VYPR

CVEs

115,453 total · page 852 of 2,310

  • CVE-2024-52940HigNov 18, 2024
    risk 0.49cvss 7.5epss 0.01

    AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network traffic. The attacker must know the victim's AnyDesk ID.

  • CVE-2024-43704HigNov 18, 2024
    risk 0.55cvss 8.4epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to gain access to the graphics buffers of a parent process.

  • CVE-2024-52920HigNov 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.

  • CVE-2024-52916HigNov 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.

  • CVE-2024-52915HigNov 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message.

  • CVE-2024-52914HigNov 18, 2024
    risk 0.49cvss 7.5epss 0.01

    In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed transaction.

  • CVE-2024-52912HigNov 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offset for newly connecting peers) and an abs64 logic bug.

  • CVE-2019-25220HigNov 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a "Chain Width Expansion" attack) because a node does not first verify that a presented chain has enough work before committing to…

  • CVE-2024-0793HigNov 17, 2024
    risk 0.43cvss 7.7epss 0.01

    A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn.

  • CVE-2023-4639HigNov 17, 2024
    risk 0.41cvss 7.4epss 0.01

    A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary additional cookie values, leading…

  • CVE-2020-25720HigNov 17, 2024
    risk 0.49cvss 7.5epss 0.00

    A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the newly created object, including security-sensitive attributes, even after the object's creation. This issue occurs because…

  • CVE-2024-52876HigNov 17, 2024
    risk 0.49cvss 7.5epss 0.00

    Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remote power off" actions (in broadcast mode) via multiple read operations on the ASTM Remote ID (0xFFFA) GATT.

  • CVE-2024-52872HigNov 17, 2024
    risk 0.00cvss 7.5epss 0.00

    In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.

  • CVE-2024-52871HigNov 17, 2024
    risk 0.00cvss 7.5epss 0.00

    In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.

  • CVE-2024-52867HigNov 17, 2024
    risk 0.46cvss 8.1epss 0.00

    guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and setgid programs) are properly addressed. The vulnerability can be remediated within the product via certain…

  • CVE-2024-52415HigNov 16, 2024
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in skipstorm SK WP Settings Backup sk-wp-settings-backup allows Object Injection.This issue affects SK WP Settings Backup: from n/a through <= 1.0.

  • CVE-2024-9887HigNov 16, 2024
    risk 0.47cvss 7.2epss 0.00

    The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.15.6 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2024-10645HigNov 16, 2024
    risk 0.49cvss 7.5epss 0.00

    The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘br’ parameter in all versions up to, and including, 2.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

  • CVE-2024-10728HigNov 16, 2024
    risk 0.53cvss 8.8epss 0.36

    The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the 'install_required_plugin_callback' function in all versions up to, and including, 4.1.16.…

  • CVE-2024-9935HigNov 16, 2024
    risk 0.49cvss 7.5epss 0.07

    The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0.0 via the rtw_pgaepb_dwnld_pdf() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary…

  • CVE-2024-9849HigNov 16, 2024
    risk 0.50cvss 8.8epss 0.01

    The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'r3dfb_save_thumbnail_callback' function in all versions up to, and including, 4.8. This makes it possible…

  • CVE-2024-9839HigNov 16, 2024
    risk 0.47cvss 7.3epss 0.01

    The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes…

  • CVE-2024-9192HigNov 16, 2024
    risk 0.57cvss 8.8epss 0.01

    The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due to insufficient validation on user meta that can be updated in the wpvr_rate_request_result() function in all versions up to, and including, 1.20.0. This makes…

  • CVE-2024-9500HigNov 15, 2024
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to insecure privilege management.

  • CVE-2017-13314HigNov 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This could lead to local escalation of privilege allowing users to access non-VPN networks, when they are supposed to be restricted to the…

  • CVE-2017-13312HigNov 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execution privileges needed. User…

  • CVE-2017-13310HigNov 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where an app can start an activity with system privileges with no additional execution privileges needed.…

  • CVE-2024-49060HigNov 15, 2024
    risk 0.57cvss 8.8epss 0.00

    Azure Stack HCI Elevation of Privilege Vulnerability

  • CVE-2024-44759HigNov 15, 2024
    risk 0.49cvss 7.5epss 0.00

    An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.

  • CVE-2024-11258HigNov 15, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in 1000 Projects Beauty Parlour Management System 1.0. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely.…

  • CVE-2024-11257HigNov 15, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in 1000 Projects Beauty Parlour Management System 1.0. This affects an unknown part of the file /admin/forgot-password.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack…

  • CVE-2024-11256HigNov 15, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. This issue affects some unknown processing of the file /login.php. The manipulation of the argument username leads to sql injection. The attack may be initiated remotely.…

  • CVE-2024-51141HigNov 15, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAutoInstallDriver.exe and MSASN1.dll components.

  • CVE-2024-45969HigNov 15, 2024
    risk 0.42cvss 7.5epss 0.00

    NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e357ef33 allows a malicious server to Cause a Denial-of-Service via the MMS InitiationResponse message.

  • CVE-2024-24431HigNov 15, 2024
    risk 0.49cvss 7.5epss 0.01

    A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet with a zero-length EMM message length.

  • CVE-2024-24426HigNov 15, 2024
    risk 0.49cvss 7.5epss 0.00

    Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation v1.2.0 allow attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

  • CVE-2024-52508HigNov 15, 2024
    risk 0.00cvss 8.2epss 0.01

    Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mail account with an email address like [email protected] that does not support auto configuration, and an attacker managed to register autoconfig.tld, the used…

  • CVE-2024-46467HigNov 15, 2024
    risk 0.51cvss 7.8epss 0.00

    By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONEPOINT has to be modified to prevent this vulnerability.

  • CVE-2024-46466HigNov 15, 2024
    risk 0.51cvss 7.8epss 0.00

    By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONECENTRAL has to be modified…

  • CVE-2024-46465HigNov 15, 2024
    risk 0.51cvss 7.8epss 0.00

    By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of CRYHOD has to be modified to prevent this vulnerability.

  • CVE-2024-46463HigNov 15, 2024
    risk 0.51cvss 7.8epss 0.00

    By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ORIZON has to be modified to prevent this vulnerability.

  • CVE-2024-46462HigNov 15, 2024
    risk 0.51cvss 7.8epss 0.00

    By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZEDMAIL has to be modified to prevent this vulnerability.

  • CVE-2024-40638HigNov 15, 2024
    risk 0.49cvss 8.1epss 0.37

    GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used to alter another user account data and take control of it. Upgrade to 10.0.17.

  • CVE-2024-50654HigNov 15, 2024
    risk 0.49cvss 7.5epss 0.02

    lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data packets for coupon collection in high concurrency.

  • CVE-2024-50653HigNov 15, 2024
    risk 0.49cvss 7.5epss 0.01

    CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets and sending a large number of data packets for coupon collection, achieving unlimited coupon collection.

  • CVE-2024-44625HigNov 15, 2024
    risk 0.58cvss 8.8epss 0.15

    Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.

  • CVE-2024-39726HigNov 15, 2024
    risk 0.53cvss 8.2epss 0.01

    IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.

  • CVE-2024-11248HigNov 15, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg. The manipulation of the argument rebootTime leads to stack-based buffer overflow. The attack may be…

  • CVE-2024-50650HigNov 15, 2024
    risk 0.49cvss 7.5epss 0.01

    python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

  • CVE-2024-50647HigNov 15, 2024
    risk 0.49cvss 7.5epss 0.00

    The python_food ordering system V1.0 has an unauthorized vulnerability that leads to the leakage of sensitive user information. Attackers can access it through https://ip:port/api/myapp/index/user/info?id=1 And modify the ID value to obtain sensitive user information beyond…