VYPR

CVEs

38,124 total · page 386 of 763

  • CVE-2023-25910CriJun 13, 2023
    risk 0.65cvss 10.0epss 0.01

    A vulnerability has been identified in SIMATIC PCS 7 (All versions < V9.1 SP2 UC04), SIMATIC S7-PM (All versions < V5.7 SP1 HF1), SIMATIC S7-PM (All versions < V5.7 SP2 HF1), SIMATIC STEP 7 V5 (All versions < V5.7). The affected product contains a database management system that…

  • CVE-2023-2278CriJun 13, 2023
    risk 0.57cvss 9.8epss 0.02

    The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' function. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any…

  • CVE-2023-32674CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to buffer overflow.

  • CVE-2023-32673CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Certain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are potentially vulnerable to elevation of privilege.

  • CVE-2023-26295CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.02

    Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation of privileges.

  • CVE-2023-27716CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in freakchicken kafkaUI-lite 1.2.11 allows attackers on the same network to gain escalated privileges for the nodes running on it.

  • CVE-2023-33626CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a stack overflow via the gena.cgi binary.

  • CVE-2023-33625CriJun 12, 2023
    risk 0.69cvss 9.8epss 0.33

    D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability via the ST parameter in the lxmldbc_system() function.

  • CVE-2023-1899CriJun 12, 2023
    risk 0.61cvss 9.4epss 0.00

    Atlas Copco Power Focus 6000 web server is not a secure connection by default, which could allow an attacker to gain sensitive information by monitoring network traffic between user and controller.

  • CVE-2023-1898CriJun 12, 2023
    risk 0.61cvss 9.4epss 0.01

    Atlas Copco Power Focus 6000 web server uses a small amount of session ID numbers. An attacker could enter a session ID number to retrieve data for an active user’s session.

  • CVE-2023-1897CriJun 12, 2023
    risk 0.61cvss 9.4epss 0.00

    Atlas Copco Power Focus 6000 web server does not sanitize the login information stored by the authenticated user’s browser, which could allow an attacker with access to the user’s computer to gain credential information of the controller.

  • CVE-2022-36331CriJun 12, 2023
    risk 0.65cvss 10.0epss 0.01

    Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and…

  • CVE-2023-35042CriJun 12, 2023
    risk 0.67cvss 9.8epss 0.43

    GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023. NOTE: the vendor states that they are unable to reproduce this…

  • CVE-2023-34581CriJun 12, 2023
    risk 0.67cvss 9.8epss 0.03

    Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2

  • CVE-2023-35036CriJun 12, 2023
    risk 0.60cvss 9.1epss 0.13

    In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilities have been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain…

  • CVE-2023-35034CriJun 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow remote code execution by unauthenticated users, aka OSFOURK-24033.

  • CVE-2023-25911CriJun 11, 2023
    risk 0.65cvss 9.9epss 0.02

    The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web application parameters.

  • CVE-2023-22585CriJun 11, 2023
    risk 0.59cvss 9.0epss 0.01

    The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting in the title parameter.

  • CVE-2023-22583CriJun 11, 2023
    risk 0.65cvss 10.0epss 0.01

    The Danfoss AK-EM100 web forms allow for SQL injection in the login forms.

  • CVE-2023-22582CriJun 11, 2023
    risk 0.59cvss 9.0epss 0.01

    The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting.

  • CVE-2023-34364CriJun 9, 2023
    risk 0.64cvss 9.8epss 0.02

    A buffer overflow was discovered in Progress DataDirect Connect for ODBC before 08.02.2770 for Oracle. An overly large value for certain options of a connection string may overrun the buffer allocated to process the string value. This allows an attacker to execute code of their…

  • CVE-2023-3173CriJun 9, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Restriction of Excessive Authentication Attempts in GitHub repository froxlor/froxlor prior to 2.0.20.

  • CVE-2023-29405CriJun 8, 2023
    risk 0.64cvss 9.8epss 0.02

    The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive.…

  • CVE-2023-29404CriJun 8, 2023
    risk 0.64cvss 9.8epss 0.02

    The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive.…

  • CVE-2023-29402CriJun 8, 2023
    risk 0.64cvss 9.8epss 0.02

    The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline characters in their names. Modules…

  • CVE-2023-34566CriJun 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter time at /goform/saveParentControlInfo.

  • CVE-2023-33443CriJun 8, 2023
    risk 0.64cvss 9.8epss 0.04

    Incorrect access control in the administrative functionalities of BES--6024PB-I50H1 VideoPlayTool v2.0.1.0 allow attackers to execute arbitrary administrative commands via a crafted payload sent to the desired endpoints.

  • CVE-2023-2986CriJun 8, 2023
    risk 0.67cvss 9.8epss 0.43

    The Abandoned Cart Lite for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.14.2. This is due to insufficient encryption on the user being supplied during the abandoned cart link decode through the plugin. This allows…

  • CVE-2023-33556CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg.

  • CVE-2023-33496CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode.

  • CVE-2023-31116CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. An incorrect default permission can cause unintended querying of RCS capability via a crafted application.

  • CVE-2023-31114CriJun 7, 2023
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer between spheres can cause unintended querying of the SIM status via a crafted application.

  • CVE-2023-33864CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.04

    StreamReader::ReadFromExternal in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. It uses uint32_t(m_BufferSize-m_InputSize) even though m_InputSize can exceed m_BufferSize.

  • CVE-2023-33863CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.04

    SerialiseValue in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. 0xffffffff is sign-extended to 0xffffffffffffffff (SIZE_MAX) and then there is an attempt to add 1.

  • CVE-2023-33282CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid session. This makes it possible to make backend calls to endpoints in the application.

  • CVE-2023-2530CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    A privilege escalation allowing remote code execution was discovered in the orchestration service.

  • CVE-2023-33553CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipulation of the LoginStatus cookie.

  • CVE-2023-20887CriKEVJun 7, 2023
    risk 0.87cvss 9.8epss 0.98

    Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.

  • CVE-2021-4380CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.04

    The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up to, and including, 1.14.3. This makes it possible for…

  • CVE-2020-36705CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.07

    The Adning Advertising plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the _ning_upload_image function in versions up to, and including, 1.5.5. This makes it possible for unauthenticated attackers to upload arbitrary files on…

  • CVE-2023-33604CriJun 7, 2023
    risk 0.59cvss 9.1epss 0.01

    Imperial CMS v7.5 was discovered to contain an arbitrary file deletion vulnerability via the DelspReFile function in /sp/ListSp.php. This vulnerability is exploited by attackers via a crafted POST request.

  • CVE-2021-4381CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::import_new_layout method in versions up to, and including, 1.6.6. This makes it possible for…

  • CVE-2021-4374CriJun 7, 2023
    risk 0.63cvss 9.1epss 0.16

    The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 3.53.2. This is due to missing authorization and option validation in the process_form.php file. This makes it possible for unauthenticated attackers to…

  • CVE-2021-4370CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is seldom validated. This issue exists in versions up to, and including, 1.6.6. This makes it possible…

  • CVE-2021-4368CriJun 7, 2023
    risk 0.64cvss 9.9epss 0.02

    The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_settings AJAX action. This makes it possible for…

  • CVE-2021-4362CriJun 7, 2023
    risk 0.64cvss 9.8epss 0.01

    The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the kiwi_social_share_get_option() function called via the kiwi_social_share_get_option AJAX action in version 2.1.0. This makes it possible for unauthenticated…

  • CVE-2021-4360CriJun 7, 2023
    risk 0.64cvss 9.9epss 0.01

    The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator role with unrestricted…

  • CVE-2021-4357CriJun 7, 2023
    risk 0.59cvss 9.1epss 0.01

    The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers…

  • CVE-2021-4356CriJun 7, 2023
    risk 0.59cvss 9.0epss 0.02

    The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action.…

  • CVE-2021-4347CriJun 7, 2023
    risk 0.64cvss 9.9epss 0.01

    The function update_shipment_status_email_status_fun in the plugin Advanced Shipment Tracking for WooCommerce in versions up to 3.2.6 is vulnerable to authenticated arbitrary options update. The function allows attackers (including those at customer level) to update any…