VYPR

CVEs

115,474 total · page 840 of 2,310

  • CVE-2024-54003HigNov 27, 2024
    risk 0.58cvss 8.0epss 0.80

    Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Create permission.

  • CVE-2024-31976HigNov 27, 2024
    risk 0.52cvss 8.0epss 0.01

    EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity parameter.

  • CVE-2024-53920HigNov 27, 2024
    risk 0.51cvss 7.8epss 0.01

    In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs…

  • CVE-2024-52951HigNov 27, 2024
    risk 0.52cvss 8.0epss 0.01

    Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History

  • CVE-2024-53603HigNov 27, 2024
    risk 0.48cvss 7.3epss 0.01

    A SQL Injection vulnerability was found in /covid-tms/password-recovery.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the contactno POST request parameter.

  • CVE-2024-52323HigNov 27, 2024
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the org-admin account.

  • CVE-2024-11667HigKEVNov 27, 2024
    risk 0.67cvss 7.5epss 0.03

    A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V5.38, and USG20(W)-VPN series…

  • CVE-2024-36467HigNov 27, 2024
    risk 0.49cvss 7.5epss 0.01

    An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having…

  • CVE-2024-52959HigNov 27, 2024
    risk 0.47cvss 7.2epss 0.01

    A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.

  • CVE-2024-52958HigNov 27, 2024
    risk 0.47cvss 7.2epss 0.00

    A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load a malicious DLL via upload plugin function.

  • CVE-2024-5921HigNov 27, 2024
    risk 0.57cvss 8.8epss 0.01

    An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable a local non-administrative operating system user or an attacker on the same subnet to install…

  • CVE-2024-11819HigNov 27, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in 1000 Projects Portfolio Management System MCA 1.0. This vulnerability affects unknown code of the file /forgot_password_process.php. The manipulation of the argument username leads to sql injection. The attack can be initiated…

  • CVE-2024-11818HigNov 27, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in PHPGurukul User Registration & Login and User Management System 1.0. This affects an unknown part of the file /signup.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the…

  • CVE-2024-11817HigNov 26, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in PHPGurukul User Registration & Login and User Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/index.php. The manipulation of the argument username leads to sql injection.…

  • CVE-2024-53675HigNov 26, 2024
    risk 0.54cvss 7.3epss 0.84

    An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

  • CVE-2024-53674HigNov 26, 2024
    risk 0.51cvss 7.3epss 0.47

    An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

  • CVE-2024-53673HigNov 26, 2024
    risk 0.53cvss 8.1epss 0.01

    A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.

  • CVE-2024-11622HigNov 26, 2024
    risk 0.48cvss 7.3epss 0.02

    An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

  • CVE-2024-11745HigNov 26, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical. Affected by this issue is the function route_static_check of the file /goform/SetStaticRouteCfg. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be launched…

  • CVE-2024-11744HigNov 26, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument name leads to sql injection. The attack can be…

  • CVE-2024-8676HigNov 26, 2024
    risk 0.41cvss 7.4epss 0.01

    A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore it. When it does that restoration, it attempts to restore the mounts from the restore archive instead of the pod request. As a result, the…

  • CVE-2024-49053HigNov 26, 2024
    risk 0.49cvss 7.6epss 0.01

    Microsoft Dynamics 365 Sales Spoofing Vulnerability

  • CVE-2024-49052HigNov 26, 2024
    risk 0.53cvss 8.2epss 0.01

    Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2024-49035HigKEVNov 26, 2024
    risk 0.69cvss 8.7epss 0.01

    An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

  • CVE-2024-8114HigNov 26, 2024
    risk 0.53cvss 8.2epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.

  • CVE-2024-52008HigNov 26, 2024
    risk 0.50cvss 8.8epss 0.01

    Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak passwords by bypassing client-side validation. While the UI enforces password complexity…

  • CVE-2024-32965HigNov 26, 2024
    risk 0.48cvss 8.1epss 0.24

    Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests to cause SSRF without logging in, attack intranet services, and leak sensitive information. The jwt token…

  • CVE-2024-53555HigNov 26, 2024
    risk 0.57cvss 8.8epss 0.01

    A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV file.

  • CVE-2024-11407HigNov 26, 2024
    risk 0.00cvss 7.5epss 0.01

    There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPC_ARG_TCP_TX_ZEROCOPY_ENABLED can experience data corruption issues. The data sent by the application may be corrupted before…

  • CVE-2024-52336HigNov 26, 2024
    risk 0.44cvss 7.8epss 0.00

    A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw allows a local non-privileged user to execute a D-Bus call with `script_pre` or `script_post`…

  • CVE-2024-9461HigNov 26, 2024
    risk 0.47cvss 7.2epss 0.01

    The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.6 via the cron_interval parameter. This is due to missing input validation and sanitization.…

  • CVE-2024-11702HigNov 26, 2024
    risk 0.49cvss 7.5epss 0.01

    Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This vulnerability affects Firefox < 133 and Thunderbird < 133.

  • CVE-2024-11700HigNov 26, 2024
    risk 0.53cvss 8.1epss 0.00

    Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133…

  • CVE-2024-11699HigNov 26, 2024
    risk 0.57cvss 8.8epss 0.01

    Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox <…

  • CVE-2024-11697HigNov 26, 2024
    risk 0.57cvss 8.8epss 0.01

    When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and…

  • CVE-2024-11691HigNov 26, 2024
    risk 0.57cvss 8.8epss 0.01

    Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were unaffected.* This…

  • CVE-2018-5852HigNov 26, 2024
    risk 0.55cvss 8.4epss 0.00

    An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat'

  • CVE-2018-11816HigNov 26, 2024
    risk 0.51cvss 7.8epss 0.00

    Crafted Binder Request Causes Heap UAF in MediaServer

  • CVE-2017-18307HigNov 26, 2024
    risk 0.55cvss 8.4epss 0.00

    Information disclosure possible while audio playback.

  • CVE-2017-18306HigNov 26, 2024
    risk 0.55cvss 8.4epss 0.00

    Information disclosure due to uninitialized variable.

  • CVE-2016-10408HigNov 26, 2024
    risk 0.55cvss 8.4epss 0.00

    QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory.

  • CVE-2024-51569HigNov 26, 2024
    risk 0.42cvss 7.5epss 0.01

    Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and invalid read from HCI transport memory. This issue requires broken or bogus Bluetooth controller and thus…

  • CVE-2024-38832HigNov 26, 2024
    risk 0.46cvss 7.1epss 0.00

    VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.

  • CVE-2024-38831HigNov 26, 2024
    risk 0.51cvss 7.8epss 0.00

    VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to  a root user on the appliance running VMware Aria Operations.

  • CVE-2024-38830HigNov 26, 2024
    risk 0.51cvss 7.8epss 0.00

    VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root user on the appliance running VMware Aria Operations.

  • CVE-2023-1521HigNov 26, 2024
    risk 0.51cvss 7.8epss 0.00

    On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LD_PRELOAD. If the server is run as root (which is the default when installing the snap package…

  • CVE-2023-0163HigNov 26, 2024
    risk 0.48cvss 8.4epss 0.00

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Mozilla Convict. This allows an attacker to inject attributes that are used in other components, or to override existing attributes with ones that have incompatible type,…

  • CVE-2024-50376HigNov 26, 2024
    risk 0.47cvss 7.3epss 0.00

    A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The vulnerability can…

  • CVE-2024-50369HigNov 26, 2024
    risk 0.47cvss 7.2epss 0.01

    A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the…

  • CVE-2024-50368HigNov 26, 2024
    risk 0.47cvss 7.2epss 0.01

    A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the…