VYPR

CVEs

115,463 total · page 846 of 2,310

  • CVE-2024-6815HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.01

    IrfanView RLE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must…

  • CVE-2024-6260HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Malwarebytes Antimalware Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Malwarebytes Antimalware. An attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2024-6249HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Wyze Cam v3 TCP Traffic Handling Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wyze Cam v3 IP cameras. Authentication is not required to exploit this…

  • CVE-2024-6248HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    Wyze Cam v3 Cloud Infrastructure Improper Authentication Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wyze Cam v3 IP cameras. Authentication is not required to exploit this…

  • CVE-2024-6246HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Wyze Cam v3 Realtek Wi-Fi Driver Heap-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Wyze Cam v3 IP cameras. Authentication is not required to exploit this…

  • CVE-2024-6233HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Check Point ZoneAlarm Extreme Security. An attacker must first obtain the ability to…

  • CVE-2024-5877HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.01

    IrfanView PIC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must…

  • CVE-2024-5876HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.01

    IrfanView PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target…

  • CVE-2024-5875HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.01

    IrfanView SHP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must…

  • CVE-2024-5874HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.01

    IrfanView PNT File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must…

  • CVE-2024-5722HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Logsign Unified SecOps Platform HTTP API Hard-coded Cryptographic Key Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Authentication is not required…

  • CVE-2024-5721HigNov 22, 2024
    risk 0.56cvss 8.1epss 0.06

    Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this…

  • CVE-2024-5720HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.03

    Logsign Unified SecOps Platform Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Although authentication is required to exploit this…

  • CVE-2024-5719HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.03

    Logsign Unified SecOps Platform Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Although authentication is required to exploit this…

  • CVE-2024-5718HigNov 22, 2024
    risk 0.53cvss 8.1epss 0.01

    Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Authentication is not required to exploit this…

  • CVE-2024-5717HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.03

    Logsign Unified SecOps Platform Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Logsign Unified SecOps Platform. Although authentication is required to exploit this…

  • CVE-2024-5581HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.02

    Allegra unzipFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2024-5580HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.02

    Allegra loadFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is required to exploit this vulnerability. The specific flaw…

  • CVE-2024-5579HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.02

    Allegra renderFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is required to exploit this vulnerability. The specific flaw…

  • CVE-2024-5513HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Kofax Power PDF JP2 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the…

  • CVE-2024-5511HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Kofax Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the…

  • CVE-2024-5510HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Kofax Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the…

  • CVE-2024-30377HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    G DATA Total Security Scan Server Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged…

  • CVE-2024-30376HigNov 22, 2024
    risk 0.47cvss 7.3epss 0.00

    Famatech Advanced IP Scanner Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Famatech Advanced IP Scanner. An attacker must first obtain the ability to…

  • CVE-2024-1868HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2024-1867HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total Security. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2023-52335HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability. The…

  • CVE-2023-52333HigNov 22, 2024
    risk 0.48cvss 7.3epss 0.02

    Allegra saveFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is required to exploit this vulnerability, product implements a…

  • CVE-2023-52332HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.02

    Allegra serveMathJaxLibraries Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2023-51644HigNov 22, 2024
    risk 0.48cvss 7.3epss 0.02

    Allegra SiteConfigAction Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is not required to exploit this vulnerability. The specific flaw…

  • CVE-2023-51635HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    NETGEAR RAX30 fing_dil Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this…

  • CVE-2023-51634HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    NETGEAR RAX30 Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR RAX30 routers. Authentication is not required to…

  • CVE-2023-39470HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.02

    PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability. The…

  • CVE-2024-52726HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.02

    CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensitive information

  • CVE-2024-11618HigNov 22, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in IPC Unigy Management System 04.03.00.08.0027. Affected by this vulnerability is an unknown functionality of the component HTTP Request Handler. The manipulation leads to server-side request forgery. The attack can be launched…

  • CVE-2024-44786HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vectors.

  • CVE-2024-10220HigNov 22, 2024
    risk 0.46cvss 8.1epss 0.03

    The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.

  • CVE-2024-52804HigNov 22, 2024
    risk 0.42cvss 7.5epss 0.01

    Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This…

  • CVE-2024-52802HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    RIOT is an operating system for internet of things (IoT) devices. In version 2024.04 and prior, the function `_parse_advertise`, located in `/sys/net/application_layer/dhcpv6/client.c`, has no minimum header length check for `dhcpv6_opt_t` after processing `dhcpv6_msg_t`. This…

  • CVE-2024-50401HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.01

    A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have…

  • CVE-2024-50400HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.01

    A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have…

  • CVE-2024-50399HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.01

    A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have…

  • CVE-2024-50398HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.01

    A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modify memory. We have…

  • CVE-2024-50397HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed…

  • CVE-2024-50396HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to obtain secret data or modify memory. We have already fixed the vulnerability in the…

  • CVE-2024-50395HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to gain privilege. We have already fixed the vulnerability in the following version: Media…

  • CVE-2024-48861HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.01

    An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. We have already fixed the vulnerability in the following versions: QuRouter 2.4.4.106 and later

  • CVE-2024-38647HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attackers to compromise the security of the system. We have already fixed the vulnerability in the following version: QNAP AI Core…

  • CVE-2024-38644HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.02

    An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later

  • CVE-2024-37044HigNov 22, 2024
    risk 0.47cvss 7.2epss 0.01

    A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute code. We have already fixed the…