VYPR

CVEs

38,104 total · page 395 of 763

  • CVE-2023-1873CriApr 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Faturamatik Bircard allows SQL Injection. This issue affects Bircard: before 23.04.05.

  • CVE-2023-27844CriApr 17, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShopleurlrewrite v.1.0 and before allow a remote attacker to gain privileges via the Dispatcher::getController component.

  • CVE-2023-1723CriApr 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veragroup Mobile Assistant allows SQL Injection. This issue affects Mobile Assistant: before 21.S.2343.

  • CVE-2023-30771CriApr 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database. This problem is fixed from version…

  • CVE-2023-24831CriApr 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 through 0.13.3. Attackers could login without authorization. This is fixed in 0.13.4.

  • CVE-2023-30537CriApr 16, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with the right to add an object on a page can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root…

  • CVE-2023-29511CriApr 16, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., it's own user page), can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki…

  • CVE-2023-29509CriApr 16, 2023
    risk 0.63cvss 9.9epss 0.76

    XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is…

  • CVE-2023-29507CriApr 16, 2023
    risk 0.52cvss 9.1epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. The Document script API returns directly a DocumentAuthors allowing to set any authors to the document, which in consequence can allow subsequent executions of scripts since this author is…

  • CVE-2023-29214CriApr 16, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the included…

  • CVE-2023-29212CriApr 16, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the included…

  • CVE-2023-29211CriApr 16, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights `WikiManager.DeleteWiki` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper…

  • CVE-2022-48312CriApr 16, 2023
    risk 0.59cvss 9.1epss 0.00

    The HwPCAssistant module has the out-of-bounds read/write vulnerability. Successful exploitation of this vulnerability may affect confidentiality and integrity.

  • CVE-2021-33990CriApr 16, 2023
    risk 0.68cvss 9.8epss 0.12

    Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not demonstrate how an unauthorized user can…

  • CVE-2022-34128CriApr 16, 2023
    risk 0.67cvss 9.8epss 0.08

    The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.

  • CVE-2018-17452CriApr 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to the validate_localhost function in url_blocker.rb.

  • CVE-2020-29007CriApr 15, 2023
    risk 0.64cvss 9.8epss 0.02

    The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary…

  • CVE-2023-29210CriApr 15, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the notification preferences macros can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access…

  • CVE-2023-29209CriApr 15, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the legacy notification activity macro can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full…

  • CVE-2023-29206CriApr 15, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author of a JavaScript xobject or StyleSheet xobject added in a XWiki document, so until now it was possible for a user having only Edit Right to create such object…

  • CVE-2023-29205CriApr 15, 2023
    risk 0.64cvss 9.9epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. The HTML macro does not systematically perform a proper neutralization of script-related html tags. As a result, any user able to use the html macro in XWiki, is able to introduce an XSS…

  • CVE-2023-29202CriApr 15, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. The RSS macro that is bundled in XWiki included the content of the feed items without any cleaning in the HTML output when the parameter `content` was set to `true`. This allowed arbitrary…

  • CVE-2023-29201CriApr 15, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1, only escaped `` and ``-tags but neither attributes that can be used to inject scripts…

  • CVE-2023-2106CriApr 15, 2023
    risk 0.57cvss 9.8epss 0.01

    Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20.

  • CVE-2022-2525CriApr 15, 2023
    risk 0.57cvss 9.8epss 0.01

    Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20.

  • CVE-2023-2027CriApr 15, 2023
    risk 0.64cvss 9.8epss 0.01

    The ZM Ajax Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.2. This is due to insufficient verification on the user being supplied during a Facebook login through the plugin. This makes it possible for…

  • CVE-2023-26463CriApr 15, 2023
    risk 0.64cvss 9.8epss 0.02

    strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two different purposes within the same function. There is initially incorrect access control, later followed by an expired pointer dereference. One attack vector is…

  • CVE-2021-46880CriApr 15, 2023
    risk 0.00cvss 9.8epss 0.01

    x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.

  • CVE-2023-27654CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in WHOv.1.0.28, v.1.0.30, v.1.0.32 allows an attacker to cause a escalation of privileges via the TTMultiProvider component.

  • CVE-2023-29199CriApr 14, 2023
    risk 0.57cvss 9.8epss 0.04

    There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass `handleException()` and leak unsanitized host exceptions which can be used to escape the sandbox and run arbitrary code in host…

  • CVE-2022-3748CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication Bypass. This issue affects Access Management: from 6.5.0 through 7.2.0.

  • CVE-2023-29805CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.02

    WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function.

  • CVE-2023-29803CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectVPN function.

  • CVE-2023-29802CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.

  • CVE-2023-29801CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parameters in the setSyslogCfg function.

  • CVE-2023-29800CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.

  • CVE-2023-29799CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.

  • CVE-2023-29798CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function.

  • CVE-2023-1833CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass by Primary Weakness vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass. This issue affects Redline Router: before 7.17.

  • CVE-2023-1803CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass by Alternate Name vulnerability in DTS Electronics Redline Router firmware allows Authentication Bypass. This issue affects Redline Router: before 7.17.

  • CVE-2022-45174CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication for SAML Users can occur under the /login/backup_code endpoint and the /api/v1/vdeskintegration/challenge endpoint. The correctness of the TOTP is not checked properly, and…

  • CVE-2022-45173CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker can modify the response,…

  • CVE-2023-27648CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.03

    Directory Traversal vulnerability found in T-ME Studios Change Color of Keypad v.1.275.1.277 allows a remote attacker to execute arbitrary code via the dex file in the internal storage.

  • CVE-2023-1617CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules).  This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 visualization on affected devices. The impact of this…

  • CVE-2022-47027CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionary traversal vulnerability and achieve arbitrary code execution.

  • CVE-2023-1863CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Water Metering Software allows Command Line Execution through SQL Injection. This issue affects Water Metering Software: before 23.04.06.

  • CVE-2023-29622CriApr 14, 2023
    risk 0.64cvss 9.8epss 0.02

    Purchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /purchase_order/admin/login.php.

  • CVE-2023-26918CriApr 14, 2023
    risk 0.67cvss 9.8epss 0.06

    Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\FileReplicationPro allows Everyone:(F) access.

  • CVE-2023-27748CriApr 13, 2023
    risk 0.64cvss 9.8epss 0.01

    BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attackers to upload crafted firmware which contains backdoors and enables arbitrary code execution.

  • CVE-2023-27746CriApr 13, 2023
    risk 0.64cvss 9.8epss 0.02

    BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracked via a brute force attack if the WPA2 handshake is intercepted.