.00

    A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK EventCam App. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive…

  • CVE-2023-2907CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Marksoft allows SQL Injection. This issue affects Marksoft: through Mobile:v.7.1.7 ; Login:1.4 ; API:20230605.

  • CVE-2023-27992CriKEVJun 19, 2023
    risk 0.82cvss 9.8epss 0.83

    The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to…

  • CVE-2023-34417CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 114.

  • CVE-2023-34416CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox…

  • CVE-2023-29542CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox and Thunderbird on…

  • CVE-2023-29534CriJun 19, 2023
    risk 0.52cvss 9.1epss 0.01

    Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This…

  • CVE-2023-25736CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affects Firefox < 110.

  • CVE-2019-25136CriJun 19, 2023
    risk 0.65cvss 10.0epss 0.01

    A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox escape. This vulnerability affects Firefox < 70.

  • CVE-2023-32216CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…

  • CVE-2023-29531CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects…

  • CVE-2023-27396CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    FINS (Factory Interface Network Service) is a message communication protocol, which is designed to be used in closed FA (Factory Automation) networks, and is used in FA networks composed of OMRON products. Multiple OMRON products that implement FINS protocol contain following…

  • CVE-2023-35857CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    In Siren Investigate before 13.2.2, session keys remain active even after logging out.

  • CVE-2023-35856CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow in Nintendo Mario Kart Wii RMCP01, RMCE01, RMCJ01, and RMCK01 can be exploited by a game client to execute arbitrary code on a client's machine via a crafted packet.

  • CVE-2023-35855CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying the lservercfgfile console variable.

  • CVE-2023-35853CriJun 19, 2023
    risk 0.00cvss 9.8epss 0.01

    In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6.0.13 by disabling Lua unless allow-rules is true in the security lua configuration section.

  • CVE-2023-35839CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload.

  • CVE-2023-35813CriJun 17, 2023
    risk 0.71cvss 9.8epss 0.87

    Multiple Sitecore products allow remote code execution. This affects Experience Manager, Experience Platform, and Experience Commerce through 10.3.

  • CVE-2014-125106CriJun 17, 2023
    risk 0.57cvss 9.8epss 0.01

    Nanopb before 0.3.1 allows size_t overflows in pb_dec_bytes and pb_dec_string.

  • CVE-2023-35784CriJun 16, 2023
    risk 0.00cvss 9.8epss 0.01

    A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.

  • CVE-2023-34832CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-Link Archer AX10(EU)_V1.2_230220 was discovered to contain a buffer overflow via the function FUN_131e8 - 0x132B4.

  • CVE-2023-34659CriJun 16, 2023
    risk 0.65cvss 9.8epss 0.12

    jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.

  • CVE-2023-25366CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.00

    In Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS, insecure SCPI interface discloses web password.

  • CVE-2023-34548CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter.

  • CVE-2022-48472CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution. Affected product versions include:BiSheng-WNM versions OTA-BiSheng-FW-2.0.0.211-beta,BiSheng-WNM FW 3.0.0.325,BiSheng-WNM FW 2.0.0.211.

  • CVE-2023-34157CriJun 16, 2023
    risk 0.65cvss 10.0epss 0.00

    Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may cause repeated pop-up windows of the app.

  • CVE-2023-35708CriJun 16, 2023
    risk 0.71cvss 9.8epss 0.97

    In Progress MOVEit Transfer before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain…

  • CVE-2023-32754CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    Thinking Software Efence login function has insufficient validation for user input. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify or delete database.

  • CVE-2023-32753CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    OMICARD EDM’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system commands or disrupt service.

  • CVE-2023-32752CriJun 16, 2023
    risk 0.64cvss 9.8epss 0.01

    L7 Networks InstantScan IS-8000 & InstantQoS IQ-8000’s file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary system…