VYPR

CVEs

38,103 total · page 406 of 763

  • CVE-2022-40347CriFeb 17, 2023
    risk 0.67cvss 9.8epss 0.05

    SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information.

  • CVE-2023-24221CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMapper.xml.

  • CVE-2023-24220CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMapper.xml.

  • CVE-2023-24219CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml.

  • CVE-2021-43529CriFeb 16, 2023
    risk 0.64cvss 9.8epss 0.00

    Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. Thunderbird versions 91.3.0 and later will not call the vulnerable code when processing S/MIME messages that contain certificates with…

  • CVE-2022-39952CriFeb 16, 2023
    risk 0.75cvss 9.8epss 1.00

    A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or…

  • CVE-2022-38375CriFeb 16, 2023
    risk 0.59cvss 9.1epss 0.01

    An improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.

  • CVE-2021-42761CriFeb 16, 2023
    risk 0.59cvss 9.0epss 0.01

    A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 through 6.0.7, 5.9.0 through 5.9.1 may allow a remote, unauthenticated attacker to…

  • CVE-2021-42756CriFeb 16, 2023
    risk 0.66cvss 9.8epss 0.35

    Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbitrary code…

  • CVE-2023-23947CriFeb 16, 2023
    risk 0.52cvss 9.1epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All Argo CD versions starting with 2.3.0-rc1 and prior to 2.3.17, 2.4.23 2.5.11, and 2.6.2 are vulnerable to an improper authorization bug which allows users who have the ability to update at least one…

  • CVE-2023-24238CriFeb 16, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRules.

  • CVE-2023-24236CriFeb 16, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDhcpRules.

  • CVE-2023-22579CriFeb 16, 2023
    risk 0.57cvss 9.9epss 0.01

    Due to improper parameter filtering in the sequalize js library, can a attacker peform injection.

  • CVE-2023-22578CriFeb 16, 2023
    risk 0.58cvss 10.0epss 0.01

    Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.

  • CVE-2022-3843CriFeb 16, 2023
    risk 0.59cvss 9.1epss 0.01

    In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters.

  • CVE-2022-43969CriFeb 16, 2023
    risk 0.59cvss 9.1epss 0.01

    Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.

  • CVE-2021-33925CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in nitinparashar30 cms-corephp through commit bdabe52ef282846823bda102728a35506d0ec8f9 (May 19, 2021) allows unauthenticated attackers to gain escilated privledges via a crafted login.

  • CVE-2021-33304CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pico_fragments_reassemble, allows attackers to execute arbitrary code.

  • CVE-2020-21120CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in file home\controls\cart.class.php in UQCMS 2.1.3, allows attackers execute arbitrary commands via the cookie_cart parameter to /index.php/cart/num.

  • CVE-2020-21119CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Kliqqi-CMS 2.0.2 in admin/admin_update_module_widgets.php in recordIDValue parameter, allows attackers to gain escalated privileges and execute arbitrary code.

  • CVE-2020-19825CriFeb 15, 2023
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.

  • CVE-2023-22855CriFeb 15, 2023
    risk 0.68cvss 9.8epss 0.15

    Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path is handed to a path-concatenation method (Path.Combine from .NET) without proper sanitisation. This yields the possibility of…

  • CVE-2023-23465CriFeb 15, 2023
    risk 0.59cvss 9.1epss 0.00

    Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint.

  • CVE-2023-23462CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Libpeconv – integer overflow, before commit 75b1565 (30/11/2022).

  • CVE-2023-23461CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Libpeconv – access violation, before commit b076013 (30/11/2022).

  • CVE-2023-23460CriFeb 15, 2023
    risk 0.59cvss 9.1epss 0.01

    Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass.

  • CVE-2023-23459CriFeb 15, 2023
    risk 0.59cvss 9.1epss 0.01

    Priority Windows may allow Command Execution via SQL Injection using an unspecified method.

  • CVE-2023-22807CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker could control and tamper with the PLC by sending the packets to the PLC over its XGT protocol.

  • CVE-2023-22804CriFeb 15, 2023
    risk 0.59cvss 9.1epss 0.01

    LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This could allow an attacker to create and use an account with elevated privileges and take control of the device.

  • CVE-2023-0102CriFeb 15, 2023
    risk 0.59cvss 9.1epss 0.01

    LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication for its deletion command. This could allow an attacker to delete arbitrary files.

  • CVE-2022-46892CriFeb 15, 2023
    risk 0.64cvss 9.8epss 0.01

    In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.

  • CVE-2023-25765CriFeb 15, 2023
    risk 0.57cvss 9.9epss 0.01

    In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the…

  • CVE-2023-21803CriFeb 14, 2023
    risk 0.64cvss 9.8epss 0.02

    Windows iSCSI Discovery Service Remote Code Execution Vulnerability

  • CVE-2023-21716CriFeb 14, 2023
    risk 0.70cvss 9.8epss 0.85

    Microsoft Word Remote Code Execution Vulnerability

  • CVE-2023-21692CriFeb 14, 2023
    risk 0.65cvss 9.8epss 0.21

    Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

  • CVE-2023-21690CriFeb 14, 2023
    risk 0.66cvss 9.8epss 0.28

    Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

  • CVE-2023-21689CriFeb 14, 2023
    risk 0.66cvss 9.8epss 0.27

    Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

  • CVE-2023-25725CriFeb 14, 2023
    risk 0.60cvss 9.1epss 0.05

    HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers…

  • CVE-2023-24161CriFeb 14, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.

  • CVE-2023-24160CriFeb 14, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.

  • CVE-2023-24159CriFeb 14, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in the setPasswordCfg function.

  • CVE-2023-24482CriFeb 14, 2023
    risk 0.65cvss 10.0epss 0.01

    A vulnerability has been identified in COMOS V10.2 (All versions), COMOS V10.3.3.1 (All versions < V10.3.3.1.45), COMOS V10.3.3.2 (All versions < V10.3.3.2.33), COMOS V10.3.3.3 (All versions < V10.3.3.3.9), COMOS V10.3.3.4 (All versions < V10.3.3.4.6), COMOS V10.4.0.0 (All…

  • CVE-2022-47034CriFeb 13, 2023
    risk 0.00cvss 9.8epss 0.01

    A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication.

  • CVE-2023-24646CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2023-24084CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    ChiKoi v1.0 was discovered to contain a SQL injection vulnerability via the load_file function.

  • CVE-2023-25718CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added without invalidating the signature, such as instructions that result in offering the end user a (different) attacker-controlled…

  • CVE-2023-25717CriKEVFeb 13, 2023
    risk 0.83cvss 9.8epss 0.98

    Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.

  • CVE-2023-24188CriFeb 13, 2023
    risk 0.59cvss 9.1epss 0.01

    ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.

  • CVE-2023-23551CriFeb 13, 2023
    risk 0.59cvss 9.1epss 0.01

    Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to remotely execute arbitrary code.

  • CVE-2022-4445CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.