VYPR

CVEs

115,388 total · page 871 of 2,308

  • CVE-2024-10430HigOct 27, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Codezips Pet Shop Management System 1.0. This issue affects some unknown processing of the file /animalsupdate.php. The manipulation of the argument id leads to sql injection. The attack may be initiated…

  • CVE-2024-50616HigOct 27, 2024
    risk 0.57cvss 8.8epss 0.00

    Ironman PowerShell Universal 5.x before 5.0.12 allows an authenticated attacker to elevate their privileges and view job information.

  • CVE-2024-50611HigOct 27, 2024
    risk 0.40cvss 7.2epss 0.01

    CycloneDX cdxgen through 10.10.7, when run against an untrusted codebase, may execute code contained within build-related files such as build.gradle.kts, a similar issue to CVE-2022-24441. cdxgen is used by, for example, OWASP dep-scan. NOTE: this has been characterized as a…

  • CVE-2024-10429HigOct 27, 2024
    risk 0.48cvss 7.2epss 0.18

    A vulnerability classified as critical has been found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. Affected is the function set_ipv6 of the file internet.cgi. The manipulation of the argument IPv6OpMode/IPv6IPAddr/IPv6WANIPAddr/IPv6GWAddr leads to command injection.…

  • CVE-2024-10428HigOct 27, 2024
    risk 0.48cvss 7.2epss 0.15

    A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This issue affects the function set_ipv6 of the file firewall.cgi. The manipulation of the argument dhcpGateway leads to command injection. The attack may be…

  • CVE-2020-26311HigOct 26, 2024
    risk 0.42cvss 7.5epss 0.01

    Useragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no patches are available.

  • CVE-2020-26310HigOct 26, 2024
    risk 0.57cvss epss 0.00

    Validate.js provides a declarative way of validating javascript objects. All versions as of 30 November 2020 contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any patches are…

  • CVE-2020-26309HigOct 26, 2024
    risk 0.50cvss epss 0.00

    Validate.js provides a declarative way of validating javascript objects. Versions 0.11.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any patches are available.

  • CVE-2020-26308HigOct 26, 2024
    risk 0.49cvss 7.5epss 0.01

    Validate.js provides a declarative way of validating javascript objects. Versions 0.13.1 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.

  • CVE-2020-26307HigOct 26, 2024
    risk 0.57cvss epss 0.00

    HTML2Markdown is a Javascript implementation for converting HTML to Markdown text. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.

  • CVE-2020-26306HigOct 26, 2024
    risk 0.50cvss epss 0.00

    Knwl.js is a Javascript library that parses through text for dates, times, phone numbers, emails, places, and more. Versions 1.0.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no…

  • CVE-2020-26305HigOct 26, 2024
    risk 0.49cvss 7.5epss 0.00

    CommonRegexJS is a CommonRegex port for JavaScript. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.

  • CVE-2020-26304HigOct 26, 2024
    risk 0.49cvss 7.5epss 0.01

    Foundation is a front-end framework. Versions 6.3.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any fixes are available.

  • CVE-2020-26303HigOct 26, 2024
    risk 0.49cvss 7.5epss 0.01

    insane is a whitelist-oriented HTML sanitizer. Versions 2.6.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.

  • CVE-2024-10402HigOct 26, 2024
    risk 0.49cvss 7.5epss 0.01

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.35.1. This makes it possible for authenticated attackers,…

  • CVE-2024-9772HigOct 26, 2024
    risk 0.48cvss 7.3epss 0.01

    The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.9. This is due to the software allowing users to execute an action that does not properly validate a value before…

  • CVE-2024-9637HigOct 26, 2024
    risk 0.50cvss 8.8epss 0.00

    The School Management System – WPSchoolPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.10. This is due to the plugin not properly validating a user's identity prior to updating their details like…

  • CVE-2024-8392HigOct 26, 2024
    risk 0.40cvss 7.2epss 0.01

    The WordPress Post Grid Layouts with Pagination – Sogrid plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.5.6 via the 'tab' parameter. This makes it possible for authenticated attackers, with Administrator-level access and…

  • CVE-2024-0128HigOct 26, 2024
    risk 0.46cvss 7.1epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager that allows a user of the guest OS to access global resources. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.

  • CVE-2024-0127HigOct 26, 2024
    risk 0.51cvss 7.8epss 0.00

    NVIDIA vGPU software contains a vulnerability in the GPU kernel driver of the vGPU Manager for all supported hypervisors, where a user of the guest OS can cause an improper input validation by compromising the guest OS kernel. A successful exploit of this vulnerability might…

  • CVE-2024-0126HigOct 26, 2024
    risk 0.53cvss 8.2epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure,…

  • CVE-2024-0121HigOct 26, 2024
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,…

  • CVE-2024-0120HigOct 26, 2024
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,…

  • CVE-2024-0119HigOct 26, 2024
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,…

  • CVE-2024-0118HigOct 26, 2024
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,…

  • CVE-2024-0117HigOct 26, 2024
    risk 0.51cvss 7.8epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges,…

  • CVE-2024-9890HigOct 26, 2024
    risk 0.50cvss 8.8epss 0.01

    The User Toolkit plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.3. This is due to an improper capability check in the 'switchUser' function. This makes it possible for authenticated attackers, with subscriber-level permissions…

  • CVE-2024-48230HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.00

    funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php.

  • CVE-2024-48229HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.00

    funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin.

  • CVE-2024-48226HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.01

    Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield.

  • CVE-2024-48223HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.01

    Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist.

  • CVE-2024-48222HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.01

    Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit.

  • CVE-2024-48218HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.01

    Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list.

  • CVE-2024-49767HigOct 25, 2024
    risk 0.42cvss 7.5epss 0.01

    Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parse `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively…

  • CVE-2024-37847HigOct 25, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted file.

  • CVE-2024-37845HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.01

    MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.

  • CVE-2024-48700HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.01

    Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or getShell via the edit_page.php component.

  • CVE-2024-48655HigOct 25, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.

  • CVE-2024-48459HigOct 25, 2024
    risk 0.48cvss 7.3epss 0.08

    A command execution vulnerability exists in the AX2 Pro home router produced by Shenzhen Tenda Technology Co., Ltd. (Jixiang Tenda) v.DI_7003G-19.12.24A1V16.03.29.50;V16.03.29.50;V16.03.29.50. An attacker can exploit this vulnerability by constructing a malicious payload to…

  • CVE-2024-10387HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.08

    CVE-2024-10387 IMPACT A Denial-of-Service vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in Denial-of-Service.

  • CVE-2022-30358HigOct 25, 2024
    risk 0.57cvss 8.8epss 0.01

    OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw parameters. Authentication is required.

  • CVE-2022-30357HigOct 25, 2024
    risk 0.57cvss 8.8epss 0.00

    OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required.

  • CVE-2022-30354HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.01

    OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserWithTeam. Authentication is required. The information disclosed is associated with all registered user ID numbers.

  • CVE-2024-49757HigOct 25, 2024
    risk 0.42cvss 7.5epss 0.03

    The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. Due to a missing security check in versions prior to 2.64.0, 2.63.5, 2.62.7, 2.61.4, 2.60.4, 2.59.5, and 2.58.7, disabling the "User Registration allowed" option…

  • CVE-2024-49381HigOct 25, 2024
    risk 0.42cvss 7.5epss 0.01

    Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write deletion when a plenti user serves their website. This issue may lead to information loss. Version 0.7.2…

  • CVE-2024-49380HigOct 25, 2024
    risk 0.42cvss 7.5epss 0.03

    Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write vulnerability when a plenti user serves their website. This issue may lead to Remote Code Execution. Version…

  • CVE-2024-9991HigOct 25, 2024
    risk 0.46cvss epss 0.00

    This vulnerability exists in Philips lighting devices due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext Wi-Fi…

  • CVE-2024-49376HigOct 25, 2024
    risk 0.50cvss 8.8epss 0.00

    Autolab, a course management service that enables auto-graded programming assignments, has misconfigured reset password permissions in version 3.0.0. For email-based accounts, users with insufficient privileges could reset and theoretically access privileged users' accounts by…

  • CVE-2024-47041HigOct 25, 2024
    risk 0.51cvss 7.8epss 0.00

    In valid_address of syscall.c, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-47035HigOct 25, 2024
    risk 0.51cvss 7.8epss 0.00

    In vring_init of external/headers/include/virtio/virtio_ring.h, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…