VYPR

CVEs

115,364 total · page 881 of 2,308

  • CVE-2020-36838HigOct 16, 2024
    risk 0.48cvss 7.4epss 0.00

    The Facebook Chat Plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ajax_update_options function in versions up to, and including, 1.5. This flaw makes it possible for low-level authenticated attackers to connect their own…

  • CVE-2020-36836HigOct 16, 2024
    risk 0.45cvss 8.0epss 0.01

    The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated users with minimal…

  • CVE-2019-25216HigOct 16, 2024
    risk 0.47cvss 7.2epss 0.01

    The Rich Review plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the POST body 'update' parameter in versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2019-25215HigOct 16, 2024
    risk 0.47cvss 7.3epss 0.00

    The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in nearly every file of the plugin in versions up to, and including, 1.1.14. This makes it possible for unauthenticated attackers to call the files directly and…

  • CVE-2019-25214HigOct 16, 2024
    risk 0.47cvss 7.2epss 0.00

    The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST API routes in versions up to, and including, 2.0.4. This makes it possible for unauthenticated attackers to call the endpoints and perform unauthorized actions…

  • CVE-2017-20192HigOct 16, 2024
    risk 0.54cvss 8.3epss 0.01

    The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2016-15041HigOct 16, 2024
    risk 0.47cvss 7.2epss 0.01

    The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mwp_setup_purchase_username’ parameter in versions up to, and including, 3.1.2 due to insufficient input…

  • CVE-2012-10018HigOct 16, 2024
    risk 0.54cvss 8.3epss 0.01

    The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and including 6.1, 1.0 respectively. This makes it possible for attackers to forgery requests coming from a vulnerable site's server and ultimately perform an XSS…

  • CVE-2024-9305HigOct 16, 2024
    risk 0.53cvss 8.1epss 0.01

    The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. This is due to the appp_reset_password() and validate_reset_password() functions not having enough controls to…

  • CVE-2024-38204HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network.

  • CVE-2024-38190HigOct 15, 2024
    risk 0.56cvss 8.6epss 0.01

    Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.

  • CVE-2024-38139HigOct 15, 2024
    risk 0.57cvss 8.7epss 0.01

    Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.

  • CVE-2024-9965HigOct 15, 2024
    risk 0.57cvss 8.8epss 0.00

    Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2024-9961HigOct 15, 2024
    risk 0.57cvss 8.8epss 0.00

    Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-9960HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.00

    Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-9959HigOct 15, 2024
    risk 0.57cvss 8.8epss 0.00

    Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)

  • CVE-2024-9957HigOct 15, 2024
    risk 0.57cvss 8.8epss 0.00

    Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-9956HigOct 15, 2024
    risk 0.51cvss 7.8epss 0.00

    Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-9955HigOct 15, 2024
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-9954HigOct 15, 2024
    risk 0.58cvss 8.8epss 0.05

    Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-48783HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postgresql.conf component.

  • CVE-2024-44775HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    kmqtt v0.2.7 is vulnerable to Denial of Service (DoS) due to a Null Pointer Exception. A remote attacker can cause the broker to crash by sending a specially crafted MQTT CONNECT packet that triggers an unhandled null reference, leading to an immediate process termination.

  • CVE-2024-41311HigOct 15, 2024
    risk 0.46cvss 8.1epss 0.01

    In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and write.

  • CVE-2024-21285HigOct 15, 2024
    risk 0.46cvss 7.1epss 0.00

    Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker with network access via…

  • CVE-2024-21284HigOct 15, 2024
    risk 0.46cvss 7.1epss 0.00

    Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacker with network access via…

  • CVE-2024-21283HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payroll for Core). Supported versions that are affected are 9.2.48-9.2.50. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2024-21282HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Financials product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2024-21280HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Authoring). Supported versions that are affected are 12.2.5-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2024-21279HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (component: Auctions). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sourcing. …

  • CVE-2024-21278HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award Processes). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2024-21277HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integration). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2024-21276HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Messages). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work…

  • CVE-2024-21275HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Quoting product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.7-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2024-21274HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2024-21272HigOct 15, 2024
    risk 0.42cvss 7.5epss 0.01

    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise…

  • CVE-2024-21271HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Field Service Engineer Portal). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2024-21270HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Tasks). Supported versions that are affected are 12.2.6-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2024-21269HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Incentive Compensation product of Oracle E-Business Suite (component: Compensation Plan). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2024-21268HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.2.11-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2024-21267HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.12-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2024-21266HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price List). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2024-21265HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Site Hierarchy Flows). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2024-21260HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to…

  • CVE-2024-21259HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22 and prior to 7.1.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where…

  • CVE-2024-21255HigOct 15, 2024
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XMLPublisher). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2024-21254HigOct 15, 2024
    risk 0.57cvss 8.8epss 0.01

    Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2024-21252HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2024-21250HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.00

    Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Manager Specification). Supported versions that are affected are 12.2.13-12.2.14. Easily exploitable vulnerability allows low privileged attacker with…

  • CVE-2024-21246HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: OSB Core Functionality). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2024-21234HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to…