VYPR

CVEs

38,103 total · page 405 of 763

  • CVE-2022-36231CriFeb 23, 2023
    risk 0.57cvss 9.8epss 0.03

    pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.

  • CVE-2023-26326CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.04

    The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects…

  • CVE-2023-23914CriFeb 23, 2023
    risk 0.59cvss 9.1epss 0.01

    A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP…

  • CVE-2023-24104CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Ubiquiti Networks UniFi Dream Machine Pro v7.2.95 allows attackers to bypass domain restrictions via crafted packets.

  • CVE-2022-2504CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SDD Computer Software SDD-Baro allows SQL Injection. This issue affects SDD-Baro: before 2.8.432.

  • CVE-2023-0939CriFeb 23, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NTN Information Technologies Online Services Software allows SQL Injection. This issue affects Online Services Software: before 1.17.

  • CVE-2022-48149CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Online Student Admission System in PHP Free Source Code 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

  • CVE-2022-45599CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gain escalated privileges only when specific conditions regarding a given accounts hashed password.

  • CVE-2022-39983CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attackers to execute arbitrary code.

  • CVE-2023-24114CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.

  • CVE-2023-0104CriFeb 22, 2023
    risk 0.62cvss 9.3epss 0.22

    The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file. This may allow an attacker to gain control of the user’s computer or gain access to sensitive data.  

  • CVE-2023-24093CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    An access control issue in H3C A210-G A210-GV100R005 allows attackers to authenticate without a password.

  • CVE-2023-25813CriFeb 22, 2023
    risk 0.58cvss 10.0epss 0.01

    Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Parameters which are passed through replacements are not properly escaped which can lead to arbitrary SQL injection depending on the specific queries in use. The…

  • CVE-2022-41217CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage.

  • CVE-2023-24108CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    MvcTools 6d48cd6830fc1df1d8c9d61caa1805fd6a1b7737 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.

  • CVE-2023-24107CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.

  • CVE-2023-0947CriFeb 22, 2023
    risk 0.00cvss 9.8epss 0.04

    Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.

  • CVE-2023-24080CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.01

    A lack of rate limiting on the password reset endpoint of Chamberlain myQ v5.222.0.32277 (on iOS) allows attackers to compromise user accounts via a bruteforce attack.

  • CVE-2023-25157CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.85

    GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (WFS) and Web Map Service…

  • CVE-2023-24320CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.01

    An access control issue in Axcora POS #0~gitf77ec09 allows unauthenticated attackers to execute arbitrary commands via unspecified vectors.

  • CVE-2023-25158CriFeb 21, 2023
    risk 0.57cvss 9.8epss 0.01

    GeoTools is an open source Java library that provides tools for geospatial data. GeoTools includes support for OGC Filter expression language parsing, encoding and execution against a range of datastore. SQL Injection Vulnerabilities have been found when executing OGC Filters…

  • CVE-2022-46637CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.02

    Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services.

  • CVE-2023-22920CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.01

    A security misconfiguration vulnerability exists in the Zyxel LTE3316-M604 firmware version V2.00(ABMP.6)C0 due to a factory default misconfiguration intended for testing purposes. A remote attacker could leverage this vulnerability to access an affected device using Telnet.

  • CVE-2023-24184CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability.

  • CVE-2022-45677CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection Vulnerability in tanujpatra228 Tution Management System (TMS) via the email parameter to processes/student_login.process.php.

  • CVE-2022-45564CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in znfit Home improvement ERP management system V50_20220207,v42 allows attackers to execute arbitrary sql commands via the userCode parameter to the wechat applet.

  • CVE-2023-0232CriFeb 21, 2023
    risk 0.64cvss 9.8epss 0.03

    The ShopLentor WordPress plugin before 2.5.4 unserializes user input from cookies in order to track viewed products and user data, which could lead to PHP Object Injection.

  • CVE-2023-23453CriFeb 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication for Critical Function in SICK FX0-GENT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.

  • CVE-2023-23452CriFeb 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication for Critical Function in SICK FX0-GPNT v3 Firmware Version V3.04 and V3.05 allows an unprivileged remote attacker to achieve arbitrary remote code execution via maliciously crafted RK512 commands to the listener on TCP port 9000.

  • CVE-2022-48337CriFeb 20, 2023
    risk 0.64cvss 9.8epss 0.02

    GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may use the "etags -u *" command…

  • CVE-2022-46836CriFeb 20, 2023
    risk 0.59cvss 9.1epss 0.01

    PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP code which will be executed upon request of the vulnerable component.

  • CVE-2023-25805CriFeb 20, 2023
    risk 0.57cvss 9.8epss 0.02

    versionn, software for changing version information across multiple files, has a command injection vulnerability in all versions prior to version 1.1.0. This issue is patched in version 1.1.0.

  • CVE-2023-25613CriFeb 20, 2023
    risk 0.64cvss 9.8epss 0.01

    An LDAP Injection vulnerability exists in the LdapIdentityBackend of Apache Kerby before 2.0.3. 

  • CVE-2023-26093CriFeb 20, 2023
    risk 0.00cvss 9.8epss 0.01

    Liima before 1.17.28 allows Hibernate query language (HQL) injection, related to colToSort in the deployment filter.

  • CVE-2023-26092CriFeb 20, 2023
    risk 0.00cvss 9.8epss 0.01

    Liima before 1.17.28 allows server-side template injection.

  • CVE-2022-48329CriFeb 20, 2023
    risk 0.64cvss 9.8epss 0.01

    MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.

  • CVE-2022-48328CriFeb 20, 2023
    risk 0.64cvss 9.8epss 0.01

    app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.

  • CVE-2023-23064CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control.

  • CVE-2022-40021CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vulnerability.

  • CVE-2023-23279CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php.

  • CVE-2021-35261CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint.

  • CVE-2021-34182CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions.

  • CVE-2021-33949CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function.

  • CVE-2021-33948CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter.

  • CVE-2021-33391CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.

  • CVE-2021-33226CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.02

    Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file. NOTE: this is disputed by third parties because an attacker cannot influence the eval input

  • CVE-2021-32163CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization.

  • CVE-2022-47986CriKEVFeb 17, 2023
    risk 0.93cvss 9.8epss 1.00

    IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary…

  • CVE-2020-29168CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint.

  • CVE-2022-40032CriFeb 17, 2023
    risk 0.68cvss 9.8epss 0.21

    SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information.