VYPR

CVEs

38,103 total · page 402 of 763

  • CVE-2023-25616CriMar 14, 2023
    risk 0.64cvss 9.9epss 0.01

    In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection vulnerability which could allow an attacker to gain access to resources that are allowed by extra privileges. Successful attack…

  • CVE-2023-23857CriMar 14, 2023
    risk 0.64cvss 9.9epss 0.01

    Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting…

  • CVE-2023-27582CriMar 13, 2023
    risk 0.52cvss 9.1epss 0.01

    maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a full authentication bypass if SASL authorization username is specified when using the PLAIN authentication mechanisms. Instead of validating the specified…

  • CVE-2023-27052CriMar 13, 2023
    risk 0.64cvss 9.8epss 0.01

    E-Commerce System v1.0 ws discovered to contain a SQL injection vulnerability via the id parameter at /admin/delete_user.php.

  • CVE-2023-27583CriMar 13, 2023
    risk 0.00cvss 9.8epss 0.01

    PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the hard-coded JWT key to sign JWT token and perform any actions as a user with admin privileges. Version 3.1.3 has a patch for the…

  • CVE-2023-0354CriMar 13, 2023
    risk 0.59cvss 9.1epss 0.01

    The Akuvox E11 web server can be accessed without any user authentication, and this could allow an attacker to access sensitive information, as well as create and download packet captures with known default URLs.

  • CVE-2023-0352CriMar 13, 2023
    risk 0.59cvss 9.1epss 0.01

    The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the device key file. An attacker could then use this page to reset the password back to the default.

  • CVE-2023-0345CriMar 13, 2023
    risk 0.64cvss 9.8epss 0.01

    The Akuvox E11 secure shell (SSH) server is enabled by default and can be accessed by the root user. This password cannot be changed by the user.

  • CVE-2023-25207CriMar 13, 2023
    risk 0.64cvss 9.8epss 0.01

    PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.

  • CVE-2023-25279CriMar 13, 2023
    risk 0.66cvss 9.8epss 0.31

    OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload.

  • CVE-2021-45423CriMar 13, 2023
    risk 0.64cvss 9.8epss 0.01

    A Buffer Overflow vulnerabilityexists in Pev 0.81 via the pe_exports function from exports.c.. The array offsets_to_Names is dynamically allocated on the stack using exp->NumberOfFunctions as its size. However, the loop uses exp->NumberOfNames to iterate over it and set its…

  • CVE-2023-0037CriMar 13, 2023
    risk 0.64cvss 9.8epss 0.04

    The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

  • CVE-2023-27063CriMar 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the DNSDomainName parameter in the formModifyDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2023-27061CriMar 13, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the wifiFilterListRemark parameter in the modifyWifiFilterRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.

  • CVE-2023-24762CriMar 13, 2023
    risk 0.64cvss 9.8epss 0.03

    OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.

  • CVE-2023-28154CriMar 13, 2023
    risk 0.57cvss 9.8epss 0.01

    Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.

  • CVE-2022-48367CriMar 12, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.

  • CVE-2023-27905CriMar 10, 2023
    risk 0.63cvss 9.6epss 0.02

    Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting.

  • CVE-2023-27898CriMar 10, 2023
    risk 0.56cvss 9.6epss 0.02

    Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site…

  • CVE-2023-25143CriMar 10, 2023
    risk 0.64cvss 9.8epss 0.02

    An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products.

  • CVE-2023-1198CriMar 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities allows SQL Injection. This issue affects Starcities: through 1.3.

  • CVE-2022-33257CriMar 10, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.

  • CVE-2022-33256CriMar 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory corruption due to improper validation of array index in Multi-mode call processor.

  • CVE-2023-27853CriMar 10, 2023
    risk 0.65cvss 9.8epss 0.20

    NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device.

  • CVE-2023-27852CriMar 10, 2023
    risk 0.64cvss 9.8epss 0.01

    NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a buffer overflow vulnerability in various CGI mechanisms that could allow an attacker to execute arbitrary code on the device.

  • CVE-2021-33360CriMar 10, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s).

  • CVE-2023-24774CriMar 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.

  • CVE-2023-1091CriMar 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpata Licensed Warehousing Automation System allows Command Line Execution through SQL Injection. This issue affects Licensed Warehousing Automation System: through 2023.1.01.

  • CVE-2023-1307CriMar 10, 2023
    risk 0.57cvss 9.8epss 0.01

    Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.

  • CVE-2023-27214CriMar 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate and todate parameters at /eduauth/student/between-date-reprtsdetails.php.

  • CVE-2023-27213CriMar 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /eduauth/student/search.php.

  • CVE-2023-27210CriMar 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/view_order.php.

  • CVE-2023-27207CriMar 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.

  • CVE-2023-27205CriMar 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.

  • CVE-2023-27204CriMar 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.

  • CVE-2023-27203CriMar 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.

  • CVE-2023-27202CriMar 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php.

  • CVE-2023-26957CriMar 9, 2023
    risk 0.59cvss 9.1epss 0.01

    onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins.

  • CVE-2023-1287CriMar 9, 2023
    risk 0.59cvss 9.0epss 0.01

    An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.

  • CVE-2023-1251CriMar 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akinsoft Wolvox. This issue affects Wolvox: before 8.02.03.

  • CVE-2023-24777CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.

  • CVE-2023-1283CriMar 8, 2023
    risk 0.58cvss 10.0epss 0.01

    Code Injection in GitHub repository builderio/qwik prior to 0.21.0.

  • CVE-2021-33353CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.02

    Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting.

  • CVE-2021-33352CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field.

  • CVE-2021-33351CriMar 8, 2023
    risk 0.59cvss 9.0epss 0.01

    Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field.

  • CVE-2023-24782CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit.

  • CVE-2023-22889CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.

  • CVE-2023-26489CriMar 8, 2023
    risk 0.57cvss 9.9epss 0.01

    wasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a bug on x86_64 targets where address-mode computation mistakenly would calculate a 35-bit effective address instead of WebAssembly's defined 33-bit effective…

  • CVE-2023-27482CriMar 8, 2023
    risk 0.71cvss 10.0epss 0.72

    homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1…

  • CVE-2023-26922CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the shell_exect parameter to the \www\pages\matrix-gui-2.0 endpoint.