VYPR

CVEs

115,461 total · page 847 of 2,310

  • CVE-2023-24466HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.

  • CVE-2022-26324HigNov 22, 2024
    risk 0.49cvss 7.6epss 0.00

    Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.6.0000.

  • CVE-2021-38135HigNov 22, 2024
    risk 0.56cvss 8.6epss 0.00

    Possible External Service Interaction attack in iManager has been discovered in OpenText™ iManager 3.2.6.0000.

  • CVE-2021-38117HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

  • CVE-2021-38116HigNov 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Possible Elevation of Privilege Vulnerability in iManager has been discovered in OpenText™ iManager. This impacts all versions before 3.2.5

  • CVE-2024-7837HigNov 22, 2024
    risk 0.53cvss 8.2epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Firmanet Software ERP allows SQL Injection. This issue affects ERP: through 22.11.2024. NOTE: The vendor was contacted early about this disclosure but did not respond in…

  • CVE-2024-11601HigNov 22, 2024
    risk 0.53cvss 8.1epss 0.00

    The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.1. This is due to…

  • CVE-2024-11104HigNov 22, 2024
    risk 0.53cvss 8.1epss 0.01

    The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check…

  • CVE-2024-31408HigNov 22, 2024
    risk 0.52cvss 8.0epss 0.01

    OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker may execute an arbitrary OS command with root privileges by sending a specially crafted request.

  • CVE-2024-52052HigNov 21, 2024
    risk 0.47cvss 7.2epss 0.00

    Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege remote code execution.

  • CVE-2024-51364HigNov 21, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a crafted .xml file.

  • CVE-2024-53093HigNov 21, 2024
    risk 0.49cvss 7.5epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: defer partition scanning We need to suppress the partition scan from occuring within the controller's scan_work context. If a path error occurs here, the IO will wait until a path becomes…

  • CVE-2024-53092HigNov 21, 2024
    risk 0.55cvss 8.4epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: virtio_pci: Fix admin vq cleanup by using correct info pointer vp_modern_avq_cleanup() and vp_del_vqs() clean up admin vq resources by virtio_pci_vq_info pointer. The info pointer of admin vq is stored in…

  • CVE-2024-53091HigNov 21, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: bpf: Add sk_is_inet and IS_ICSK check in tls_sw_has_ctx_tx/rx As the introduction of the support for vsock and unix sockets in sockmap, tls_sw_has_ctx_tx/rx cannot presume the socket passed in must be IS_ICSK.…

  • CVE-2024-53090HigNov 21, 2024
    risk 0.49cvss 7.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: afs: Fix lock recursion afs_wake_up_async_call() can incur lock recursion. The problem is that it is called from AF_RXRPC whilst holding the ->notify_lock, but it tries to take a ref on the afs_call struct in…

  • CVE-2024-53432HigNov 21, 2024
    risk 0.49cvss 7.5epss 0.01

    While parsing certain malformed PLY files, PCL version 1.14.1 crashes due to an uncaught std::out_of_range exception in PCLPointCloud2::at. This issue could potentially be exploited to cause a denial-of-service (DoS) attack when processing untrusted PLY files.

  • CVE-2024-53335HigNov 21, 2024
    risk 0.51cvss 7.8epss 0.00

    TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi.

  • CVE-2024-53334HigNov 21, 2024
    risk 0.57cvss 8.8epss 0.01

    TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in infostat.cgi.

  • CVE-2024-52287HigNov 21, 2024
    risk 0.00cvss 7.2epss 0.01

    authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from authentik with scopes that haven't been configured in authentik. authentik 2024.8.5 and 2024.10.3 fix this issue.

  • CVE-2024-48288HigNov 21, 2024
    risk 0.53cvss 8.0epss 0.10

    TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend.

  • CVE-2024-48286HigNov 21, 2024
    risk 0.53cvss 8.0epss 0.12

    Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function.

  • CVE-2024-52803HigNov 21, 2024
    risk 0.42cvss 7.5epss 0.02

    LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has been identified in the LLama Factory training process. This vulnerability arises from improper handling of user input, allowing malicious actors to execute…

  • CVE-2024-52799HigNov 21, 2024
    risk 0.46cvss 8.2epss 0.00

    Argo Workflows Chart is used to set up argo and its needed dependencies through one command. Prior to 0.44.0, the workflow-role has excessive privileges, the worst being create pods/exec, which will allow kubectl exec into any Pod in the same namespace, i.e. arbitrary code…

  • CVE-2024-53429HigNov 21, 2024
    risk 0.49cvss 7.5epss 0.01

    Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.

  • CVE-2024-28027HigNov 21, 2024
    risk 0.47cvss 7.2epss 0.07

    Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger…

  • CVE-2024-28026HigNov 21, 2024
    risk 0.47cvss 7.2epss 0.06

    Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger…

  • CVE-2024-28025HigNov 21, 2024
    risk 0.47cvss 7.2epss 0.07

    Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger…

  • CVE-2024-21786HigNov 21, 2024
    risk 0.48cvss 7.2epss 0.11

    An OS command injection vulnerability exists in the web interface configuration upload functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger…

  • CVE-2024-11592HigNov 21, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in 1000 Projects Beauty Parlour Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/about-us.php. The manipulation of the argument pagetitle leads to sql injection. The attack can be…

  • CVE-2024-7026HigNov 21, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind SQL Injection. This issue affects Closed Circuit Vehicle Tracking Software: through…

  • CVE-2024-11591HigNov 21, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in 1000 Projects Beauty Parlour Management System 1.0. This affects an unknown part of the file /admin/add-services.php. The manipulation of the argument sername leads to sql injection. It is possible to initiate the…

  • CVE-2024-11590HigNov 21, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affected by this issue is some unknown functionality of the file /forget_password_process.php. The manipulation of the argument unm leads to sql injection. The…

  • CVE-2024-7517HigNov 21, 2024
    risk 0.51cvss 7.8epss 0.01

    A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific exploitation is only…

  • CVE-2024-11596HigNov 21, 2024
    risk 0.51cvss 7.8epss 0.00

    ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file

  • CVE-2024-11595HigNov 21, 2024
    risk 0.51cvss 7.8epss 0.00

    FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file

  • CVE-2024-11409HigNov 21, 2024
    risk 0.47cvss 7.2epss 0.01

    The Grid View Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input from cs_all_photos_details parameter. This makes it possible for authenticated attackers, with Editor-level access…

  • CVE-2024-10898HigNov 21, 2024
    risk 0.50cvss 8.8epss 0.01

    The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the cf7_email_add_on_add_admin_template() function. This makes it possible for authenticated attackers, with Contributor-level access and…

  • CVE-2024-10788HigNov 21, 2024
    risk 0.40cvss 7.2epss 0.01

    The Activity Log – Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event parameters in all versions up to, and including, 2.11.1 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2024-10403HigNov 21, 2024
    risk 0.49cvss 7.5epss 0.01

    Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that is later captured via…

  • CVE-2024-10400HigNov 21, 2024
    risk 0.48cvss 7.5epss 0.82

    The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

  • CVE-2024-9875HigNov 21, 2024
    risk 0.46cvss 7.1epss 0.00

    Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. To remediate this vulnerability, upgrade the Okta Privileged Access server agent (SFTD) to version 1.87.1…

  • CVE-2024-52581HigNov 20, 2024
    risk 0.42cvss 7.5epss 0.01

    Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.13.0, the multipart form parser shipped with litestar expects the entire request body as a single byte string and there is no default limit for the total size of the request body. This…

  • CVE-2024-48986HigNov 20, 2024
    risk 0.00cvss 7.5epss 0.00

    An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from its header. Certain events cause a callback, the logic for which allocates a buffer (the length of which is determined by looking…

  • CVE-2024-48982HigNov 20, 2024
    risk 0.00cvss 7.5epss 0.00

    An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from its header. This value is assumed to be greater than or equal to 3, but the software doesn't ensure that this is the case.…

  • CVE-2024-48536HigNov 20, 2024
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request.

  • CVE-2024-48530HigNov 20, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

  • CVE-2024-48985HigNov 20, 2024
    risk 0.00cvss 7.5epss 0.00

    An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading 2 bytes from the packet data. A buffer is then allocated to contain the entire packet, the size of which is calculated as the…

  • CVE-2024-48983HigNov 20, 2024
    risk 0.00cvss 7.5epss 0.00

    An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading 2 bytes from the packet header. A buffer is then allocated to contain the entire packet, the size of which is calculated as…

  • CVE-2024-48981HigNov 20, 2024
    risk 0.00cvss 7.5epss 0.00

    An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet header by looking up the identifying first byte and matching it against a table of possible lengths. The initial parsing function,…

  • CVE-2024-52739HigNov 20, 2024
    risk 0.53cvss 8.0epss 0.09

    D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters.