VYPR

CVEs

115,363 total · page 882 of 2,308

  • CVE-2024-21214HigOct 15, 2024
    risk 0.53cvss 8.1epss 0.01

    Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2024-21195HigOct 15, 2024
    risk 0.49cvss 7.6epss 0.00

    Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to…

  • CVE-2024-21191HigOct 15, 2024
    risk 0.49cvss 7.6epss 0.00

    Vulnerability in the Oracle Enterprise Manager Fusion Middleware Control product of Oracle Fusion Middleware (component: FMW Control Plugin). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network…

  • CVE-2024-21190HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability in the Oracle Global Lifecycle Management FMW Installer product of Oracle Fusion Middleware (component: Cloning). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SFTP…

  • CVE-2024-41344HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.00

    A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.

  • CVE-2024-35584HigOct 15, 2024
    risk 0.58cvss 8.8epss 0.06

    SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible for an authenticated user to perform SQL Injection due to the…

  • CVE-2024-5749HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.

  • CVE-2024-48915HigOct 15, 2024
    risk 0.50cvss epss 0.00

    Agent Dart is an agent library built for Internet Computer for Dart and Flutter apps. Prior to version 1.0.0-dev.29, certificate verification in `lib/agent/certificate.dart` does not occur properly. During the delegation verification in the `_checkDelegation` function, the…

  • CVE-2024-47876HigOct 15, 2024
    risk 0.50cvss 8.8epss 0.01

    Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in as a normal user. This can result in illegal access being granted to the system. Version 23.3 fixes this vulnerability.

  • CVE-2024-47874HigOct 15, 2024
    risk 0.50cvss epss 0.01

    Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treats `multipart/form-data` parts without a `filename` as text form fields and buffers those in byte strings with no size limit. This allows an attacker to upload…

  • CVE-2024-47824HigOct 15, 2024
    risk 0.50cvss epss 0.01

    matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious homeserver to potentially steal message keys for a room when a user invites…

  • CVE-2024-47779HigOct 15, 2024
    risk 0.39cvss epss 0.00

    Element is a Matrix web client built using the Matrix React SDK. Element Web versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been…

  • CVE-2024-47771HigOct 15, 2024
    risk 0.39cvss epss 0.01

    Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified…

  • CVE-2024-47080HigOct 15, 2024
    risk 0.50cvss epss 0.01

    matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 through 34.7.0, the method `MatrixClient.sendSharedHistoryKeys` is vulnerable to interception by malicious homeservers. The method was introduced by MSC3061)…

  • CVE-2024-9986HigOct 15, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file member_register.php. The manipulation of the argument fullname/username/password/email leads to sql injection. The…

  • CVE-2024-48282HigOct 15, 2024
    risk 0.49cvss 7.6epss 0.00

    A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP…

  • CVE-2024-48280HigOct 15, 2024
    risk 0.49cvss 7.6epss 0.00

    A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request.

  • CVE-2024-48279HigOct 15, 2024
    risk 0.49cvss 7.6epss 0.01

    A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request.

  • CVE-2024-49387HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.00

    Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

  • CVE-2024-47674HigOct 15, 2024
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: mm: avoid leaving partial pfn mappings around in error case As Jann points out, PFN mappings are special, because unlike normal memory mappings, there is no lifetime information associated with the mapping -…

  • CVE-2024-45276HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.

  • CVE-2024-45273HigOct 15, 2024
    risk 0.55cvss 8.4epss 0.00

    An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.

  • CVE-2024-45272HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in connection lost.

  • CVE-2024-45271HigOct 15, 2024
    risk 0.55cvss 8.4epss 0.00

    An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.

  • CVE-2024-9983HigOct 15, 2024
    risk 0.49cvss 7.5epss 0.01

    Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

  • CVE-2024-9981HigOct 15, 2024
    risk 0.57cvss 8.8epss 0.01

    The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regular privileges to upload a malicious PHP file first and then exploit this vulnerability to include the file, resulting in arbitrary code execution on the server.

  • CVE-2024-9980HigOct 15, 2024
    risk 0.57cvss 8.8epss 0.01

    The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regular privileges to inject arbitrary SQL commands to read, modify and delete database contents.

  • CVE-2024-9837HigOct 15, 2024
    risk 0.40cvss 7.3epss 0.01

    The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.1. This is due to the software allowing users to execute an action that does not properly validate a value before…

  • CVE-2024-46898HigOct 15, 2024
    risk 0.00cvss 7.5epss 0.01

    SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploited, arbitrary files on the server may be retrieved when processing crafted HTTP requests.

  • CVE-2024-9971HigOct 15, 2024
    risk 0.57cvss 8.8epss 0.01

    The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents.

  • CVE-2024-9970HigOct 15, 2024
    risk 0.57cvss 8.8epss 0.01

    The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie.

  • CVE-2024-9968HigOct 15, 2024
    risk 0.57cvss 8.8epss 0.01

    WebEIP v3.0 from NewType does not properly validate user input, allowing remote attackers with regular privilege to inject SQL commands to read, modify, and delete data stored in database. The affected product is no longer maintained. It is recommended to upgrade to the new…

  • CVE-2024-9687HigOct 15, 2024
    risk 0.57cvss 8.8epss 0.00

    The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0. This is due to insufficient validation of the user-controlled key on the 'validate_tg' action. This makes it possible for authenticated attackers, with…

  • CVE-2024-9548HigOct 15, 2024
    risk 0.40cvss 7.2epss 0.01

    The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due to insufficient input sanitization and output escaping when logging visitor requests. This makes it possible for…

  • CVE-2024-35520HigOct 14, 2024
    risk 0.55cvss 8.4epss 0.09

    Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.

  • CVE-2024-35519HigOct 14, 2024
    risk 0.55cvss 8.4epss 0.01

    Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter.

  • CVE-2024-35518HigOct 14, 2024
    risk 0.55cvss 8.4epss 0.01

    Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.

  • CVE-2024-6207HigOct 14, 2024
    risk 0.49cvss 7.5epss 0.01

    CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected…

  • CVE-2024-48911HigOct 14, 2024
    risk 0.44cvss 7.8epss 0.00

    OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0.9.4, where the config file is stored in an unprivileged user directory but the daemon is executed by root, it’s possible for the unprivileged user to change…

  • CVE-2024-48824HigOct 14, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to obtain sensitive information via the Racine & FileName parameters in the download-file.php component.

  • CVE-2024-48822HigOct 14, 2024
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php page.

  • CVE-2024-48792HigOct 14, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Hideez com.hideez 2.7.8.3 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48791HigOct 14, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware update process

  • CVE-2024-48789HigOct 14, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in INATRONIC com.inatronic.drivedeck.home 2.6.23 allows a remote attacker to obtain sensitve information via the firmware update process.

  • CVE-2024-48799HigOct 14, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48798HigOct 14, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48797HigOct 14, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-48796HigOct 14, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update process.

  • CVE-2024-45733HigOct 14, 2024
    risk 0.57cvss 8.8epss 0.01

    In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution (RCE) due to an insecure session storage configuration.

  • CVE-2024-45732HigOct 14, 2024
    risk 0.46cvss 7.1epss 0.00

    In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could run a search as the…