VYPR

CVEs

115,482 total · page 823 of 2,310

  • CVE-2024-56174HigDec 18, 2024
    risk 0.53cvss 8.1epss 0.00

    In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection in search history.

  • CVE-2024-4464HigDec 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-3325 allows remote attackers to read specific files via unspecified vectors.

  • CVE-2024-21548HigDec 18, 2024
    risk 0.42cvss 7.5epss 0.01

    Versions of the package bun after 0.0.12 and before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun's APIs that accept objects. **Note:** This issue relates to the widely known and actively…

  • CVE-2024-21547HigDec 18, 2024
    risk 0.42cvss 7.5epss 0.01

    Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation in the browser where the file:// check can be bypassed with file:\\. An attacker could read any file on the server by exploiting the normalization of \ into /.

  • CVE-2024-12432HigDec 18, 2024
    risk 0.53cvss 8.1epss 0.01

    The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the 'generate_key' function not producing a sufficiently random value. This makes it possible…

  • CVE-2024-12259HigDec 18, 2024
    risk 0.57cvss 8.8epss 0.01

    The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.8120. This is due to the plugin not properly validating a user's identity prior to updating their email through the…

  • CVE-2024-12025HigDec 18, 2024
    risk 0.49cvss 7.5epss 0.03

    The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-json/collapsing-categories/v1/get REST API in all versions up to, and including, 3.0.8 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2024-47480HigDec 18, 2024
    risk 0.51cvss 7.8epss 0.00

    Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulnerability. A low-privilege attacker with local access may exploit this vulnerability, potentially resulting in Elevation of Privileges and unauthorized file…

  • CVE-2024-9779HigDec 17, 2024
    risk 0.42cvss 7.5epss 0.00

    A flaw was found in Open Cluster Management (OCM) when a user has access to the worker nodes which contain the cluster-manager or klusterlet deployments. The cluster-manager deployment uses a service account with the same name "cluster-manager" which is bound to a ClusterRole…

  • CVE-2024-51175HigDec 17, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1526.cfg component.

  • CVE-2024-49194HigDec 17, 2024
    risk 0.48cvss 7.3epss 0.01

    Databricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI injection via a JDBC URL parameter. The vulnerability is rooted in the improper handling of the krbJAASFile parameter. An attacker could potentially exploit this…

  • CVE-2024-51479HigDec 17, 2024
    risk 0.42cvss 7.5epss 0.04

    Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly under the application's root…

  • CVE-2024-53144HigDec 17, 2024
    risk 0.57cvss 8.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE This aligned BR/EDR JUST_WORKS method with LE which since 92516cd97fd4 ("Bluetooth: Always request for user confirmation for Just Works") always…

  • CVE-2024-12671HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

  • CVE-2024-12670HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current…

  • CVE-2024-12669HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current…

  • CVE-2024-12200HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

  • CVE-2024-12199HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

  • CVE-2024-12198HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

  • CVE-2024-12197HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

  • CVE-2024-12194HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2024-12193HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

  • CVE-2024-12192HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWF file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

  • CVE-2024-12191HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

  • CVE-2024-12179HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current…

  • CVE-2024-12178HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

  • CVE-2024-11422HigDec 17, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

  • CVE-2024-10476HigDec 17, 2024
    risk 0.52cvss 8.0epss 0.00

    Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modify or delete data, including sensitive information such as protected health information (PHI) and personally identifiable information (PII).…

  • CVE-2024-36832HigDec 17, 2024
    risk 0.49cvss 7.5epss 0.00

    A NULL pointer dereference in D-Link DAP-1513 REVA_FIRMWARE_1.01 allows attackers to cause a Denial of Service (DoS) via a crafted web request without authentication. The vulnerability occurs in the /bin/webs binary of the firmware. When /bin/webs receives a carefully…

  • CVE-2024-8326HigDec 17, 2024
    risk 0.50cvss 8.8epss 0.01

    The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 241114 via the 'sc_get_details' function. This makes it…

  • CVE-2024-12024HigDec 17, 2024
    risk 0.47cvss 7.2epss 0.00

    The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_data parameters in all versions up to, and including, 4.0.7.3 due to insufficient input…

  • CVE-2024-12293HigDec 17, 2024
    risk 0.50cvss 8.8epss 0.00

    The User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.64.3. This is due to missing or incorrect nonce validation on the update_roles() function. This makes it possible for unauthenticated attackers to add or…

  • CVE-2024-11999HigDec 17, 2024
    risk 0.57cvss 8.8epss 0.01

    CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticated user installs malicious code into HMI product.

  • CVE-2021-26280HigDec 17, 2024
    risk 0.51cvss 7.9epss 0.00

    Locally installed application can bypass the permission check and perform system operations that require permission.

  • CVE-2024-9624HigDec 17, 2024
    risk 0.49cvss 7.6epss 0.00

    The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.9.3 due to missing SSRF protection on the pmxi_curl_download function. This makes it possible for authenticated attackers, with Administrator-level…

  • CVE-2024-38499HigDec 17, 2024
    risk 0.57cvss 8.8epss 0.00

    CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a…

  • CVE-2020-12487HigDec 17, 2024
    risk 0.46cvss 7.0epss 0.00

    Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make the ABE service execute some commands with root privilege.

  • CVE-2024-56017HigDec 16, 2024
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects Stop Registration Spam: from n/a through 1.23.

  • CVE-2024-52949HigDec 16, 2024
    risk 0.49cvss 7.5epss 0.01

    iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control the size, and it is consequently possible to overflow memory on the stack.

  • CVE-2024-37775HigDec 16, 2024
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location which bypasses an RBAC check.

  • CVE-2024-37774HigDec 16, 2024
    risk 0.52cvss 8.0epss 0.00

    A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their privileges by forcing an Administrator user to perform sensitive requests in some admin screens.

  • CVE-2024-55104HigDec 16, 2024
    risk 0.47cvss 7.2epss 0.01

    Online Nurse Hiring System v1.0 was discovered to contain multiple SQL injection vulnerabilities in the component /admin/add-nurse.php via the gender and emailid parameters.

  • CVE-2024-55103HigDec 16, 2024
    risk 0.47cvss 7.2epss 0.01

    Online Nurse Hiring System v1.0 was discovered to contain a SQL injection vulnerability in the component /admin/profile.php via the fullname parameter.

  • CVE-2024-8058HigDec 16, 2024
    risk 0.49cvss 7.6epss 0.00

    An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ directory to read arbitrary files on the device due to URL preloading.

  • CVE-2024-6001HigDec 16, 2024
    risk 0.53cvss 8.1epss 0.00

    An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update request to a remote server and execute code with elevated privileges.

  • CVE-2024-4762HigDec 16, 2024
    risk 0.51cvss 7.8epss 0.00

    An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escalate privileges.

  • CVE-2024-11144HigDec 16, 2024
    risk 0.49cvss 7.5epss 0.00

    The server lacks thread safety and can be crashed by anomalous data sent by an anonymous user from a remote network. The crash causes the FTP service to become unavailable, affecting all users and processes that rely on it for file transfers. If the crash occurs during file…

  • CVE-2024-10095HigDec 16, 2024
    risk 0.55cvss 8.4epss 0.01

    In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability.

  • CVE-2024-54376HigDec 16, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Spider Themes EazyDocs eazydocs allows PHP Local File Inclusion.This issue affects EazyDocs: from n/a through <= 2.8.0.

  • CVE-2024-54284HigDec 16, 2024
    risk 0.49cvss 7.6epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SeedProd LLC SeedProd Pro allows SQL Injection.This issue affects SeedProd Pro: from n/a through 6.18.10.