VYPR

CVEs

115,383 total · page 872 of 2,308

  • CVE-2024-47022HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.00

    Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ACPM component, A-331255656.

  • CVE-2024-47021HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.00

    In sms_ExtractCbLanguage of sms_CellBroadcast.c, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-47020HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.00

    Android before 2024-10-05 on Google Pixel devices allows information disclosure in the ABL component, A-331966488.

  • CVE-2024-47017HigOct 25, 2024
    risk 0.51cvss 7.8epss 0.00

    In ufshc_scsi_cmd of ufs.c, there is a possible stack variable use after free due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-47016HigOct 25, 2024
    risk 0.51cvss 7.8epss 0.00

    there is a possible privilege escalation due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-47014HigOct 25, 2024
    risk 0.57cvss 8.8epss 0.00

    Android before 2024-10-05 on Google Pixel devices allows privilege escalation in the ABL component, A-330537292.

  • CVE-2024-47013HigOct 25, 2024
    risk 0.51cvss 7.8epss 0.00

    In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-47012HigOct 25, 2024
    risk 0.51cvss 7.8epss 0.00

    In mm_GetMobileIdIndexForNsUpdate of mm_GmmPduCodec.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-44101HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.00

    there is a possible Null Pointer Dereference (modem crash) due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-44100HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.00

    Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.

  • CVE-2024-44098HigOct 25, 2024
    risk 0.48cvss 7.4epss 0.00

    In lwis_device_event_states_clear_locked of lwis_event.c, there is a possible privilege escalation due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-9598HigOct 25, 2024
    risk 0.50cvss 8.8epss 0.00

    The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible for unauthenticated…

  • CVE-2024-45785HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.00

    MUSASI version 3 contains an issue with use of client-side authentication. If this vulnerability is exploited, other users' credential and sensitive information may be retrieved.

  • CVE-2024-9302HigOct 25, 2024
    risk 0.46cvss 8.1epss 0.01

    The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.3.7. This is due to the verify_otp_forgot_password() and update_password() functions not…

  • CVE-2024-9235HigOct 25, 2024
    risk 0.50cvss 8.8epss 0.01

    The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to an insufficient capability check on the mapster_wp_maps_set_option_from_js() function in all versions up to, and including, 1.5.0. This makes…

  • CVE-2024-47801HigOct 25, 2024
    risk 0.48cvss 7.4epss 0.00

    Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scripting vulnerability. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.

  • CVE-2024-47549HigOct 25, 2024
    risk 0.48cvss 7.4epss 0.00

    Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of unintended data to HTTP response headers. Accessing a crafted URL which points to an affected product may cause malicious script executed on the web browser.

  • CVE-2024-47005HigOct 25, 2024
    risk 0.53cvss 8.1epss 0.00

    Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted. A non-administrative user may execute some configuration APIs.

  • CVE-2024-43424HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.01

    Sharp and Toshiba Tec MFPs improperly process HTTP request headers, resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed.

  • CVE-2024-42420HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.01

    Sharp and Toshiba Tec MFPs contain multiple Out-of-bounds Read vulnerabilities, due to improper processing of keyword search input and improper processing of SOAP messages. Crafted HTTP requests may cause affected products crashed.

  • CVE-2024-10011HigOct 25, 2024
    risk 0.46cvss 8.1epss 0.01

    The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the…

  • CVE-2024-10370HigOct 25, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Codezips Sales Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /addcustind.php. The manipulation of the argument refno leads to sql injection. The attack may be launched remotely.…

  • CVE-2024-10369HigOct 25, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Codezips Sales Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /addcustcom.php. The manipulation of the argument refno leads to sql injection. The attack can be launched…

  • CVE-2024-10368HigOct 25, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Codezips Sales Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /addstock.php. The manipulation of the argument prodtype leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2024-10351HigOct 25, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Tenda RX9 Pro 22.03.02.20. It has been rated as critical. This issue affects the function sub_424CE0 of the file /goform/setMacFilterCfg of the component POST Request Handler. The manipulation of the argument deviceList leads to stack-based buffer…

  • CVE-2024-49760HigOct 24, 2024
    risk 0.39cvss 7.1epss 0.01

    OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the path of the localization file to load, of the form `translations-$LANG.json`. But when doing so in versions prior to 3.8.3, it…

  • CVE-2024-49359HigOct 24, 2024
    risk 0.49cvss 7.5epss 0.01

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoint `http://<Zima_Server_IP:PORT>/v2_1/file` in ZimaOS is vulnerable to a directory traversal attack, allowing authenticated users…

  • CVE-2024-49357HigOct 24, 2024
    risk 0.50cvss 7.5epss 0.24

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpoints in ZimaOS, such as `http:///v1/users/image?path=/var/lib/casaos/1/app_order.json` and…

  • CVE-2024-48931HigOct 24, 2024
    risk 0.49cvss 7.5epss 0.01

    ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the ZimaOS API endpoint `http://<Zima_Server_IP:PORT>/v3/file?token=&files=<file_path>` is vulnerable to arbitrary file reading due to…

  • CVE-2024-48423HigOct 24, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.

  • CVE-2024-48208HigOct 24, 2024
    risk 0.00cvss 8.6epss 0.02

    pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.

  • CVE-2024-47881HigOct 24, 2024
    risk 0.46cvss 8.1epss 0.01

    OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker to load (local or remote)…

  • CVE-2024-47880HigOct 24, 2024
    risk 0.46cvss 8.1epss 0.00

    OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a way that it reflects part of the request verbatim, with a Content-Type header also taken from the request. An attacker could lead a user to…

  • CVE-2024-47879HigOct 24, 2024
    risk 0.42cvss 7.6epss 0.00

    OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `preview-expression` command means that visiting a malicious website could cause an attacker-controlled expression to be executed. The…

  • CVE-2024-47878HigOct 24, 2024
    risk 0.46cvss 8.1epss 0.00

    OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/authorized` endpoint includes the `state` GET parameter verbatim in a `` tag in the output, so without escaping. An attacker could lead or redirect a user to…

  • CVE-2024-45263HigOct 24, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to information leakage, enabling complete…

  • CVE-2024-45262HigOct 24, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path.

  • CVE-2024-45261HigOct 24, 2024
    risk 0.52cvss 8.0epss 0.00

    An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses…

  • CVE-2024-45260HigOct 24, 2024
    risk 0.52cvss 8.0epss 0.04

    An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereby gaining complete control over it.

  • CVE-2024-10327HigOct 24, 2024
    risk 0.53cvss 8.1epss 0.01

    A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature allowing the authentication to proceed regardless of the user’s selection. When a user long-presses the…

  • CVE-2024-45242HigOct 24, 2024
    risk 0.53cvss 7.8epss 0.35

    EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping or Speed Test utility. During the time of initial setup, the device creates an open unsecured network whose admin panel is configured with…

  • CVE-2024-48454HigOct 24, 2024
    risk 0.47cvss 7.2epss 0.01

    An issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via the /admin?page=user component

  • CVE-2024-48427HigOct 24, 2024
    risk 0.57cvss 8.8epss 0.01

    A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id

  • CVE-2024-48142HigOct 24, 2024
    risk 0.49cvss 7.5epss 0.00

    A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

  • CVE-2024-48141HigOct 24, 2024
    risk 0.49cvss 7.5epss 0.00

    A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

  • CVE-2024-48140HigOct 24, 2024
    risk 0.49cvss 7.5epss 0.00

    A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

  • CVE-2024-48139HigOct 24, 2024
    risk 0.49cvss 7.5epss 0.00

    A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

  • CVE-2024-46998HigOct 24, 2024
    risk 0.46cvss 7.1epss 0.00

    baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Edit Email Form Settings Feature. Version 5.1.2 fixes the issue.

  • CVE-2024-48441HigOct 24, 2024
    risk 0.57cvss 8.8epss 0.02

    Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp.

  • CVE-2024-48440HigOct 24, 2024
    risk 0.57cvss 8.8epss 0.02

    Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection vulnerability via the component at_command.asp.