VYPR

CVEs

115,481 total · page 827 of 2,310

  • CVE-2024-54237HigDec 13, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni CRM Lead ni-crm-lead allows Reflected XSS.This issue affects Ni CRM Lead: from n/a through <= 1.3.0.

  • CVE-2024-54236HigDec 13, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni WooCommerce Bulk Product Editor ni-woocommerce-product-editor allows Reflected XSS.This issue affects Ni WooCommerce Bulk Product Editor: from n/a through <=…

  • CVE-2024-54235HigDec 13, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shiptimize Shiptimize for WooCommerce shiptimize-for-woocommerce allows Reflected XSS.This issue affects Shiptimize for WooCommerce: from n/a through <= 3.1.86.

  • CVE-2024-54233HigDec 13, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in overclokk Advanced Control Manager for WordPress by ItalyStrap advanced-control-manager allows Reflected XSS.This issue affects Advanced Control Manager for WordPress by…

  • CVE-2024-54231HigDec 13, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Anzar Ahmed Ni WooCommerce Order Export ni-woocommerce-order-export allows Reflected XSS.This issue affects Ni WooCommerce Order Export: from n/a through <= 3.1.6.

  • CVE-2023-41130HigDec 13, 2024
    risk 0.53cvss 8.1epss 0.00

    Missing Authorization vulnerability in Premmerce Premmerce User Roles premmerce-user-roles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Premmerce User Roles: from n/a through <= 1.0.12.

  • CVE-2023-39920HigDec 13, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in Themeisle Redirection for Contact Form 7 wpcf7-redirect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Redirection for Contact Form 7: from n/a through <= 2.9.2.

  • CVE-2023-38385HigDec 13, 2024
    risk 0.54cvss 8.3epss 0.01

    Missing Authorization vulnerability in Artbees JupiterX Core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JupiterX Core: from 3.0.0 through 3.3.0.

  • CVE-2023-36510HigDec 13, 2024
    risk 0.47cvss 7.3epss 0.01

    Missing Authorization vulnerability in Reservation Diary ReDi Restaurant Reservation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReDi Restaurant Reservation: from n/a through 23.0211.

  • CVE-2023-35037HigDec 13, 2024
    risk 0.49cvss 7.6epss 0.00

    Missing Authorization vulnerability in Surfer Surfer surferseo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Surfer: from n/a through <= 1.3.2.357.

  • CVE-2023-33996HigDec 13, 2024
    risk 0.57cvss 8.8epss 0.01

    Missing Authorization vulnerability in СleanTalk - Anti-Spam Protection Spam protection, AntiSpam, FireWall by CleanTalk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spam protection, AntiSpam, FireWall by CleanTalk: from n/a through…

  • CVE-2023-32585HigDec 13, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in Total-Soft Portfolio Gallery – Responsive Image Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Portfolio Gallery – Responsive Image Gallery: from n/a through 1.4.6.

  • CVE-2023-32520HigDec 13, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in Webcodin WCP Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WCP Contact Form: from n/a through 3.1.0.

  • CVE-2023-32507HigDec 13, 2024
    risk 0.47cvss 7.3epss 0.01

    Missing Authorization vulnerability in wp3sixty Woo Custom Emails allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Woo Custom Emails: from n/a through 2.2.

  • CVE-2023-30490HigDec 13, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in Matthew Ruddy Easing Slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easing Slider : from n/a through 3.0.8.

  • CVE-2023-25988HigDec 13, 2024
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization vulnerability in Video Gallery by Total-Soft Video Gallery – YouTube Gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Video Gallery – YouTube Gallery: from n/a through 1.7.6.

  • CVE-2024-22461HigDec 13, 2024
    risk 0.57cvss 8.8epss 0.01

    Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially exploit this vulnerability by running any command as root, leading to gaining of root-level access and compromise of complete system.

  • CVE-2024-52066HigDec 13, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Routing Service) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.5, from 6.1.0 before…

  • CVE-2024-52065HigDec 13, 2024
    risk 0.46cvss 7.1epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional on non-Windows (Persistence Service) allows Buffer Overflow via Environment Variables.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.1.2…

  • CVE-2024-52064HigDec 13, 2024
    risk 0.46cvss 7.1epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.0 before 6.1.2.21, from 6.0.0 before…

  • CVE-2024-52063HigDec 13, 2024
    risk 0.56cvss 8.6epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries, Routing Service) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.0.0 before 7.3.0.5, from 6.1.0 before 6.1.2.21,…

  • CVE-2024-52062HigDec 13, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.0.0 before 7.3.0.5, from 6.1.0 before 6.1.2.21, from 6.0.0 before…

  • CVE-2024-52060HigDec 13, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Routing Service, Recording Service, Queuing Service, Observability Collector Service, Cloud Discovery Service) allows Buffer Overflow via Environment Variables.This…

  • CVE-2024-52059HigDec 13, 2024
    risk 0.51cvss 7.8epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Heap-based Buffer Overflow, Integer Overflow or Wraparound vulnerability in RTI Connext Professional (Security Plugins) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.0.0…

  • CVE-2024-52058HigDec 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in RTI Connext Professional (System Designer) allows OS Command Injection.This issue affects Connext Professional: from 7.0.0 before 7.3.0.2, from 6.1.0 before 6.1.2.19.

  • CVE-2024-10783HigDec 13, 2024
    risk 0.53cvss 8.1epss 0.02

    The MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites plugin for WordPress is vulnerable to privilege escalation due to a missing authorization checks on the register_site function in all versions up to, and including, 5.2 when a site is left in…

  • CVE-2024-11839HigDec 13, 2024
    risk 0.49cvss 7.5epss 0.00

    Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

  • CVE-2024-11836HigDec 13, 2024
    risk 0.49cvss 7.5epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in PlexTrac allowing requests to internal system resources.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

  • CVE-2024-11835HigDec 13, 2024
    risk 0.49cvss 7.5epss 0.00

    Uncontrolled Resource Consumption vulnerability in PlexTrac allows WebSocket DoS.This issue affects PlexTrac: from 1.61.3 before 2.8.1.

  • CVE-2024-21544HigDec 13, 2024
    risk 0.49cvss 8.6epss 0.01

    Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by using leading whitespace (%20) before the file:// protocol, resulting in Local…

  • CVE-2024-21543HigDec 13, 2024
    risk 0.39cvss 7.1epss 0.01

    Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to querying the database directly, granting access to users with valid credentials, and eventually bypassing custom…

  • CVE-2024-9508HigDec 13, 2024
    risk 0.51cvss 7.8epss 0.00

    Horner Automation Cscape contains a memory corruption vulnerability, which could allow an attacker to disclose information and execute arbitrary code.

  • CVE-2024-12212HigDec 13, 2024
    risk 0.51cvss 7.8epss 0.00

    The vulnerability occurs in the parsing of CSP files. The issues result from the lack of proper validation of user-supplied data, which could allow reading past the end of allocated data structures, resulting in execution of arbitrary code.

  • CVE-2024-55888HigDec 12, 2024
    risk 0.39cvss 7.1epss 0.00

    Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the productions server appeared to have been misconfigured and missed providing any content security policy or security headers. This could result in bypassing of…

  • CVE-2024-55885HigDec 12, 2024
    risk 0.42cvss 7.5epss 0.00

    beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a hashing algorithm. MD5 is no longer considered secure against well-funded opponents due to its vulnerability to collision attacks. Version 2.3.4 replaces MD5 with…

  • CVE-2024-47238HigDec 12, 2024
    risk 0.49cvss 7.5epss 0.00

    Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.

  • CVE-2024-21575HigDec 12, 2024
    risk 0.49cvss 8.6epss 0.01

    ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the extension to the server. This results in writing arbitrary files to the file system which…

  • CVE-2024-28146HigDec 12, 2024
    risk 0.55cvss 8.4epss 0.00

    The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some passwords allow a direct connection to the database server of the affected device.

  • CVE-2024-28143HigDec 12, 2024
    risk 0.55cvss 8.4epss 0.00

    The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this to forcefully set a new password within the -rsetpass+-aaction+- parameter for a user without knowing…

  • CVE-2024-8233HigDec 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could cause a denial of service with requests for diff files on a commit or merge request.

  • CVE-2024-54107HigDec 12, 2024
    risk 0.46cvss 7.1epss 0.00

    Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-54106HigDec 12, 2024
    risk 0.46cvss 7.1epss 0.00

    Null pointer dereference vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-54098HigDec 12, 2024
    risk 0.55cvss 8.5epss 0.00

    Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service integrity.

  • CVE-2024-54097HigDec 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability may affect feature implementation and integrity.

  • CVE-2024-11274HigDec 12, 2024
    risk 0.57cvss 8.7epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.

  • CVE-2024-12397HigDec 12, 2024
    risk 0.41cvss 7.4epss 0.01

    A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values,…

  • CVE-2024-12312HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    The Print Science Designer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.152 via deserialization of untrusted input through the 'designer-saved-projects' cookie. This makes it possible for unauthenticated attackers to inject…

  • CVE-2024-12172HigDec 12, 2024
    risk 0.49cvss 7.5epss 0.01

    The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpc_update_user_meta_option() function in all versions up to, and including,…

  • CVE-2024-12040HigDec 12, 2024
    risk 0.50cvss 8.8epss 0.01

    The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9.10 via the 'theme' attribute of the `wcpcsu` shortcode. This makes it possible for authenticated attackers, with…

  • CVE-2024-11052HigDec 12, 2024
    risk 0.47cvss 7.2epss 0.00

    The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter in all versions up to, and including, 3.8.19 due to insufficient input sanitization and output escaping. This makes…