VYPR

CVEs

38,103 total · page 408 of 763

  • CVE-2023-24200CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php.

  • CVE-2023-24199CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.

  • CVE-2023-24198CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters.

  • CVE-2021-36226CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.

  • CVE-2021-36224CriFeb 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Western Digital My Cloud devices before OS5 have a nobody account with a blank password.

  • CVE-2022-31733CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.00

    Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. If mTLS route integrity is enabled AND unproxied ports are…

  • CVE-2023-23088CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer OverFlow Vulnerability in Barenboim json-parser master and v1.1.0 fixed in v1.1.1 allows an attacker to execute arbitrary code via the json_value_parse function.

  • CVE-2023-23087CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was found in MojoJson v1.2.3 allows attackers to execute arbitary code via the destroy function.

  • CVE-2023-23086CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Buffer OverFlow Vulnerability in MojoJson v1.2.3 allows an attacker to execute arbitrary code via the SkipString function.

  • CVE-2021-37497CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.

  • CVE-2021-37317CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.02

    Directory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the target for COPY and MOVE operations.

  • CVE-2021-37315CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.01

    Incorrect Access Control issue discoverd in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers to write arbitrary files via improper sanitation on the source for COPY and MOVE operations.

  • CVE-2021-36503CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in native-php-cms 1.0 allows remote attackers to run arbitrary SQL commands via the cat parameter to /list.php file.

  • CVE-2021-36484CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page.

  • CVE-2021-36434CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.01

    SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check function in jocms/apps/mask/inc/getmask.php.

  • CVE-2021-36433CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.01

    SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_delete_mask function in jocms/apps/mask/mask.php.

  • CVE-2021-36431CriFeb 3, 2023
    risk 0.59cvss 9.1epss 0.01

    SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check() function in jocms/apps/mask/inc/mask.php.

  • CVE-2021-36424CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.

  • CVE-2023-24157CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the serverIp parameter in the function updateWifiInfo of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2023-24156CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the ip parameter in the function recvSlaveUpgstatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2023-24155CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK T8 V4.1.5cu was discovered to contain a hard code password for the telnet service which is stored in the component /web_cste/cgi-bin/product.ini.

  • CVE-2023-24154CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK T8 V4.1.5cu was discovered to contain a command injection vulnerability via the slaveIpList parameter in the function setUpgradeFW.

  • CVE-2023-24153CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the version parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2023-24152CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the serverIp parameter in the function meshSlaveUpdate of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2023-24151CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the ip parameter in the function recvSlaveCloudCheckStatus of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2023-24150CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the serverIp parameter in the function meshSlaveDlfw of TOTOLINK T8 V4.1.5cu allows attackers to execute arbitrary commands via a crafted MQTT packet.

  • CVE-2023-24149CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a hard code password for root which is stored in the component /etc/shadow.

  • CVE-2023-24148CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadUserData function.

  • CVE-2023-24146CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the minute parameter in the setRebootScheCfg function.

  • CVE-2023-24145CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the plugin_version parameter in the setUnloadUserData function.

  • CVE-2023-24144CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the hour parameter in the setRebootScheCfg function.

  • CVE-2023-24143CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagTracertHop parameter in the setNetworkDiag function.

  • CVE-2023-24142CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingSize parameter in the setNetworkDiag function.

  • CVE-2023-24141CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingTimeOut parameter in the setNetworkDiag function.

  • CVE-2023-24140CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagPingNum parameter in the setNetworkDiag function.

  • CVE-2023-24139CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the NetDiagHost parameter in the setNetworkDiag function.

  • CVE-2023-24138CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the host_time parameter in the NTPSyncWithHost function.

  • CVE-2023-25139CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    sprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct buffer size. This is unrelated to CWE-676. It may write beyond the bounds of the destination buffer when attempting to write a padded, thousands-separated…

  • CVE-2023-25135CriFeb 3, 2023
    risk 0.66cvss 9.8epss 0.24

    vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling unserialize and then checking for errors.…

  • CVE-2022-48021CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in Zammad v5.3.0 allows attackers to execute arbitrary code or escalate privileges via a crafted message sent to the server.

  • CVE-2022-22486CriFeb 3, 2023
    risk 0.65cvss 10.0epss 0.01

    IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226328.

  • CVE-2022-48114CriFeb 2, 2023
    risk 0.64cvss 9.8epss 0.01

    RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.

  • CVE-2022-48113CriFeb 2, 2023
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials.

  • CVE-2022-48130CriFeb 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Tenda W20E v15.11.0.6 was discovered to contain multiple stack overflows in the function formSetStaticRoute via the parameters staticRouteNet, staticRouteMask, staticRouteGateway, staticRouteWAN.

  • CVE-2022-48082CriFeb 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Easyone CRM v5.50.02 was discovered to contain a SQL Injection vulnerability via the text parameter at /Services/Misc.asmx/SearchTag.

  • CVE-2022-48079CriFeb 2, 2023
    risk 0.64cvss 9.8epss 0.01

    Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory of the system.

  • CVE-2023-23076CriFeb 1, 2023
    risk 0.70cvss 9.8epss 0.74

    OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.

  • CVE-2023-22501CriFeb 1, 2023
    risk 0.60cvss 9.1epss 0.16

    An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and…

  • CVE-2023-24997CriFeb 1, 2023
    risk 0.57cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.1.0 through 1.5.0. Users are advised to upgrade to Apache InLong's latest version or cherry-pick https://github.com/apache/inlong/pull/7223…

  • CVE-2022-47714CriFeb 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Last Yard 22.09.8-1 does not enforce HSTS headers