VYPR

CVEs

38,103 total · page 404 of 763

  • CVE-2023-22752CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-22751CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-22750CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.02

    There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-22749CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.02

    There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-22748CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.02

    There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-22747CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.02

    There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2023-20032CriMar 1, 2023
    risk 0.66cvss 9.8epss 0.29

    On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to…

  • CVE-2022-37938CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated server side request forgery in HPE Serviceguard Manager

  • CVE-2022-37937CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Pre-auth memory corruption in HPE Serviceguard

  • CVE-2022-37936CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Java deserialization vulnerability in Serviceguard Manager

  • CVE-2023-27372CriFeb 28, 2023
    risk 0.75cvss 9.8epss 1.00

    SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.

  • CVE-2023-20946CriFeb 28, 2023
    risk 0.64cvss 9.8epss 0.00

    In onStart of BluetoothSwitchPreferenceController.java, there is a possible permission bypass due to a confused deputy. This could lead to remote escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-0511CriFeb 28, 2023
    risk 0.59cvss 9.1epss 0.01

    Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all versions up to 5.10.1

  • CVE-2023-0339CriFeb 28, 2023
    risk 0.59cvss 9.1epss 0.01

    Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Policy Agent: all versions up to 5.10.1

  • CVE-2023-24258CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.02

    SPIP v4.1.5 and earlier was discovered to contain a SQL injection vulnerability via the _oups parameter. This vulnerability allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2023-23513CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.02

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.7.3, macOS Ventura 13.2, macOS Monterey 12.6.3. Mounting a maliciously crafted Samba network share may lead to arbitrary code execution.

  • CVE-2022-46723CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.1, macOS Big Sur 11.7.1. A remote user may be able to write arbitrary files.

  • CVE-2022-26760CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 15.5 and iPadOS 15.5. A malicious application may be able to elevate privileges.

  • CVE-2023-24253CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Domotica Labs srl Ikon Server before v2.8.6 was discovered to contain a SQL injection vulnerability.

  • CVE-2022-48284CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.00

    A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.

  • CVE-2022-48283CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.00

    A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions.

  • CVE-2022-48259CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could allow attackers to gain higher privileges.

  • CVE-2022-48255CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    There is a system command injection vulnerability in BiSheng-WNM FW 3.0.0.325. A Huawei printer has a system command injection vulnerability. Successful exploitation could lead to remote code execution.

  • CVE-2023-25234CriFeb 27, 2023
    risk 0.65cvss 9.8epss 0.17

    Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromAddressNat via parameters entrys and mitInterface.

  • CVE-2023-25233CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AC500 V2.0.1.9(1307) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.

  • CVE-2023-25231CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda Router W30E V1.0.1.25(633) is vulnerable to Buffer Overflow in function fromRouteStatic via parameters entrys and mitInterface.

  • CVE-2023-23156CriFeb 27, 2023
    risk 0.67cvss 9.8epss 0.04

    Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.

  • CVE-2023-23155CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the username parameter in the Admin Login.

  • CVE-2022-45140CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    The configuration backend allows an unauthenticated user to write arbitrary data with root privileges to the storage, which could lead to unauthenticated remote code execution and full system compromise.

  • CVE-2022-45138CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    The configuration backend of the web-based management can be used by unauthenticated users, although only authenticated users should be able to use the API. The vulnerability allows an unauthenticated attacker to read and set several device parameters that can lead to full…

  • CVE-2023-23080CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.02

    Certain Tenda products are vulnerable to command injection. This affects Tenda CP7 Tenda CP7<=V11.10.00.2211041403 and Tenda CP3 v.10 Tenda CP3 v.10<=V20220906024_2025 and Tenda IT7-PCS Tenda IT7-PCS<=V2209020914 and Tenda IT7-LCS Tenda IT7-LCS<=V2209020914 and Tenda IT7-PRS…

  • CVE-2023-24206CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.01

    Davinci v0.3.0-rc was discovered to contain a SQL injection vulnerability via the copyDisplay function.

  • CVE-2023-26602CriFeb 26, 2023
    risk 0.68cvss 9.8epss 0.17

    ASUS ASMB8 iKVM firmware through 1.14.51 allows remote attackers to execute arbitrary code by using SNMP to create extensions, as demonstrated by snmpset for NET-SNMP-EXTEND-MIB with /bin/sh for command execution.

  • CVE-2021-3329CriFeb 26, 2023
    risk 0.62cvss 9.6epss 0.01

    Lack of proper validation in HCI Host stack initialization can cause a crash of the bluetooth stack

  • CVE-2023-26550CriFeb 25, 2023
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in BMC Control-M before 9.0.20.214 allows attackers to execute arbitrary SQL commands via the memname JSON field.

  • CVE-2022-2024CriFeb 25, 2023
    risk 0.65cvss 9.8epss 0.98

    OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.

  • CVE-2023-26034CriFeb 25, 2023
    risk 0.63cvss 9.6epss 0.02

    ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are affected by a SQL Injection vulnerability. The (blind) SQL Injection vulnerability is present within…

  • CVE-2023-24189CriFeb 24, 2023
    risk 0.64cvss 9.8epss 0.01

    An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile.

  • CVE-2021-35370CriFeb 24, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.

  • CVE-2021-33387CriFeb 24, 2023
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.

  • CVE-2021-33224CriFeb 24, 2023
    risk 0.64cvss 9.8epss 0.01

    File upload vulnerability in Umbraco Forms v.8.7.0 allows unauthenticated attackers to execute arbitrary code via a crafted web.config and asp file.

  • CVE-2023-25696CriFeb 24, 2023
    risk 0.57cvss 9.8epss 0.02

    Improper Input Validation vulnerability in the Apache Airflow Hive Provider. This issue affects Apache Airflow Hive Provider versions before 5.1.3.

  • CVE-2023-25693CriFeb 24, 2023
    risk 0.57cvss 9.8epss 0.02

    Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider. This issue affects Apache Airflow Sqoop Provider versions before 3.1.1.

  • CVE-2023-25691CriFeb 24, 2023
    risk 0.57cvss 9.8epss 0.02

    Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0.

  • CVE-2021-4105CriFeb 24, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Handling of Parameters vulnerability in BG-TEK COSLAT Firewall allows Remote Code Inclusion. This issue affects COSLAT Firewall: from 5.24.0.R.20180630 before 5.24.0.R.20210727.

  • CVE-2023-26468CriFeb 24, 2023
    risk 0.00cvss 9.1epss 0.01

    Cerebrate 1.12 does not properly consider organisation_id during creation of API keys.

  • CVE-2023-24212CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda AX3 V16.03.12.11 was discovered to contain a stack overflow via the timeType function at /goform/SetSysTimeCfg.

  • CVE-2023-24205CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Clash for Windows v0.20.12 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via overwriting the configuration file (cfw-setting.yaml).

  • CVE-2023-0755CriFeb 23, 2023
    risk 0.65cvss 9.8epss 0.12

    The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.

  • CVE-2023-0754CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.03

    The affected products are vulnerable to an integer overflow or wraparound, which could  allow an attacker to crash the server and remotely execute arbitrary code.