VYPR

CVEs

115,452 total · page 860 of 2,310

  • CVE-2024-11099HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in code-projects Job Recruitment 1.0 and classified as critical. This issue affects some unknown processing of the file /login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been…

  • CVE-2024-47590HigNov 12, 2024
    risk 0.57cvss 8.8epss 0.01

    An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data will be used by the web site page generation to create content which when executed in the victim's browser (XXS)…

  • CVE-2024-25253HigNov 11, 2024
    risk 0.49cvss 7.5epss 0.00

    Driver Booster v10.6 was discovered to contain a buffer overflow via the Host parameter under the Customize proxy module.

  • CVE-2024-46966HigNov 11, 2024
    risk 0.53cvss 8.1epss 0.00

    The Ikhgur mn.ikhgur.khotoch (aka Video Downloader Pro & Browser) application through 1.0.42 for Android allows an attacker to execute arbitrary JavaScript code via the mn.ikhgur.khotoch.MainActivity component.

  • CVE-2024-46964HigNov 11, 2024
    risk 0.53cvss 8.1epss 0.00

    The com.video.downloader.all (aka All Video Downloader) application through 11.28 for Android allows an attacker to execute arbitrary JavaScript code via the com.video.downloader.all.StartActivity component.

  • CVE-2024-46963HigNov 11, 2024
    risk 0.53cvss 8.1epss 0.00

    The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via the com.bluesky.browser.ui.BrowserMainActivity component.

  • CVE-2024-52532HigNov 11, 2024
    risk 0.49cvss 7.5epss 0.01

    GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.

  • CVE-2024-52530HigNov 11, 2024
    risk 0.49cvss 7.5epss 0.01

    GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: chunked" header is treated the same as a "Transfer-Encoding: chunked" header.

  • CVE-2024-51487HigNov 11, 2024
    risk 0.53cvss 8.1epss 0.00

    Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating catalog. This vulnerability allows an attacker to exploit CSRF attacks, potentially…

  • CVE-2024-51485HigNov 11, 2024
    risk 0.53cvss 8.1epss 0.00

    Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating plugins. This vulnerability allows an attacker to exploit CSRF attacks, potentially…

  • CVE-2024-51484HigNov 11, 2024
    risk 0.53cvss 8.1epss 0.00

    Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or deactivating controllers. This vulnerability allows an attacker to exploit CSRF attacks, potentially…

  • CVE-2024-51186HigNov 11, 2024
    risk 0.52cvss 8.0epss 0.01

    D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr parameter in the ping_v4 and ping_v6 functions.

  • CVE-2024-48322HigNov 11, 2024
    risk 0.46cvss 8.1epss 0.01

    UsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability.

  • CVE-2024-11077HigNov 11, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in code-projects Job Recruitment 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has…

  • CVE-2024-47131HigNov 11, 2024
    risk 0.51cvss 7.8epss 0.00

    If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in BACnetObjectInfo can be exploited, allowing the attacker to remotely execute arbitrary code.

  • CVE-2024-39605HigNov 11, 2024
    risk 0.51cvss 7.8epss 0.03

    If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in BACnetParameter can be exploited, allowing the attacker to remotely execute arbitrary code.

  • CVE-2024-39354HigNov 11, 2024
    risk 0.51cvss 7.8epss 0.00

    If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in CEtherIPTagItem can be exploited, allowing the attacker to remotely execute arbitrary code.

  • CVE-2024-50263HigNov 11, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: fork: only invoke khugepaged, ksm hooks if no error There is no reason to invoke these hooks early against an mm that is in an incomplete state. The change in commit d24062914837 ("fork: use __mt_dup() to…

  • CVE-2024-10345HigNov 11, 2024
    risk 0.57cvss epss 0.00

    In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Karol Więsek.

  • CVE-2024-10344HigNov 11, 2024
    risk 0.57cvss epss 0.00

    In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the refuse function was identified. Reported by Karol Więsek.

  • CVE-2024-10314HigNov 11, 2024
    risk 0.57cvss epss 0.00

    In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the auto-generation function was identified. Reported by Karol Więsek.

  • CVE-2024-11067HigNov 11, 2024
    risk 0.49cvss 7.5epss 0.01

    The D-Link DSL6740C modem has a Path Traversal Vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files. Additionally, since the device's default password is a combination of the MAC address, attackers can obtain the…

  • CVE-2024-11066HigNov 11, 2024
    risk 0.47cvss 7.2epss 0.02

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through the specific web page.

  • CVE-2024-11065HigNov 11, 2024
    risk 0.47cvss 7.2epss 0.01

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.

  • CVE-2024-11064HigNov 11, 2024
    risk 0.47cvss 7.2epss 0.01

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.

  • CVE-2024-11063HigNov 11, 2024
    risk 0.47cvss 7.2epss 0.01

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.

  • CVE-2024-11062HigNov 11, 2024
    risk 0.47cvss 7.2epss 0.01

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.

  • CVE-2024-11017HigNov 11, 2024
    risk 0.57cvss 8.8epss 0.01

    Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to arbitrary code execution on the server.

  • CVE-2024-51882HigNov 11, 2024
    risk 0.55cvss 8.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopalkumar315 Gboy Custom Google Map gboy-custom-google-map allows Blind SQL Injection.This issue affects Gboy Custom Google Map: from n/a through <= 1.2.

  • CVE-2024-51845HigNov 11, 2024
    risk 0.55cvss 8.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in richteam Share Buttons – Social Media rich-web-share-button allows Blind SQL Injection.This issue affects Share Buttons – Social Media: from n/a through <= 1.0.2.

  • CVE-2024-51843HigNov 11, 2024
    risk 0.55cvss 8.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in fruitcakestudios Horsemanager fruitcake-horsemanager allows Blind SQL Injection.This issue affects Horsemanager: from n/a through <= 1.3.

  • CVE-2024-51837HigNov 11, 2024
    risk 0.55cvss 8.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sophia M Williams WP Contest wp-contest allows SQL Injection.This issue affects WP Contest: from n/a through <= 1.0.0.

  • CVE-2024-51820HigNov 11, 2024
    risk 0.55cvss 8.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wplsquared L Squared Hub WP l-squared-hub-wp-virtual-device allows SQL Injection.This issue affects L Squared Hub WP: from n/a through <= 1.0.

  • CVE-2024-48939HigNov 11, 2024
    risk 0.49cvss 7.5epss 0.01

    Insufficient validation performed on the REST API License file in Paxton Net2 before 6.07.14023.5015 (SR4) enables use of the REST API with an invalid License File. Attackers may be able to retrieve access-log data.

  • CVE-2024-41992HigNov 11, 2024
    risk 0.57cvss 8.8epss 0.03

    Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP…

  • CVE-2024-11061HigNov 11, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability classified as critical was found in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function FUN_0044db3c of the file /goform/fast_setting_wifi_set. The manipulation of the argument timeZone leads to stack-based buffer overflow. The attack can be…

  • CVE-2020-10370HigNov 11, 2024
    risk 0.50cvss 8.8epss 0.01

    Certain Cypress (and Broadcom) Wireless Combo chips such as CYW43455, when a 2021-01-26 Bluetooth firmware update is not present, allow a Bluetooth outage via a "Spectra" attack.

  • CVE-2021-41737HigNov 10, 2024
    risk 0.49cvss 7.5epss 0.00

    In Faust 2.23.1, an input file with the lines "// r visualisation tCst" and "//process = +: L: abM-^Q;" and "process = route(3333333333333333333,2,1,2,3,1) : *;" leads to stack consumption.

  • CVE-2024-46956HigNov 10, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

  • CVE-2024-46954HigNov 10, 2024
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.

  • CVE-2024-46953HigNov 10, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.

  • CVE-2024-46952HigNov 10, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values).

  • CVE-2024-46951HigNov 10, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.

  • CVE-2024-11057HigNov 10, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in Codezips Hospital Appointment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /removeBranchResult.php. The manipulation of the argument ID/Name leads to sql injection. The attack can…

  • CVE-2024-11056HigNov 10, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability, which was classified as critical, was found in Tenda AC10 16.03.10.13. Affected is the function FUN_0046AC38 of the file /goform/WifiExtraSet. The manipulation of the argument wpapsk_crypto leads to stack-based buffer overflow. It is possible to launch the…

  • CVE-2024-11055HigNov 10, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in 1000 Projects Beauty Parlour Management System 1.0. This issue affects some unknown processing of the file /admin/admin-profile.php. The manipulation of the argument adminname leads to sql injection. The attack…

  • CVE-2024-10958HigNov 10, 2024
    risk 0.48cvss 7.3epss 0.02

    The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the software allowing users to execute an action that does not…

  • CVE-2024-11048HigNov 10, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been rated as critical. Affected by this issue is the function dbsrv_asp of the file /dbsrv.asp. The manipulation of the argument str leads to stack-based buffer overflow. The attack may be launched remotely. The…

  • CVE-2024-11047HigNov 10, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been declared as critical. Affected by this vulnerability is the function upgrade_filter_asp of the file /upgrade_filter.asp. The manipulation of the argument path leads to stack-based buffer overflow. The attack can…

  • CVE-2024-51608HigNov 9, 2024
    risk 0.55cvss 8.5epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in colinph970 AmaDiscount amadiscount allows SQL Injection.This issue affects AmaDiscount: from n/a through <= 1.0.