VYPR

CVEs

38,103 total · page 400 of 763

  • CVE-2023-23149CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.01

    DEK-1705 <=Firmware:34.23.1 device was discovered to have a command execution vulnerability.

  • CVE-2022-45597CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.00

    ComponentSpace.Saml2 4.4.0 Missing SSL Certificate Validation. NOTE: the vendor does not consider this a vulnerability because the report is only about use of certificates at the application layer (not the transport layer) and "Certificates are exchanged in a controlled fashion…

  • CVE-2023-26864CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in PrestaShop smplredirectionsmanager v.1.1.19 and before allow a remote attacker to gain privileges via the SmplTools::getMatchingRedirectionsFromPartscomponent.

  • CVE-2023-28444CriMar 24, 2023
    risk 0.57cvss 9.9epss 0.01

    angular-server-side-configuration helps configure an angular application at runtime on the server or in a docker container via environment variables. angular-server-side-configuration detects used environment variables in TypeScript (.ts) files during build time of an Angular…

  • CVE-2023-21058CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.00

    In lcsm_SendRrAcquiAssist of lcsm_bcm_assist.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21057CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.00

    In ProfSixDecomTcpSACKoption of RohcPacketCommon, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-20954CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.00

    In SDP_AddAttribute of sdp_db.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2023-20951CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.00

    In gatt_process_prep_write_rsp of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-42499CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In sms_SendMmCpErrMsg of sms_MmConManagement.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2022-42498CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.01

    In Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…

  • CVE-2022-20532CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.00

    In parseTrackFragmentRun() of MPEG4Extractor.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-1177CriMar 24, 2023
    risk 0.59cvss 9.3epss 0.70

    Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.

  • CVE-2022-42948CriKEVMar 24, 2023
    risk 0.76cvss 9.8epss 0.03

    Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

  • CVE-2022-28495CriMar 24, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2023-28445CriMar 24, 2023
    risk 0.57cvss 9.9epss 0.01

    Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. Resizable ArrayBuffers passed to asynchronous functions that are shrunk during the asynchronous operation could result in an out-of-bound read/write. It is unlikely that this has been exploited in…

  • CVE-2023-27034CriMar 23, 2023
    risk 0.68cvss 9.8epss 0.59

    PrestaShop jmsblog 2.5.5 was discovered to contain a SQL injection vulnerability.

  • CVE-2023-28611CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Incorrect authorization in OMICRON StationGuard 1.10 through 2.20 and StationScout 1.30 through 2.20 allows an attacker to bypass intended access restrictions.

  • CVE-2023-28333CriMar 23, 2023
    risk 0.57cvss 9.8epss 0.01

    The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).

  • CVE-2023-26359CriKEVMar 23, 2023
    risk 0.77cvss 9.8epss 0.17

    Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require…

  • CVE-2023-25655CriMar 23, 2023
    risk 0.57cvss 9.8epss 0.01

    baserCMS is a Content Management system. Prior to version 4.7.5, any file may be uploaded on the management system of baserCMS. Version 4.7.5 contains a patch.

  • CVE-2023-25654CriMar 23, 2023
    risk 0.57cvss 9.8epss 0.02

    baserCMS is a Content Management system. Prior to version 4.7.5, there is a Remote Code Execution (RCE) Vulnerability in the management system of baserCMS. Version 4.7.5 contains a patch.

  • CVE-2022-36413CriMar 23, 2023
    risk 0.59cvss 9.1epss 0.03

    Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.

  • CVE-2022-28496CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 discovered to contain a command injection vulnerability in the setPasswordCfg function via the adminuser and adminpassparameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2023-28610CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    The update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified firmware update image. This allows a remote attacker to gain root access to the system.

  • CVE-2022-28497CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the mtd_write_bootloader function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2023-27135CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the enabled parameter at /setting/setWanIeCfg.

  • CVE-2023-27078CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.02

    A command injection issue was found in TP-Link MR3020 v.1_150921 that allows a remote attacker to execute arbitrary commands via a crafted request to the tftp endpoint.

  • CVE-2022-28493CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in TOTOLINK CP900 V6.3c.566 allows attackers to start the Telnet service,

  • CVE-2022-28491CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.05

    TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 contains a command injection vulnerability in the NTPSyncWithHost function via the host_name parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2022-28492CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK Technology CPE with firmware V6.3c.566 ,allows remote attackers to bypass Login.

  • CVE-2023-1050CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in As Koc Energy Web Report System allows SQL Injection. This issue affects Web Report System: before 23.03.10.

  • CVE-2022-22512CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.

  • CVE-2023-24655CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function.

  • CVE-2022-28494CriMar 23, 2023
    risk 0.64cvss 9.8epss 0.03

    TOTOLink outdoor CPE CP900 V6.3c.566_B20171026 is discovered to contain a command injection vulnerability in the setUpgradeFW function via the filename parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.

  • CVE-2023-27100CriMar 22, 2023
    risk 0.67cvss 9.8epss 0.10

    Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.

  • CVE-2023-27060CriMar 22, 2023
    risk 0.64cvss 9.8epss 0.01

    LightCMS v1.3.7 was discovered to contain a remote code execution (RCE) vulnerability via the image:make function.

  • CVE-2023-28667CriMar 22, 2023
    risk 0.64cvss 9.8epss 0.01

    The Lead Generated WordPress Plugin, version <= 1.23, was affected by an unauthenticated insecure deserialization issue. The tve_labels parameter of the tve_api_form_submit action is passed to the PHP unserialize() function without being sanitized or verified, and as a result…

  • CVE-2023-28662CriMar 22, 2023
    risk 0.67cvss 9.8epss 0.42

    The Gift Cards (Gift Vouchers and Packages) WordPress Plugin, version <= 4.3.1, is affected by an unauthenticated SQL injection vulnerability in the template parameter in the wpgv_doajax_voucher_pdf_save_func action.

  • CVE-2023-27224CriMar 22, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in NginxProxyManager v.2.9.19 allows an attacker to execute arbitrary code via a lua script to the configuration file.

  • CVE-2023-27638CriMar 22, 2023
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised tshirtecommerce_design_cart_id GET parameter in order to exploit an insecure parameter in the functions…

  • CVE-2023-27637CriMar 22, 2023
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in the tshirtecommerce (aka Custom Product Designer) component 2.1.4 for PrestaShop. An HTTP request can be forged with a compromised product_id GET parameter in order to exploit an insecure parameter in the front controller file designer.php, which could…

  • CVE-2023-25589CriMar 22, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an unauthenticated remote attacker to create arbitrary users on the platform. A successful exploit allows an attacker to achieve total cluster compromise.

  • CVE-2023-28725CriMar 22, 2023
    risk 0.61cvss 9.1epss 0.21

    General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in…

  • CVE-2023-27855CriMar 22, 2023
    risk 0.68cvss 9.8epss 0.13

    In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where…

  • CVE-2023-1529CriMar 21, 2023
    risk 0.64cvss 9.8epss 0.01

    Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High)

  • CVE-2022-37337CriMar 21, 2023
    risk 0.59cvss 9.1epss 0.03

    A command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2023-27570CriMar 21, 2023
    risk 0.64cvss 9.8epss 0.01

    The eo_tags package before 1.4.19 for PrestaShop allows SQL injection via a crafted _ga cookie.

  • CVE-2023-27569CriMar 21, 2023
    risk 0.64cvss 9.8epss 0.01

    The eo_tags package before 1.3.0 for PrestaShop allows SQL injection via an HTTP User-Agent or Referer header.

  • CVE-2022-45637CriMar 21, 2023
    risk 0.64cvss 9.8epss 0.01

    An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism.

  • CVE-2023-27874CriMar 21, 2023
    risk 0.64cvss 9.9epss 0.01

    IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands. IBM X-Force ID: 249845.