VYPR

CVEs

38,103 total · page 407 of 763

  • CVE-2022-40022CriFeb 13, 2023
    risk 0.74cvss 9.8epss 0.92

    Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.

  • CVE-2022-48323CriFeb 13, 2023
    risk 0.68cvss 9.8epss 0.57

    Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated attacker can execute arbitrary programs on the victim host by sending a crafted HTTP request, as demonstrated by /check?cmd=ping../…

  • CVE-2022-48322CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affects MR60 before 1.1.7.132, MS60 before 1.1.7.132, R6900P before 1.3.3.154, R7000P before 1.3.3.154, R7960P before 1.4.4.94, and R8000P before 1.4.4.94.

  • CVE-2022-4557CriFeb 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Group Arge Energy and Control Systems Smartpower Web allows SQL Injection. This issue affects Smartpower Web: before 23.01.01.

  • CVE-2022-45088CriFeb 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web allows PHP Local File Inclusion. This issue affects Smartpower Web: before 23.01.01.

  • CVE-2022-40514CriFeb 12, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption due to buffer copy without checking the size of input in WLAN Firmware while processing CCKM IE in reassoc response frame.

  • CVE-2022-33279CriFeb 12, 2023
    risk 0.64cvss 9.8epss 0.01

    Memory corruption due to stack based buffer overflow in WLAN having invalid WNM frame length.

  • CVE-2022-33232CriFeb 12, 2023
    risk 0.60cvss 9.3epss 0.00

    Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory.

  • CVE-2022-25729CriFeb 12, 2023
    risk 0.64cvss 9.8epss 0.00

    Memory corruption in modem due to improper length check while copying into memory

  • CVE-2023-23163CriFeb 10, 2023
    risk 0.67cvss 9.8epss 0.04

    Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.

  • CVE-2023-23162CriFeb 10, 2023
    risk 0.67cvss 9.8epss 0.04

    Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.

  • CVE-2023-0777CriFeb 10, 2023
    risk 0.61cvss 9.8epss 0.15

    Authentication Bypass by Primary Weakness in GitHub repository modoboa/modoboa prior to 2.0.4.

  • CVE-2022-45766CriFeb 10, 2023
    risk 0.59cvss 9.1epss 0.01

    Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Management permits remote attackers to impact availability, confidentiality, accessibility and dependability of electronic key boxes.

  • CVE-2023-24352CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the webpage parameter at /goform/formWPS.

  • CVE-2023-24351CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the FILECODE parameter at /goform/formLogin.

  • CVE-2023-24350CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the config.smtp_email_subject parameter at /goform/formSetEmail.

  • CVE-2023-24349CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetRoute.

  • CVE-2023-24348CriFeb 10, 2023
    risk 0.64cvss 9.8epss 0.01

    D-Link N300 WI-FI Router DIR-605L v2.13B01 was discovered to contain a stack overflow via the curTime parameter at /goform/formSetACLFilter.

  • CVE-2022-43501CriFeb 10, 2023
    risk 0.59cvss 9.1epss 0.01

    KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP connections from an insufficiently random source. An attacker may be able to determine the ISN of the current or future TCP connections and either hijack existing ones or spoof future…

  • CVE-2022-45699CriFeb 10, 2023
    risk 0.70cvss 9.8epss 0.77

    Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.

  • CVE-2022-43550CriFeb 9, 2023
    risk 0.00cvss 9.8epss 0.02

    A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which could allow an attacker to insert an arbitrary URL which opens up the opportunity to remote execution.

  • CVE-2022-48290CriFeb 9, 2023
    risk 0.59cvss 9.1epss 0.00

    The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality and integrity.

  • CVE-2023-25168CriFeb 9, 2023
    risk 0.55cvss 9.6epss 0.01

    Wings is Pterodactyl's server control plane. This vulnerability can be used to delete files and directories recursively on the host system. This vulnerability can be combined with `GHSA-p8r3-83r8-jwj5` to overwrite files on the host system. In order to use this exploit, an…

  • CVE-2022-45982CriFeb 8, 2023
    risk 0.64cvss 9.8epss 0.01

    thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

  • CVE-2022-45527CriFeb 8, 2023
    risk 0.64cvss 9.8epss 0.01

    File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory.

  • CVE-2022-45526CriFeb 8, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_transfer.php.

  • CVE-2022-43764CriFeb 8, 2023
    risk 0.64cvss 9.8epss 0.01

    Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code.

  • CVE-2022-43761CriFeb 8, 2023
    risk 0.61cvss 9.4epss 0.01

    Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration. 

  • CVE-2023-0744CriFeb 8, 2023
    risk 0.60cvss 9.8epss 0.06

    Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.

  • CVE-2023-0743CriFeb 8, 2023
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4.

  • CVE-2023-0742CriFeb 8, 2023
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

  • CVE-2023-0741CriFeb 8, 2023
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.

  • CVE-2023-0740CriFeb 8, 2023
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.

  • CVE-2021-36471CriFeb 7, 2023
    risk 0.64cvss 9.8epss 0.02

    Directory Traversal vulnerability in AdminLTE 3.1.0 allows remote attackers to gain escalated privilege and view sensitive information via /admin/index2.html, /admin/index3.html URIs. Note: AdminLTE developers dispute that this a weakness with AdminLTE and is instead a…

  • CVE-2023-24813CriFeb 7, 2023
    risk 0.58cvss 10.0epss 0.02

    Dompdf is an HTML to PDF converter written in php. Due to the difference in the attribute parser of Dompdf and php-svg-lib, an attacker can still call arbitrary URLs with arbitrary protocols. Dompdf parses the href attribute of `image` tags and respects `xlink:href` even if…

  • CVE-2022-43757CriFeb 7, 2023
    risk 0.57cvss 9.9epss 0.01

    A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials exposed This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to…

  • CVE-2022-3229CriFeb 6, 2023
    risk 0.08cvss 9.8epss 0.66

    Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated…

  • CVE-2023-23333CriFeb 6, 2023
    risk 0.75cvss 9.8epss 0.99

    There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.

  • CVE-2021-31578CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    In Boa, there is a possible escalation of privilege due to a stack buffer overflow. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210008;…

  • CVE-2021-31577CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    In Boa, there is a possible escalation of privilege due to a missing permission check. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A20210008;…

  • CVE-2021-31575CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.02

    In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2021-31574CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.02

    In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2021-31573CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.02

    In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2022-48311CriFeb 6, 2023
    risk 0.59cvss 9.0epss 0.01

    **UNSUPPORTED WHEN ASSIGNED** Cross Site Scripting (XSS) in HP Deskjet 2540 series printer Firmware Version CEP1FN1418BR and Product Model Number A9U23B allows authenticated attacker to inject their own script into the page via HTTP configuration page. NOTE: This vulnerability…

  • CVE-2022-4681CriFeb 6, 2023
    risk 0.67cvss 9.8epss 0.04

    The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

  • CVE-2022-47071CriFeb 6, 2023
    risk 0.66cvss 9.8epss 0.26

    In NVS365 V01, the background network test function can trigger command execution.

  • CVE-2022-48078CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    pycdc commit 44a730f3a889503014fec94ae6e62d8401cb75e5 was discovered to contain a stack overflow via the component ASTree.cpp:BuildFromCode.

  • CVE-2023-24276CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules.

  • CVE-2023-24202CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.

  • CVE-2023-24201CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php.