VYPR

CVEs

115,482 total · page 821 of 2,310

  • CVE-2024-54663HigDec 19, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists in the /h/rest endpoint, allowing authenticated remote attackers to include and access sensitive files in the WebRoot…

  • CVE-2024-12700HigDec 19, 2024
    risk 0.57cvss 8.8epss 0.01

    There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to upload an jsp shell and execute code with the privileges of user running the web server.

  • CVE-2024-12729HigDec 19, 2024
    risk 0.57cvss 8.8epss 0.01

    A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).

  • CVE-2024-12672HigDec 19, 2024
    risk 0.47cvss 7.3epss 0.00

    A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this…

  • CVE-2024-12175HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this…

  • CVE-2024-11364HigDec 19, 2024
    risk 0.47cvss 7.3epss 0.00

    Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage…

  • CVE-2024-11157HigDec 19, 2024
    risk 0.47cvss 7.3epss 0.00

    A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this…

  • CVE-2024-53991HigDec 19, 2024
    risk 0.51cvss 7.5epss 0.27

    Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances configured to use `FileStore::LocalStore` which means uploads and backups are stored locally on disk. If an attacker knows the name of the Discourse backup file,…

  • CVE-2024-12111HigDec 19, 2024
    risk 0.52cvss 8.0epss 0.00

    In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5)

  • CVE-2024-56200HigDec 19, 2024
    risk 0.49cvss 8.6epss 0.01

    Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image proxy for compressing and resizing remote files could allow attacks that could affect availability, such as by abnormally increasing the CPU usage of the server…

  • CVE-2024-55196HigDec 19, 2024
    risk 0.49cvss 7.5epss 0.00

    Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.

  • CVE-2024-38819HigDec 19, 2024
    risk 0.46cvss 7.5epss 0.55

    Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the…

  • CVE-2024-12792HigDec 19, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in Codezips E-Commerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file newadmin.php. The manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit…

  • CVE-2024-12791HigDec 19, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Codezips E-Commerce Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file signin.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been…

  • CVE-2023-7005HigDec 19, 2024
    risk 0.49cvss 7.5epss 0.00

    A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication, and can be utilized to compromise the lock, such as through revealing the unlockKey field.

  • CVE-2024-12788HigDec 19, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Codezips Technical Discussion Forum 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file signinpost.php. The manipulation of the argument username leads to sql injection. The attack may be launched…

  • CVE-2024-9154HigDec 19, 2024
    risk 0.56cvss epss 0.01

    A code injection vulnerability in HMS Networks Ewon Flexy 205 allows executing commands on system level on the device. This issue affects Ewon Flexy 205: through 14.8s0 (#2633).

  • CVE-2024-55082HigDec 19, 2024
    risk 0.49cvss 7.5epss 0.00

    A Server-Side Request Forgery (SSRF) in the endpoint http://{your-server}/url-to-pdf of Stirling-PDF 0.35.1 allows attackers to access sensitive information via a crafted request.

  • CVE-2024-12787HigDec 19, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /student/check_student_login.php. The manipulation of the argument student_emailid leads…

  • CVE-2024-54790HigDec 19, 2024
    risk 0.49cvss 7.5epss 0.01

    A SQL Injection vulnerability was found in /index.php in PHPGurukul Pre-School Enrollment System v1.0, which allows remote attackers to execute arbitrary code via the visittime parameter.

  • CVE-2024-47093HigDec 19, 2024
    risk 0.00cvss 8.8epss 0.01

    Improper neutralization of input in Nagvis before version 1.9.42 which can lead to XSS

  • CVE-2024-25131HigDec 19, 2024
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-privileged user on the cluster can create a MustGather object with a specially crafted file and set the most privileged service account to run the job. This can…

  • CVE-2024-12786HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected is the function shouldAcceptNewConnection of the file com.x1a0he.macOS.Adobe-Downloader.helper of the component XPC Service. The manipulation leads to improper…

  • CVE-2024-12782HigDec 19, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 and classified as critical. This vulnerability affects unknown code of the file /home/index.html#hashHome of the component Web Interface. The manipulation leads…

  • CVE-2021-32589HigDec 19, 2024
    risk 0.53cvss 8.1epss 0.09

    A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.2.10 and below, version 5.0.12 and below and FortiAnalyzer version…

  • CVE-2021-26115HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.01

    An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate their privileges to root via executing a specially-crafted command.An OS command injection (CWE-78)…

  • CVE-2020-15934HigDec 19, 2024
    risk 0.57cvss 8.8epss 0.00

    An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to elevate their privileges to root by creating a malicious script or program on the target machine.

  • CVE-2024-12569HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allows an attacker to read camera credentials stored in the Recording Server under specific conditions.

  • CVE-2024-4230HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in…

  • CVE-2024-4229HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information…

  • CVE-2021-26093HigDec 19, 2024
    risk 0.47cvss 7.3epss 0.00

    An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker to crash the access point being managed by the controller by executing a crafted CLI command.

  • CVE-2024-11740HigDec 19, 2024
    risk 0.48cvss 7.3epss 0.02

    The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This…

  • CVE-2024-11984HigDec 19, 2024
    risk 0.57cvss 8.8epss 0.01

    A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows remote authenticated users to bypass file upload restrictions and perform arbitrary system commands with SYSTEM privilege via a…

  • CVE-2024-51532HigDec 19, 2024
    risk 0.46cvss 7.1epss 0.00

    Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.

  • CVE-2024-35141HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges.

  • CVE-2023-23354HigDec 19, 2024
    risk 0.47cvss 7.3epss 0.00

    A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security mechanisms or read application data. We have already fixed…

  • CVE-2022-27595HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user access to execute unauthorized code or commands. We have already fixed the vulnerability in the following…

  • CVE-2022-44520HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…

  • CVE-2022-44518HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…

  • CVE-2022-44514HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires…

  • CVE-2022-44513HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2022-44512HigDec 19, 2024
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue…

  • CVE-2024-56319HigDec 18, 2024
    risk 0.42cvss 7.5epss 0.01

    In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userlabel cluster can lead to a denial of service (resource exhaustion).

  • CVE-2024-56318HigDec 18, 2024
    risk 0.42cvss 7.5epss 0.01

    In raw\TCP.cpp in Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before 27ca6ec, there is a NULL pointer dereference in TCPBase::ProcessSingleMessage via TCP packets with zero messageSize, leading to denial of service.

  • CVE-2024-56317HigDec 18, 2024
    risk 0.42cvss 7.5epss 0.00

    In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes all existing ACL entries first, and then attempts to recreate them based on user input. If input validation fails during decoding, the process stops, and no entries are restored by…

  • CVE-2024-56116HigDec 18, 2024
    risk 0.57cvss 8.8epss 0.00

    A Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator account.

  • CVE-2024-55506HigDec 18, 2024
    risk 0.57cvss 8.8epss 0.01

    An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id parameter.

  • CVE-2024-53580HigDec 18, 2024
    risk 0.49cvss 7.5epss 0.01

    iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

  • CVE-2024-43106HigDec 18, 2024
    risk 0.46cvss 7.1epss 0.01

    A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and…

  • CVE-2024-42220HigDec 18, 2024
    risk 0.46cvss 7.1epss 0.01

    A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this…