VYPR

CVEs

38,124 total · page 394 of 763

  • CVE-2023-26865CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop bdroppy v.2.2.12 and before allowing a remote attacker to gain privileges via the BdroppyCronModuleFrontController::importProducts component.

  • CVE-2023-24823CriApr 24, 2023
    risk 0.00cvss 9.8epss 0.01

    RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in a type confusion between IPv6 extension headers…

  • CVE-2023-30378CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function "sub_8EE8" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30376CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function "henan_pppoe_user" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30375CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function "getIfIp" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30373CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30372CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30371CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow vulnerability.

  • CVE-2023-30370CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow vulnerability.

  • CVE-2023-24819CriApr 24, 2023
    risk 0.00cvss 9.8epss 0.01

    RIOT-OS, an operating system that supports Internet of Things devices, contains a network stack with the ability to process 6LoWPAN frames. Prior to version 2022.10, an attacker can send a crafted frame to the device resulting in an out of bounds write in the packet buffer. The…

  • CVE-2023-30369CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow.

  • CVE-2023-30368CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function.

  • CVE-2023-25133CriApr 24, 2023
    risk 0.59cvss 9.1epss 0.01

    Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel…

  • CVE-2023-25132CriApr 24, 2023
    risk 0.59cvss 9.1epss 0.01

    Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and…

  • CVE-2023-25131CriApr 24, 2023
    risk 0.61cvss 9.4epss 0.01

    Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for…

  • CVE-2023-22581CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under the context of the web application (the default installation makes the webserver run as the root user).

  • CVE-2023-22577CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Within White Rabbit Switch it's possible as an unauthenticated user to retrieve sensitive information such as password hashes and the SNMP community strings.

  • CVE-2023-28131CriApr 24, 2023
    risk 0.64cvss 9.6epss 0.23

    A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself…

  • CVE-2023-31060CriApr 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Repetier Server through 1.4.10 executes as SYSTEM. This can be leveraged in conjunction with CVE-2023-31059 for full compromise.

  • CVE-2023-31056CriApr 24, 2023
    risk 0.59cvss 9.1epss 0.01

    CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The fixed versions are 5.15.4, 5.16.2, 5.17.3, and 6.0.x.

  • CVE-2023-23753CriApr 23, 2023
    risk 0.64cvss 9.8epss 0.01

    The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be able to read, modify and delete data on it.

  • CVE-2023-30621CriApr 21, 2023
    risk 0.00cvss 9.8epss 0.02

    Gipsy is a multi-purpose discord bot which aim to be as modular and user-friendly as possible. In versions prior to 1.3 users can run command on the host machine with sudoer permission. The `!ping` command when provided with an IP or hostname used to run a bash `ping `…

  • CVE-2023-29924CriApr 21, 2023
    risk 0.64cvss 9.8epss 0.01

    PowerJob V4.3.1 is vulnerable to Incorrect Access Control that allows for remote code execution.

  • CVE-2023-26556CriApr 21, 2023
    risk 0.59cvss 9.1epss 0.01

    io.finnet tss-lib before 2.0.0 can leak a secret key via a timing side-channel attack because it relies on the scalar-multiplication implementation in Go crypto/elliptic, which is not constant time (there is an if statement in a loop). One leak is in ecdsa/keygen/round_2.go.…

  • CVE-2023-2231CriApr 21, 2023
    risk 0.64cvss 9.8epss 0.02

    A vulnerability, which was classified as critical, was found in MAXTECH MAX-G866ac 0.4.1_TBRO_20160314. This affects an unknown part of the component Remote Management. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The exploit…

  • CVE-2023-2227CriApr 21, 2023
    risk 0.56cvss 9.1epss 0.44

    Improper Authorization in GitHub repository modoboa/modoboa prior to 2.1.0.

  • CVE-2023-1892CriApr 21, 2023
    risk 0.56cvss 9.6epss 0.03

    Cross-site Scripting (XSS) - Reflected in GitHub repository sidekiq/sidekiq prior to 7.0.8.

  • CVE-2023-2131CriApr 20, 2023
    risk 0.65cvss 10.0epss 0.02

    Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to remotely execute arbitrary code.

  • CVE-2023-20873CriApr 20, 2023
    risk 0.57cvss 9.8epss 0.01

    In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to…

  • CVE-2023-20864CriApr 20, 2023
    risk 0.69cvss 9.8epss 0.70

    VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.

  • CVE-2023-30076CriApr 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms/print_judges.php?print_judges.php=&se_name=&sub_event_id=.

  • CVE-2023-29528CriApr 20, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1 and massively improved in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus…

  • CVE-2023-27350CriKEVApr 20, 2023
    risk 0.93cvss 9.8epss 1.00

    This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetupCompleted class. The issue results from…

  • CVE-2023-29926CriApr 20, 2023
    risk 0.64cvss 9.8epss 0.01

    PowerJob V4.3.2 has unauthorized interface that causes remote code execution.

  • CVE-2022-29606CriApr 20, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state, which is misleading to a network operator. Improper handling of such port numbers causes inconsistency between intent and flow rules in the network.

  • CVE-2022-29604CriApr 20, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows the CORRUPT state, which is misleading to a network operator. Improper handling of case sensitivity causes inconsistency between intent and flow rules in the network.

  • CVE-2023-23451CriApr 19, 2023
    risk 0.64cvss 9.8epss 0.01

    The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN1 FLEXI ETHERNET GATEW. with serial number <=2311xxxx all Firmware versions, SICK UE410-EN3S04 FLEXI ETHERNET GATEW. with serial…

  • CVE-2021-33970CriApr 19, 2023
    risk 0.65cvss 10.0epss 0.03

    Buffer Overflow vulnerability in Qihoo 360 Chrome v13.0.2170.0 allows attacker to escalate priveleges.

  • CVE-2021-33975CriApr 19, 2023
    risk 0.65cvss 10.0epss 0.01

    Buffer Overflow vulnerability in Qihoo 360 Total Security v10.8.0.1060 and v10.8.0.1213 allows attacker to escalate privileges.

  • CVE-2021-33972CriApr 19, 2023
    risk 0.65cvss 10.0epss 0.01

    Buffer Overflow vulnerability in Qihoo 360 Safe Browser v13.0.2170.0 allows attacker to escalate priveleges.

  • CVE-2023-21096CriApr 19, 2023
    risk 0.64cvss 9.8epss 0.00

    In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L…

  • CVE-2023-2136CriKEVApr 19, 2023
    risk 0.75cvss 9.6epss 0.06

    Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-29527CriApr 19, 2023
    risk 0.64cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions a user without script or programming right may edit a user profile (or any other document) with the wiki editor and add groovy script content. Viewing…

  • CVE-2023-29526CriApr 19, 2023
    risk 0.64cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to display or interact with any page a user cannot access through the combination of the async and display macros. A comment with either…

  • CVE-2023-29525CriApr 19, 2023
    risk 0.64cvss 9.9epss 0.78

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versions of xwiki are subject to code injection in the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration` endpoint.…

  • CVE-2023-29524CriApr 19, 2023
    risk 0.70cvss 9.9epss 0.76

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute anything with the right of the Scheduler Application sheet page. A user without script or programming rights, edit your user profile with the object…

  • CVE-2023-29523CriApr 19, 2023
    risk 0.58cvss 9.9epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted…

  • CVE-2023-29522CriApr 19, 2023
    risk 0.57cvss 9.9epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access…

  • CVE-2023-29519CriApr 19, 2023
    risk 0.52cvss 9.0epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A registered user can perform remote code execution leading to privilege escalation by injecting the proper code in the "property" field of an attachment selector, as a…

  • CVE-2023-29518CriApr 19, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping…