VYPR

CVEs

38,103 total · page 403 of 763

  • CVE-2023-24773CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list.

  • CVE-2023-26261CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication bypass by stealing the session of another connected user. The fixed versions are WAAP Gateway & Cloud 6.11.0 and 6.5.6-patch15.

  • CVE-2023-25395CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU V7.4cu.2313_B20191024 router was discovered to contain a command injection vulnerability via the ou parameter at /setting/delStaticDhcpRules.

  • CVE-2023-1267CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ulkem Company PtteM Kart. This issue affects PtteM Kart: before 2.1.

  • CVE-2023-1269CriMar 8, 2023
    risk 0.57cvss 9.8epss 0.01

    Use of Hard-coded Credentials in GitHub repository alextselegidis/easyappointments prior to 1.5.0.

  • CVE-2023-0090CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such access is a non-standard configuration.…

  • CVE-2023-24780CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/columns.

  • CVE-2023-27479CriMar 7, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause…

  • CVE-2023-24775CriMar 7, 2023
    risk 0.65cvss 9.8epss 0.20

    Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.

  • CVE-2023-25690CriMar 7, 2023
    risk 0.70cvss 9.8epss 0.85

    Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some…

  • CVE-2023-24781CriMar 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\MemberLevel.php.

  • CVE-2022-3760CriMar 7, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mia Technology Mia-Med. This issue affects Mia-Med: before 1.0.0.58.

  • CVE-2022-45141CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.00

    Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable Samba Active Directory DCs will issue rc4-hmac encrypted tickets despite the target server supporting…

  • CVE-2023-26949CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin1/config/update of onekeyadmin v1.3.9 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2023-24736CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.02

    PMB v7.4.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /sauvegarde/restaure_act.php.

  • CVE-2023-24734CriMar 6, 2023
    risk 0.65cvss 9.8epss 0.21

    An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbitrary code via a crafted image file.

  • CVE-2021-36394CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.07

    In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

  • CVE-2021-36393CriMar 6, 2023
    risk 0.68cvss 9.8epss 0.52

    In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.

  • CVE-2021-36392CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    In Moodle, an SQL injection risk was identified in the library fetching a user's enrolled courses.

  • CVE-2023-24776CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php.

  • CVE-2023-0979CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData MedDataPACS allows SQL Injection. This issue affects MedDataPACS : before 2023-03-03.

  • CVE-2022-4328CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.04

    The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server

  • CVE-2023-0839CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Protection for Outbound Error Messages and Alert Signals vulnerability in ProMIS Process Co. InSCADA allows Account Footprinting. This issue affects inSCADA: before 20230115-1.

  • CVE-2023-22344CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Use of hard-coded credentials vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to obtain the password of the debug tool and execute it. As a result of exploiting this vulnerability with CVE-2023-22335 and…

  • CVE-2023-22336CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a specially crafted file to an arbitrary directory. As a result of exploiting this vulnerability with CVE-2023-22335 and…

  • CVE-2023-26481CriMar 4, 2023
    risk 0.59cvss 9.1epss 0.00

    authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow link that is created by an admin (or sent via email by an admin) can be used to set the password for any arbitrary user. This attack is only possible if a recovery flow exists,…

  • CVE-2023-27290CriMar 3, 2023
    risk 0.63cvss 9.1epss 0.09

    Docker based datastores for IBM Instana (IBM Observability with Instana 239-0 through 239-2, 241-0 through 241-2, and 243-0) do not currently require authentication. Due to this, an attacker within the network could access the datastores with read/write access. IBM X-Force ID: …

  • CVE-2023-26779CriMar 3, 2023
    risk 0.64cvss 9.8epss 0.01

    CleverStupidDog yf-exam v 1.8.0 is vulnerable to Deserialization which can lead to remote code execution (RCE).

  • CVE-2023-27574CriMar 3, 2023
    risk 0.00cvss 9.8epss 0.00

    ShadowsocksX-NG 1.10.0 signs with com.apple.security.get-task-allow entitlements because of CODE_SIGNING_INJECT_BASE_ENTITLEMENTS.

  • CVE-2022-46973CriMar 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Report v0.9.8.6 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability.

  • CVE-2023-24643CriMar 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateBlankTxtview.php.

  • CVE-2023-24642CriMar 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateTxtview.php.

  • CVE-2023-24641CriMar 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateview.php.

  • CVE-2023-20079CriMar 3, 2023
    risk 0.65cvss 9.8epss 0.10

    Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details…

  • CVE-2023-20078CriMar 3, 2023
    risk 0.65cvss 9.8epss 0.10

    Multiple vulnerabilities in the web-based management interface of certain Cisco IP Phones could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details…

  • CVE-2022-45553CriMar 3, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary commands via serial connection to the UART port.

  • CVE-2022-45551CriMar 3, 2023
    risk 0.66cvss 9.8epss 0.24

    An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint.

  • CVE-2022-46501CriMar 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Accruent LLC Maintenance Connection 2021 (all) & 2022.2 was discovered to contain a SQL injection vulnerability via the E-Mail to Work Order function.

  • CVE-2023-26475CriMar 2, 2023
    risk 0.62cvss 9.9epss 0.64

    XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by annotating the document. This has been…

  • CVE-2023-26474CriMar 2, 2023
    risk 0.64cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execute a text area property. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. There are no known workarounds.

  • CVE-2023-26472CriMar 2, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with the right of IconThemeSheet author by creating an icon theme with certain content. This can be done by creating a new page or even through the user profile for…

  • CVE-2023-26471CriMar 2, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in restricted mode (anything dangerous is disabled), but the async macro does not take into account the restricted mode. This means…

  • CVE-2023-26055CriMar 2, 2023
    risk 0.64cvss 9.9epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-milestone-1, any user can edit their own profile and inject code, which is going to be executed with programming right. The same vulnerability can also be exploited in…

  • CVE-2023-26477CriMar 2, 2023
    risk 0.64cvss 10.0epss 0.75

    XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the `newThemeName` request parameter (URL parameter), in combination with additional…

  • CVE-2023-26780CriMar 2, 2023
    risk 0.64cvss 9.8epss 0.01

    CleverStupidDog yf-exam v 1.8.0 is vulnerable to SQL Injection.

  • CVE-2021-3854CriMar 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Useroam Hotspot allows SQL Injection. This issue affects Useroam Hotspot: before 5.1.0.15.

  • CVE-2023-1097CriMar 1, 2023
    risk 0.61cvss 9.3epss 0.01

    Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP GET command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods have been tested and validated…

  • CVE-2023-23315CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method `stripejsValidationModuleFrontController::initContent()` has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a…

  • CVE-2023-1114CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization vulnerability in Eskom e-Belediye allows Information Elicitation. This issue affects e-Belediye: from 1.0.0.95 before 1.0.0.100.

  • CVE-2023-1064CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighbridge Automation Software allows SQL Injection. This issue affects Weighbridge Automation Software: before 1.1.