VYPR

CVEs

38,124 total · page 385 of 763

  • CVE-2023-34800CriJun 15, 2023
    risk 0.66cvss 9.8epss 0.29

    D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.

  • CVE-2023-34852CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.

  • CVE-2023-31672CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    In the PrestaShop < 2.4.3 module "Length, weight or volume sell" (ailinear) there is a SQL injection vulnerability.

  • CVE-2023-2686CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow in Wi-Fi Commissioning MicriumOS example in Silicon Labs Gecko SDK v4.2.3 or earlier allows connected device to write payload onto the stack.

  • CVE-2023-29297CriJun 15, 2023
    risk 0.59cvss 9.1epss 0.01

    Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier) are affected by a Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could lead to arbitrary code execution by an admin-privilege authenticated…

  • CVE-2023-21130CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    In btm_ble_periodic_adv_sync_lost of btm_ble_gap.cc, there is a possible remote code execution due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2021-0945CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.00

    In _PMRCreate of the PowerVR kernel driver, a missing bounds check means it is possible to overwrite heap memory via PhysmemNewRamBackedPMR. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2021-0701CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.00

    In PVRSRVBridgeSyncPrimOpCreate of the PowerVR kernel driver, a missing size check means there is a possible integer overflow that could allow out-of-bounds heap access. This could lead to local escalation of privilege with no additional execution privileges needed. User…

  • CVE-2023-34880CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to execute arbitrary code and perform a local file inclusion.

  • CVE-2023-34251CriJun 14, 2023
    risk 0.58cvss 9.9epss 0.02

    Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is possible by embedding malicious PHP code on the administrator screen by a user with page editing privileges. Version 1.7.42 contains…

  • CVE-2023-31746CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.03

    There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated attacker can exploit the vulnerability to execute system commands as the root user.

  • CVE-2023-30150CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    PrestaShop leocustomajax 1.0 and 1.0.0 are vulnerable to SQL Injection via modules/leocustomajax/leoajax.php.

  • CVE-2023-1329CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.01

    A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products.

  • CVE-2023-31671CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop postfinance <= 17.1.13 is vulnerable to SQL Injection via PostfinanceValidationModuleFrontController::postProcess().

  • CVE-2023-34095CriJun 14, 2023
    risk 0.00cvss 9.8epss 0.02

    cpdb-libs provides frontend and backend libraries for the Common Printing Dialog Backends (CPDB) project. In versions 1.0 through 2.0b4, cpdb-libs is vulnerable to buffer overflows via improper use of `scanf(3)`. cpdb-libs uses the `fscanf()` and `scanf()` functions to parse…

  • CVE-2023-25367CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.02

    Siglent SDS 1104X-E SDS1xx4X-E_V6.1.37R9.ADS allows unfiltered user input resulting in Remote Code Execution (RCE) with SCPI interface or web server.

  • CVE-2023-34540CriJun 14, 2023
    risk 0.57cvss 9.8epss 0.02

    Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper (aka the JIRA API wrapper). This vulnerability allows attackers to execute arbitrary code via crafted input. As noted in the "releases/tag" reference,…

  • CVE-2023-34865CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.

  • CVE-2023-34756CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=charset&action=edit.

  • CVE-2023-34755CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the userid parameter at admin/index.php?mode=user&action=edit.

  • CVE-2023-34754CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.03

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.

  • CVE-2023-34753CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.

  • CVE-2023-34752CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.

  • CVE-2023-34751CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.04

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.

  • CVE-2023-34750CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.01

    bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit.

  • CVE-2023-34747CriJun 14, 2023
    risk 0.65cvss 9.8epss 0.20

    File upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload.

  • CVE-2023-32015CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

  • CVE-2023-32014CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

  • CVE-2023-29363CriJun 14, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

  • CVE-2023-29357CriKEVJun 14, 2023
    risk 0.93cvss 9.8epss 1.00

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

  • CVE-2023-24470CriJun 13, 2023
    risk 0.59cvss 9.1epss 0.01

    Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0.

  • CVE-2023-34944CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.

  • CVE-2023-29562CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    TP-Link TL-WPA7510 (EU)_V2_190125 was discovered to contain a stack overflow via the operation parameter at /admin/locale.

  • CVE-2022-28550CriJun 13, 2023
    risk 0.00cvss 9.8epss 0.01

    Matthias-Wandel/jhead jhead 3.06 is vulnerable to Buffer Overflow via shellescape(), jhead.c, jhead. jhead copies strings to a stack buffer when it detects a &i or &o. However, jhead does not check the boundary of the stack buffer. As a result, there will be a stack buffer…

  • CVE-2023-27836CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.02

    TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the devicePwd parameter in the function sub_ 40A80C.

  • CVE-2022-43684CriJun 13, 2023
    risk 0.64cvss 9.9epss 0.02

    ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to Patch 10 Hot Fix 8b * …

  • CVE-2023-3224CriJun 13, 2023
    risk 0.61cvss 9.8epss 0.59

    Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.

  • CVE-2023-34249CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    benjjvi/PyBB is an open source bulletin board. Prior to commit dcaeccd37198ecd3e41ea766d1099354b60d69c2, benjjvi/PyBB is vulnerable to SQL Injection. This vulnerability has been fixed as of commit dcaeccd37198ecd3e41ea766d1099354b60d69c2. As a workaround, a user may be able to…

  • CVE-2023-31541CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    A unrestricted file upload vulnerability was discovered in the ‘Browse and upload images’ feature of the CKEditor v1.2.3 plugin for Redmine, which allows arbitrary files to be uploaded to the server.

  • CVE-2023-27837CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.02

    TP-Link TL-WPA8630P (US)_ V2_ Version 171011 was discovered to contain a command injection vulnerability via the key parameter in the function sub_ 40A774.

  • CVE-2023-35064CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Satos Satos Mobile allows SQL Injection through SOAP Parameter Tampering. This issue affects Satos Mobile: before 20230607.

  • CVE-2023-3050CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Reliance on Cookies without Validation and Integrity Checking in a Security Decision vulnerability in TMT Lockcell allows Privilege Abuse, Authentication Bypass. This issue affects Lockcell: before 15.

  • CVE-2023-3049CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.04

    Unrestricted Upload of File with Dangerous Type vulnerability in TMT Lockcell allows Command Injection. This issue affects Lockcell: before 15.

  • CVE-2023-3048CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authentication Bypass. This issue affects Lockcell: before 15.

  • CVE-2023-3047CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.02

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TMT Lockcell allows SQL Injection. This issue affects Lockcell: before 15.

  • CVE-2023-30766CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Hidden functionality issue exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS command may be executed on the product or the device settings may be altered. Affected products and versions are as follows: KB-AHR04D versions prior to…

  • CVE-2023-30764CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.02

    OS command injection vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS command may be executed on the product or the device settings may be altered. Affected products and versions are as follows: KB-AHR04D versions…

  • CVE-2023-30762CriJun 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper authentication vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS command may be executed on the product or the device settings may be altered. Affected products and versions are as follows: KB-AHR04D versions…

  • CVE-2023-29129CriJun 13, 2023
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.4.0), Mendix SAML (Mendix 8…

  • CVE-2023-27997CriKEVJun 13, 2023
    risk 0.89cvss 9.8epss 0.86

    A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all…