VYPR

CVEs

115,481 total · page 828 of 2,310

  • CVE-2024-10499HigDec 12, 2024
    risk 0.47cvss 7.2epss 0.01

    The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint before using it in a SQL statement, allowing admins to perform SQL injection attacks

  • CVE-2024-10910HigDec 12, 2024
    risk 0.47cvss 7.3epss 0.01

    The The Grid Plus – Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid_plus_load_by_category AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not…

  • CVE-2024-10590HigDec 12, 2024
    risk 0.57cvss 8.8epss 0.01

    The Opt-In Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the admin_upload() function in all versions up to, and including, 4.07. This makes it possible for authenticated attackers, with Subscriber-level access and…

  • CVE-2024-11689HigDec 12, 2024
    risk 0.57cvss 8.8epss 0.00

    The HQ Rental Software plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.29. This is due to missing or incorrect nonce validation on the displaySettingsPage() function. This makes it possible for unauthenticated attackers…

  • CVE-2024-11443HigDec 12, 2024
    risk 0.57cvss 8.8epss 0.01

    The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the debranding_save() function in all versions up to, and including, 1.0.2. This makes it possible for authenticated…

  • CVE-2024-10111HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.26.3. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for…

  • CVE-2024-55658HigDec 12, 2024
    risk 0.42cvss 7.5epss 0.01

    SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary file read via path traversal. It is possible to manipulate the paths parameter to access and download arbitrary files from the host…

  • CVE-2024-55657HigDec 12, 2024
    risk 0.42cvss 7.5epss 0.01

    SiYuan is a personal knowledge management system. Prior to version 3.1.16, an arbitrary file read vulnerability exists in Siyuan's `/api/template/render` endpoint. The absence of proper validation on the path parameter allows attackers to access sensitive files on the host…

  • CVE-2024-54529HigDec 12, 2024
    risk 0.51cvss 7.8epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.

  • CVE-2024-54528HigDec 12, 2024
    risk 0.46cvss 7.1epss 0.00

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to overwrite arbitrary files.

  • CVE-2024-54515HigDec 12, 2024
    risk 0.51cvss 7.8epss 0.00

    A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2. A malicious app may be able to gain root privileges.

  • CVE-2024-54514HigDec 12, 2024
    risk 0.56cvss 8.6epss 0.00

    The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. An app may be able to break out of its sandbox.

  • CVE-2024-54508HigDec 12, 2024
    risk 0.49cvss 7.5epss 0.01

    The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2024-54505HigDec 12, 2024
    risk 0.57cvss 8.8epss 0.01

    A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to memory corruption.

  • CVE-2024-54498HigDec 12, 2024
    risk 0.57cvss 8.8epss 0.01

    A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to break out of its sandbox.

  • CVE-2024-54489HigDec 12, 2024
    risk 0.51cvss 7.8epss 0.00

    A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. Running a mount command may unexpectedly execute arbitrary code.

  • CVE-2024-54479HigDec 12, 2024
    risk 0.49cvss 7.5epss 0.02

    The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. Processing maliciously crafted web content may lead to an unexpected process crash.

  • CVE-2024-44291HigDec 12, 2024
    risk 0.51cvss 7.8epss 0.00

    A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A malicious app may be able to gain root privileges.

  • CVE-2024-44245HigDec 12, 2024
    risk 0.46cvss 7.1epss 0.00

    The issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, visionOS 2.2. An app may be able to cause unexpected system termination or corrupt kernel memory.

  • CVE-2024-44225HigDec 12, 2024
    risk 0.51cvss 7.8epss 0.00

    A logic issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2, tvOS 18.2, watchOS 11.2. An app may be able to gain elevated privileges.

  • CVE-2024-44224HigDec 12, 2024
    risk 0.51cvss 7.8epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A malicious app may be able to gain root privileges.

  • CVE-2024-42407HigDec 12, 2024
    risk 0.55cvss 8.5epss 0.00

    Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authenticated Operator to view some security sensitive information to which they have not been granted access. This issue affects: Command Centre…

  • CVE-2024-12497HigDec 12, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in 1000 Projects Attendance Tracking Management System 1.0. Affected is an unknown function of the file /admin/check_admin_login.php. The manipulation of the argument admin_user_name leads to sql injection. It is possible to…

  • CVE-2024-55587HigDec 12, 2024
    risk 0.50cvss 8.8epss 0.02

    python-libarchive through 4.2.1 allows directory traversal (to create files) in extract in zip.py for ZipFile.extractall and ZipFile.extract.

  • CVE-2024-49142HigDec 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Access Remote Code Execution Vulnerability

  • CVE-2024-49138HigKEVDec 12, 2024
    risk 0.68cvss 7.8epss 0.25

    Windows Common Log File System Driver Elevation of Privilege Vulnerability

  • CVE-2024-49132HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-49129HigDec 12, 2024
    risk 0.49cvss 7.5epss 0.01

    Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

  • CVE-2024-49128HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

  • CVE-2024-49127HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

  • CVE-2024-49126HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability

  • CVE-2024-49125HigDec 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2024-49124HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability

  • CVE-2024-49123HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-49122HigDec 12, 2024
    risk 0.54cvss 8.1epss 0.20

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2024-49121HigDec 12, 2024
    risk 0.49cvss 7.5epss 0.02

    Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

  • CVE-2024-49120HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-49119HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-49118HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2024-49117HigDec 12, 2024
    risk 0.57cvss 8.8epss 0.01

    Windows Hyper-V Remote Code Execution Vulnerability

  • CVE-2024-49116HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.10

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-49115HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-49114HigDec 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

  • CVE-2024-49113HigDec 12, 2024
    risk 0.55cvss 7.5epss 0.83

    Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

  • CVE-2024-49108HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-49107HigDec 12, 2024
    risk 0.48cvss 7.3epss 0.02

    WmsRepair Service Elevation of Privilege Vulnerability

  • CVE-2024-49106HigDec 12, 2024
    risk 0.53cvss 8.1epss 0.01

    Windows Remote Desktop Services Remote Code Execution Vulnerability

  • CVE-2024-49105HigDec 12, 2024
    risk 0.55cvss 8.4epss 0.02

    Remote Desktop Client Remote Code Execution Vulnerability

  • CVE-2024-49104HigDec 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

  • CVE-2024-49102HigDec 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability